[FD] CVE-2014-8493 - ZTE ZXHN H108L Authentication Bypass

2014-11-17 Thread Project Zero Labs
About the software == ZTE ZXHN H108L is provided by some large Greek ISPs to their subscribers. Vulnerability Details = CWMP configuration is accessible only through the Administrator account. CWMP is a protocol widely used by ISPs worldwide for remote pro

[FD] Zoph <= 0.9.1 - Multiple Vulnerabilities

2014-11-17 Thread Manuel Garcia Cardenas
= MGC ALERT 2014-005 - Original release date: March 5, 2014 - Last revised: November 18, 2014 - Discovered by: Manuel Garcia Cardenas - Severity: 10/10 (CVSS Base Score) = I. VULNERABILITY

[FD] WebsiteBaker <=2.8.3 - Multiple Vulnerabilities

2014-11-17 Thread Manuel Garcia Cardenas
= MGC ALERT 2014-004 - Original release date: March 11, 2014 - Last revised: November 18, 2014 - Discovered by: Manuel Garcia Cardenas - Severity: 10/10 (CVSS Base Score) = I. VULNERABILITY ---

[FD] Proticaret E-Commerce Script v3.0 SQL Injection

2014-11-17 Thread Onur Alanbel
Document Title: Proticaret E-Commerce Script v3.0 >= SQL Injection Release Date: === 13 Nov 2014 Product & Service Introduction: Proticaret is a free e-commerce script. Abstract Advisory Information: === BGA Security Team discover

[FD] Vulnerabilities in D-Link DCS-2103

2014-11-17 Thread MustLive
Hello list! There are Directory Traversal and Full path disclosure vulnerabilities in D-Link DCS-2103 (IP camera). - Affected products: - Vulnerable is the next model: D-Link DCS-2103, Firmware 1.0.0. This model with other firmware versions als

Re: [FD] xdg-open RCE

2014-11-17 Thread Brandon Perry
This is very similar to this gksu bug (which only applies to gksu when in SU_MODE) http://savannah.nongnu.org/bugs/?40023 Attempted to email the gksu 'maintainer', but with no response. Did a quick write up on the Rapid7 site on how I found out about it and the vector I was using to exploit it:

[FD] 81% of Tor users can be de-anonymised by analysing router information, research indicates

2014-11-17 Thread Ivan .Heca
http://thestack.com/chakravarty-tor-traffic-analysis-141114 ___ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] XOOPS <= 2.5.6 - Blind SQL Injection

2014-11-17 Thread Manuel Garcia Cardenas
= MGC ALERT 2014-003 - Original release date: March 6, 2014 - Last revised: November 18, 2014 - Discovered by: Manuel Garcia Cardenas - Severity: 7,1/10 (CVSS Base Score) = I. VULNERABILITY ---

[FD] Reflected XSS in Nibbleblog <= v4.0.1

2014-11-17 Thread Manuel Garcia Cardenas
= MGC ALERT 2014-002 - Original release date: March 5, 2014 - Last revised: November 17, 2014 - Discovered by: Manuel Garcia Cardenas - Severity: 4,8/10 (CVSS Base Score) = I. VULNERABILITY ---