[FD] Multiple banks - potential risk of an inconsequent client separation

2019-08-09 Thread Tim Schughart
Hello together, as many of you already know some german banks are sharing the same hoster. Via google dorking it is possible to determine some customers of one of those hosters (Fiducia & GAD IT AG). The hoster uses a GET parameter called „bankid“ to identify its customers. For example: h

[FD] Dlink-CVE-2019-13101

2019-08-09 Thread Devendra Solanki
A remote vulnerability was discovered on D-Link DIR-600M Wireless N 150 Home Router in multiple respective firmware versions. The vulnerability provides unauthenticated remote access to the router's WAN configuration page i.e. "wan.htm", which leads to disclosure of sensitive user information inclu

[FD] Mitel 6869i SIP Deskphone 4.2.2032: Unauthenticated Bash Command Injection Vulnerability with Root Priviledges in /cgi-bin/webuploadconfig script

2019-08-09 Thread Axel Rengstorf
BlueBox Security http://www.bluebox-security.de/ security(at)bluebox-security.de bbs-2019.001.txt 08-August-2019 Vendor: Mitel Affected Products: Mitel 6869i Voip De