[FD] [KIS-2021-01] IPS Community Suite <= 4.5.4 (Downloads REST API) SQL Injection Vulnerability

2021-01-06 Thread Egidio Romano
- IPS Community Suite <= 4.5.4 (Downloads REST API) SQL Injection Vulnerability - [-] Software Link: https://invisioncommunity.com [-] Affecte

[FD] Backdoor.Win32.Zombam.k / Remote Stack Buffer Overflow

2021-01-06 Thread malvuln
Discovery / credits: malvuln - Malvuln.com (c) 2021 Original source: https://malvuln.com/advisory/79d9908b6769e64f922e74a090f5ceeb.txt Contact: malvul...@gmail.com Media: twitter.com/malvuln Threat: Backdoor.Win32.Zombam.k Vulnerability: Remote String Dereference Stack Buffer Overflow Description

[FD] Files.com - Auth Bypass (Fat Client)

2021-01-06 Thread Balázs Hambalkó
Hi, Vendor: Files.com Product: Fat Client Tested version: 3.3.6 but newer version high likely also affected Credit: Balazs Hambalko, IT Security Consultant This vulnerability was identified and reported promptly to the vendor in April 2020. The answer was they do not see any risk here. Anyway I

[FD] CVE-2020-24386: IMAP hibernation allows accessing other peoples mail

2021-01-06 Thread Aki Tuomi
Open-Xchange Security Advisory 2021-01-04 Product: Dovecot Vendor: OX Software GmbH Internal reference: DOP-2009 (Bug ID) Vulnerability type: CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences Vulnerable version: 2.2.26-2.3.11.3 Vulnerable component: imap Report confidence: Con

[FD] CVE-2020-24386: IMAP hibernation allows accessing other peoples mail

2021-01-06 Thread Aki Tuomi
Open-Xchange Security Advisory 2021-01-04 Product: Dovecot Vendor: OX Software GmbH Internal reference: DOV-4113 (Bug ID) Vulnerability type: CWE-20: Improper Input Validation Vulnerable version: 2.3.11-2.3.11.3 Vulnerable component: lda, lmtp, imap Report confidence: Confirmed Solution status: Fi