[FD] Kaseya Browser Android Path Traversal

2015-01-28 Thread Denis Andzakovic
(, ) (, . '.' ) ('.', ). , ('. ( ) ( (_,) .'), ) _ _, / _/ / _ \ _ \ \==/ /_\ \ _/ ___\/ _ \ / \ / \/ |\\ \__( <_> ) Y Y \ /__ /\___|__ / \___ >/|__|_| / \/ \/.-.\/ \/:wq

[FD] Kaseya BYOD Gateway Multiple Vulnerabilities

2015-01-28 Thread Denis Andzakovic
(, ) (, . '.' ) ('.', ). , ('. ( ) ( (_,) .'), ) _ _, / _/ / _ \ _ \ \==/ /_\ \ _/ ___\/ _ \ / \ / \/ |\\ \__( <_> ) Y Y \ /__ /\___|__ / \___ >/|__|_| / \/ \/.-.\/ \/:wq

[FD] Fortinet FortiOS Multiple Vulnerabilities

2015-01-28 Thread Denis Andzakovic
(, ) (, . '.' ) ('.', ). , ('. ( ) ( (_,) .'), ) _ _, / _/ / _ \ _ \ \==/ /_\ \ _/ ___\/ _ \ / \ / \/ |\\ \__( <_> ) Y Y \ /__ /\___|__ / \___ >/|__|_| / \/ \/.-.\/ \/:wq

[FD] Cisco Meraki Systems Manager Multiple Vulnerabilities

2015-01-28 Thread Denis Andzakovic
(, ) (, . '.' ) ('.', ). , ('. ( ) ( (_,) .'), ) _ _, / _/ / _ \ _ \ \==/ /_\ \ _/ ___\/ _ \ / \ / \/ |\\ \__( <_> ) Y Y \ /__ /\___|__ / \___ >/|__|_| / \/ \/.-.\/ \/:wq

[FD] Fortinet FortiClient Multiple Vulnerabilities

2015-01-28 Thread Denis Andzakovic
(, ) (, . '.' ) ('.', ). , ('. ( ) ( (_,) .'), ) _ _, / _/ / _ \ _ \ \==/ /_\ \ _/ ___\/ _ \ / \ / \/ |\\ \__( <_> ) Y Y \ /__ /\___|__ / \___ >/|__|_| / \/ \/.-.\/ \/:wq

[FD] Fortinet FortiAuthenticator Multiple Vulnerabilities

2015-01-28 Thread Denis Andzakovic
(, ) (, . '.' ) ('.', ). , ('. ( ) ( (_,) .'), ) _ _, / _/ / _ \ _ \ \==/ /_\ \ _/ ___\/ _ \ / \ / \/ |\\ \__( <_> ) Y Y \ /__ /\___|__ / \___ >/|__|_| / \/ \/.-.\/ \/:wq

[FD] AirWatch Multiple Direct Object References

2015-01-28 Thread Denis Andzakovic
(, ) (, . '.' ) ('.', ). , ('. ( ) ( (_,) .'), ) _ _, / _/ / _ \ _ \ \==/ /_\ \ _/ ___\/ _ \ / \ / \/ |\\ \__( <_> ) Y Y \ /__ /\___|__ / \___ >/|__|_| / \/ \/.-.\/ \/:wq

Re: [FD] CVE-2015-1169 - CAS Server 3.5.2 allows remote attackers to bypass LDAP authentication via crafted wildcards.

2015-01-28 Thread Paul B. Henson
This CVE claims CAS has a vulnerability that "allows remote attackers to bypass LDAP authentication via crafted wildcards". My understanding of an "authentication bypass" vulnerability is one that actually bypasses authentication, accessing a resource without having to authenticate, as enumerated a

[FD] KL-001-2015-001 : Windows 2003 tcpip.sys Privilege Escalation

2015-01-28 Thread KoreLogic Disclosures
KL-001-2015-001 : Microsoft Windows Server 2003 SP2 Arbitrary Write Privilege Escalation Title: Microsoft Windows Server 2003 SP2 Arbitrary Write Privilege Escalation Advisory ID: KL-001-2015-001 Publication Date: 2015.01.28 Publication URL: https://www.korelogic.com/Resources/Advisories/KL-001-

[FD] Vulnerabilities in HP LaserJet

2015-01-28 Thread MustLive
Hello list! There are Information Leakage and Insufficient Authorization vulnerabilities in HP LaserJet. Vulnerabilities are in control panel of HP network MFP and printers. Earlier I informed HP about it. You can read articles in BBC (http://seclists.org/fulldisclosure/2014/Dec/98) and Glob

[FD] AST-2015-002: Mitigation for libcURL HTTP request injection vulnerability

2015-01-28 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2015-002 ProductAsterisk SummaryMitigation for libcURL HTTP request injection vulnerability

[FD] AST-2015-001: File descriptor leak when incompatible codecs are offered

2015-01-28 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2015-001 ProductAsterisk SummaryFile descriptor leak when incompatible codecs are offered

Re: [FD] Qualys Security Advisory CVE-2015-0235 - GHOST: glibc gethostbyname buffer overflow

2015-01-28 Thread Timo Goosen
"Do you trust glibc? OK, perhaps that snide remark is overstating things a bit, but secure software only happens when all the pieces have 100% correct behavior." KernelTrap.org, November 26, 2001 Theo De Raadt http://en.wikiquote.org/wiki/Talk:Theo_de_Raadt On 27/01/2015 18:24, Qualys Secu

[FD] [The ManageOwnage Series, part XII]: Multiple vulnerabilities in FailOverServlet (OpManager, AppManager, IT360)

2015-01-28 Thread Pedro Ribeiro
Hi, This is part 12 of the ManageOwnage series. For previous parts, see [1]. This time we have an arbitrary file download, directory content disclosure and blind SQL injection vulnerabilities in ManageEngine OpManager, Applications Manager and IT360. I've pushed two new Metasploit modules into t

[FD] Wordpress Geo Mashup plugin <= 1.8.2 XSS vulnerability

2015-01-28 Thread Paolo Perego
Vulnerability title: Wordpress Geo Mashup plugin XSS Author: Paolo Perego CVE: CVE-2015-1383 Affected versions: <= 1.8.2 Fixed version: 1.8.3 (January, 11 2015) Product link: https://wordpress.org/plugins/geo-mashup/ Description Geo Mashup is a wordpress plugin designed to let you save location i