FreshRSS

๐Ÿ”’
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Wordpress Seotheme - Remote Code Execution Unauthenticated

February 9th 2024 at 00:00
Wordpress Seotheme - Remote Code Execution Unauthenticated
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Wordpress Augmented-Reality - Remote Code Execution Unauthenticated

February 9th 2024 at 00:00
Wordpress Augmented-Reality - Remote Code Execution Unauthenticated
โ˜ โ˜† โœ‡ Exploit-DB Updates

[dos] Elasticsearch - StackOverflow DoS

February 9th 2024 at 00:00
Elasticsearch - StackOverflow DoS
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Online Nurse Hiring System 1.0 - Time-Based SQL Injection

February 9th 2024 at 00:00
Online Nurse Hiring System 1.0 - Time-Based SQL Injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] Zyxel zysh - Format string

February 9th 2024 at 00:00
Zyxel zysh - Format string
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Rail Pass Management System 1.0 - Time-Based SQL Injection

February 9th 2024 at 00:00
Rail Pass Management System 1.0 - Time-Based SQL Injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Advanced Page Visit Counter 1.0 - Admin+ Stored Cross-Site Scripting (XSS) (Authenticated)

February 9th 2024 at 00:00
Advanced Page Visit Counter 1.0 - Admin+ Stored Cross-Site Scripting (XSS) (Authenticated)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Wordpress 'simple urls' Plugin < 115 - XSS

February 5th 2024 at 00:00
Wordpress 'simple urls' Plugin
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Curfew e-Pass Management System 1.0 - FromDate SQL Injection

February 5th 2024 at 00:00
Curfew e-Pass Management System 1.0 - FromDate SQL Injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] GYM MS - GYM Management System - Cross Site Scripting (Stored)

February 5th 2024 at 00:00
GYM MS - GYM Management System - Cross Site Scripting (Stored)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] Milesight Routers UR5X, UR32L, UR32, UR35, UR41 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption

February 5th 2024 at 00:00
Milesight Routers UR5X, UR32L, UR32, UR35, UR41 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] TASKHUB-2.8.8 - XSS-Reflected

February 5th 2024 at 00:00
TASKHUB-2.8.8 - XSS-Reflected
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] WhatsUp Gold 2022 (22.1.0 Build 39) - XSS

February 5th 2024 at 00:00
WhatsUp Gold 2022 (22.1.0 Build 39) - XSS
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] MISP 2.4.171 - Stored XSS

February 5th 2024 at 00:00
MISP 2.4.171 - Stored XSS
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Clinic's Patient Management System 1.0 - Unauthenticated RCE

February 5th 2024 at 00:00
Clinic's Patient Management System 1.0 - Unauthenticated RCE
โ˜ โ˜† โœ‡ Full Disclosure

APPLE-SA-02-02-2024-1 visionOS 1.0.2

February 4th 2024 at 08:13

Posted by Apple Product Security via Fulldisclosure on Feb 04

APPLE-SA-02-02-2024-1 visionOS 1.0.2

visionOS 1.0.2 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/HT214070.

Apple maintains a Security Releases page at
https://support.apple.com/HT201222 which lists recent
software updates with security advisories.

WebKit
Available for: Apple Vision Pro
Impact: Processing maliciously crafted web content may lead to
arbitrary code...
โ˜ โ˜† โœ‡ Full Disclosure

CVE-2023-6246: Heap-based buffer overflow in the glibc's syslog()

February 4th 2024 at 08:12

Posted by Qualys Security Advisory via Fulldisclosure on Feb 04

Qualys Security Advisory

CVE-2023-6246: Heap-based buffer overflow in the glibc's syslog()

========================================================================
Contents
========================================================================

Summary
Analysis
Proof of concept
Exploitation
Acknowledgments
Timeline

========================================================================
Summary...
โ˜ โ˜† โœ‡ Full Disclosure

Out-of-bounds read & write in the glibc's qsort()

February 4th 2024 at 08:12

Posted by Qualys Security Advisory via Fulldisclosure on Feb 04

Qualys Security Advisory

For the algorithm lovers: Nontransitive comparison functions lead to
out-of-bounds read & write in glibc's qsort()

========================================================================
Contents
========================================================================

Summary
Background
Experiments
Analysis
Patch
Discussion
Acknowledgments
Timeline

CUT MY LIST IN TWO PIECES
THAT'S HOW YOU START...
โ˜ โ˜† โœ‡ Full Disclosure

TROJAN.WIN32 BANKSHOT / Remote Stack Buffer Overflow (SEH)

February 4th 2024 at 08:11

Posted by malvuln on Feb 04

Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2024
Original source:
https://malvuln.com/advisory/f2fd6a7b400782bb43499e722fb62cf4.txt
Contact: malvuln13 () gmail com
Media: twitter.com/malvuln

Threat: Trojan.Win32 BankShot
Vulnerability: Remote Stack Buffer Overflow (SEH)
Description: The malware listens on TCP port 1978 and creates a local
Windows service running with SYSTEM integrity. Third-party adversaries who
can reach the...
โ˜ โ˜† โœ‡ Full Disclosure

Research about usage & possible issues of the NVD

February 4th 2024 at 08:11

Posted by Andreas Hammer on Feb 04

Hello there!

The University of Erlangen-Nuremberg (Germany) is conducting a research
study to investigate the usage and possible issues of the NVD (National
Vulnerability Database). If you are using the NVD regularly, we would
greatly appreciate your participation which contributes to the
improvement of vulnerability management. You can read more about the
survey here:

https://www.cs1.tf.fau.de/2024/01/29/survey-on-usage-of-nvd/

The...
โ˜ โ˜† โœ‡ Full Disclosure

[KIS-2024-01] XenForo <= 2.2.13 (ArchiveImport.php) Zip Slip Vulnerability

February 4th 2024 at 08:11

Posted by Egidio Romano on Feb 04

------------------------------------------------------------
XenForo <= 2.2.13 (ArchiveImport.php) Zip Slip Vulnerability
------------------------------------------------------------

[-] Software Link:

https://xenforo.com

[-] Affected Versions:

Version 2.2.13 and prior versions.

[-] Vulnerability Description:

The vulnerability is located in the
/src/XF/Service/Style/ArchiveImport.php script. Specifically, into the...
โ˜ โ˜† โœ‡ Full Disclosure

NULL pointer dereference in the function handle_viminfo_register() of vim

February 4th 2024 at 08:09

Posted by Christian Brabandt on Feb 04

Meng Ruijie wrote:

Meng,

This particular problem was fixed in Vim v9.0.1740
https://github.com/vim/vim/commit/0a0764684591c7c6a5d722b628f11dc96208e853

I have no idea, why this issue is worth a CVE, because if an attacker
can modify your .viminfo file to make Vim crash, he already has the
possibilities to do much more harm directly. So I don't think this is
particular useful CVE. I'd also like to dispute this.

Thanks,
Christian
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Electrolink FM/DAB/TV Transmitter - Pre-Auth MPFS Image Remote Code Execution

February 2nd 2024 at 00:00
Electrolink FM/DAB/TV Transmitter - Pre-Auth MPFS Image Remote Code Execution
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Electrolink FM/DAB/TV Transmitter (Login Cookie) - Authentication Bypass

February 2nd 2024 at 00:00
Electrolink FM/DAB/TV Transmitter (Login Cookie) - Authentication Bypass
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] TP-Link TL-WR740N - UnAuthenticated Directory Transversal

February 2nd 2024 at 00:00
TP-Link TL-WR740N - UnAuthenticated Directory Transversal
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] TP-LINK TL-WR740N - Multiple HTML Injection

February 2nd 2024 at 00:00
TP-LINK TL-WR740N - Multiple HTML Injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] mooSocial 3.1.8 - Cross-Site Scripting (XSS) on User Login Page

February 2nd 2024 at 00:00
mooSocial 3.1.8 - Cross-Site Scripting (XSS) on User Login Page
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] PCMan FTP Server 2.0 - 'pwd' Remote Buffer Overflow

February 2nd 2024 at 00:00
PCMan FTP Server 2.0 - 'pwd' Remote Buffer Overflow
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure

February 2nd 2024 at 00:00
Electrolink FM/DAB/TV Transmitter (controlloLogin.js) - Credentials Disclosure
โ˜ โ˜† โœ‡ Exploit-DB Updates

[dos] Electrolink FM/DAB/TV Transmitter - Unauthenticated Remote DoS

February 2nd 2024 at 00:00
Electrolink FM/DAB/TV Transmitter - Unauthenticated Remote DoS
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Juniper-SRX-Firewalls&EX-switches - (PreAuth-RCE) (PoC)

February 2nd 2024 at 00:00
Juniper-SRX-Firewalls&EX-switches - (PreAuth-RCE) (PoC)
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Electrolink FM/DAB/TV Transmitter (login.htm/mail.htm) - Credentials Disclosure

February 2nd 2024 at 00:00
Electrolink FM/DAB/TV Transmitter (login.htm/mail.htm) - Credentials Disclosure
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] WebCatalog 48.4 - Arbitrary Protocol Execution

February 2nd 2024 at 00:00
WebCatalog 48.4 - Arbitrary Protocol Execution
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Electrolink FM/DAB/TV Transmitter - Remote Authentication Removal

February 2nd 2024 at 00:00
Electrolink FM/DAB/TV Transmitter - Remote Authentication Removal
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] GoAhead Web Server 2.5 - 'goform/formTest' Multiple HTML Injection Vulnerabilities

January 31st 2024 at 00:00
GoAhead Web Server 2.5 - 'goform/formTest' Multiple HTML Injection Vulnerabilities
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] RoyalTSX 6.0.1 - RTSZ File Handling Heap Memory Corruption PoC

January 31st 2024 at 00:00
RoyalTSX 6.0.1 - RTSZ File Handling Heap Memory Corruption PoC
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] Proxmox VE - TOTP Brute Force

January 31st 2024 at 00:00
Proxmox VE - TOTP Brute Force
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] 101 News 1.0 - Multiple-SQLi

January 31st 2024 at 00:00
101 News 1.0 - Multiple-SQLi
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Academy LMS 6.2 - SQL Injection

January 31st 2024 at 00:00
Academy LMS 6.2 - SQL Injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Academy LMS 6.2 - Reflected XSS

January 31st 2024 at 00:00
Academy LMS 6.2 - Reflected XSS
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] Equipment Rental Script-1.0 - SQLi

January 29th 2024 at 00:00
Equipment Rental Script-1.0 - SQLi
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] Ricoh Printer - Directory and File Exposure

January 29th 2024 at 00:00
Ricoh Printer - Directory and File Exposure
โ˜ โ˜† โœ‡ Exploit-DB Updates

[remote] Blood Bank & Donor Management System using v2.2 - Stored XSS

January 29th 2024 at 00:00
Blood Bank & Donor Management System using v2.2 - Stored XSS
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Fundraising Script 1.0 - SQLi

January 29th 2024 at 00:00
Fundraising Script 1.0 - SQLi
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] PHP Shopping Cart 4.2 - Multiple-SQLi

January 29th 2024 at 00:00
PHP Shopping Cart 4.2 - Multiple-SQLi
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] Typora v1.7.4 - OS Command Injection

January 29th 2024 at 00:00
Typora v1.7.4 - OS Command Injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[local] 7 Sticky Notes v1.9 - OS Command Injection

January 29th 2024 at 00:00
7 Sticky Notes v1.9 - OS Command Injection
โ˜ โ˜† โœ‡ Exploit-DB Updates

[webapps] Bank Locker Management System - SQL Injection

January 29th 2024 at 00:00
Bank Locker Management System - SQL Injection
โ˜ โ˜† โœ‡ Full Disclosure

Re: Buffer Overflow in graphviz via via a crafted config6a file

January 27th 2024 at 22:03

Posted by Matthew Fernandez on Jan 27

More specifically, this issue is an out-of-bounds read.

AFAICT the issue was actually introduced in Graphviz 2.36. It was fixed
in commit a95f977f5d809915ec4b14836d2b5b7f5e74881e (essentially
reverting cf95714837f06f684929b54659523c2c9b1fc19f that introduced the
issue), but there has been no release yet since then. The next release
will be 10.0.0. So affected versions would be [2.36, 10.0.0).

To exploit this issue, you need to modify a...
โ˜ โ˜† โœ‡ Full Disclosure

Re: null pointer deference in nano via read_the_list()

January 27th 2024 at 22:03

Posted by Mark Esler on Jan 27

Hi Meng,

In your recent mass posts to FD, are you reporting vulnerabilities or
bug reports which have words like "segfault" in the title? What benefit
do you see this having? Have you spoken to each upstream project before
requesting a CVE be assigned?

Thank you,
Mark Esler
โ˜ โ˜† โœ‡ Full Disclosure

CVEs based on commit messages

January 27th 2024 at 22:03

Posted by Mark Esler on Jan 27

Dear Meng Rujie,

In regards to your recent FD posts, are you requesting CVEs based on the
presence of strings in commit messages such as "null pointer dereference"?

Are you reaching out to each upstream project before assigning a CVE? Do
you believe that every null pointer bug is a vulnerability? What impact
are you hoping to achieve?

Please reconsider how you are requesting CVEs.

CVE assignment based on commit message allows...
โ˜ โ˜† โœ‡ Full Disclosure

Re: NULL pointer dereference in freedesktop Mesa via check_xshm()

January 27th 2024 at 22:01

Posted by Dan Cross on Jan 27

I find it very difficult to believe that every NULL pointer error in
existence is a security vulnerability.

- Dan C.
โ˜ โ˜† โœ‡ Full Disclosure

Re: Null pointer dereference in Xedit

January 27th 2024 at 22:01

Posted by Alan Coopersmith on Jan 27

I will be asking that this CVE be withdrawn on behalf of the X.Org security team.

While it is a low-priority bug, we did not see any security exposure
when this bug was first brought to our attention because there is no
way for an attacker to change the contents of the lisp.lsp file or to
cause a *.lsp file to be loaded for another user.

The bug report states "replace /usr/local/lib/X11/xedit/lisp/lisp.lsp with
the attached version,"...
โ˜ โ˜† โœ‡ Full Disclosure

null pointer deference in MiniZinc via a crafted Preferences.json file

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
A null pointer deference existed in MiniZinc v.2.7.6 via a crafted Preferences.json file.

[VulnerabilityType Other]
null pointer deference

[Vendor of Product]
MiniZinc

[Affected Product Code Base]
MiniZinc - 2.7.6

[Reference]
https://github.com/MiniZinc/libminizinc/issues/729

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-46050 to this...
โ˜ โ˜† โœ‡ Full Disclosure

arithmetic exception in S-lang via the function tt_sprintf()

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
S-Lang v2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf().

[VulnerabilityType Other]
FPE

[Vendor of Product]
S-Lang

[Affected Product Code Base]
S-Lang - 2.3.2

[Reference]
http://lists.jedsoft.org/lists/slang-users/2023/0000003.html

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-45927 to this
vulnerability.
โ˜ โ˜† โœ‡ Full Disclosure

null pointer deference in gnome gtk via parse_settings() at xsettings-client.c

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
gnome gtk ac60bc60 was discovered to contain a segmentation violation via the function parse_settings() at
xsettings-client.c.

[VulnerabilityType Other]
null pointer deference

[Vendor of Product]
gnome

[Affected Product Code Base]
gtk - ac60bc60

[Reference]
https://gitlab.gnome.org/GNOME/gtk/-/issues/5983

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name...
โ˜ โ˜† โœ‡ Full Disclosure

NULL pointer dereference in freedesktop Mesa via check_xshm()

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
freedesktop Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function check_xshm().

[Vulnerability Type]
NULL pointer dereference

[Vendor of Product]
freedesktop

[Affected Product Code Base]
Mesa - 23.0.4

[Reference]
https://gitlab.freedesktop.org/mesa/mesa/-/issues/9859

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-45931 to...
โ˜ โ˜† โœ‡ Full Disclosure

null pointer deference in nano via read_the_list()

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
Nano v6.2 was discovered to contain a segmentation violation via the function read_the_list().

[VulnerabilityType Other]
null pointer deference

[Vendor of Product]
nano

[Affected Product Code Base]
nano - 6.2

[Reference]
https://savannah.gnu.org/bugs/index.php?64465

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-45932 to this
vulnerability.
โ˜ โ˜† โœ‡ Full Disclosure

SEGV in S-Lang via fixup_tgetstr()

January 26th 2024 at 15:11

Posted by Meng Ruijie on Jan 26

[Vulnerability description]
S-Lang v2.3.2 was discovered to contain a SEGV via the function fixup_tgetstr().

[VulnerabilityType Other]
SEGV

[Vendor of Product]
S-Lang

[Affected Product Code Base]
S-Lang - 2.3.2

[Reference]
http://lists.jedsoft.org/lists/slang-users/2023/0000002.html

[CVE Reference]
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-45929 to this
vulnerability.
โŒ