[FD] ManageEngine ServiceDesk Plus <= 9.1 build 9110 - Path Traversal

2015-10-05 Thread xistence
ath Traversal Credit: xistence Product Description --- ServiceDesk Plus is an ITIL ready IT help desk software for organizations of all sizes. With advanced ITSM functionality and easy-to-use capability, ServiceDesk Plus helps IT support teams deliver world-class services to end users w

[FD] ManageEngine OpManager multiple vulnerabilities

2015-09-15 Thread xistence
Exploit Title: ManageEngine OpManager multiple vulnerabilities Product: ManageEngine OpManager Vulnerable Versions: v11.5 and previous versions Tested Version: v11.5 (Windows) Advisory Publication: 14/09/2015 Vulnerability Type: hardcoded credentials, SQL query protection bypass Credit: xistence

[FD] ManageEngine EventLog Analyzer SQL query execution

2015-09-15 Thread xistence
Credit: xistence Product Description --- EventLog Analyzer carry out logs analysis for all Windows, Linux and Unix systems, Switches and Routers (Cisco), other Syslog supporting devices, and applications like IIS, MS SQL. Eventlog analyzer application is capable of performing real

[FD] Western Digital Arkeia "ARKFS_EXEC_CMD" <= v11.0.12 Remote Code Execution

2015-07-10 Thread xistence
## Advisory Information Title: Western Digital Arkeia "ARKFS_EXEC_CMD" <= v11.0.12 Remote Code Execution Submitter: xistence Date published: 2015-07-10 Vendors contacted: Western Digital / Arkeia Class: OS Command Injection [CWE-78] Impact: Code execution Remotely Exploitable: Yes