[FD] Information Exposure via SNMP on ARRIS / Motorola SBG6580 Cable Modem Gateway

2014-05-18 Thread Inokii Security Advisory
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512  Inokii Security Advisory Inokii-ID: 2014-01 Affected Product: ARRIS / Motorola SURFboard SBG6580 Series Wi-Fi Cable Modem Gateway Severity Rating: Important Impact

Re: [FD] [CVE-2014-3719] ALEPH500 (Integrated librarymanagement system) SQL Injection

2014-05-18 Thread shady.liu
Greetings:Oh very feel shy, injection parameter "lib, docnum"[0] place: GET, parameter: docnum, type: Single quoted string (default)[1] place: GET, parameter: lib, type: Single quoted stringReplace "lib, docnum" parameter value with "AND 6012=6012AND'SM'='SM'"Could you update information. Thank you