CXSECURITY Database RSS Feed - CXSecurity.com https://cxsecurity.com/wlb/ CXSECURITY Database RSS Feed - World Laboratory of Bugtraq 2 CXSecurity.com en-US Wed, 27 Nov 2024 18:24:25 +0000 CXSecurity CXSecurity: World Laboratory of Bugtraq 2 https://cxsecurity.com/wlb/rss/all/ https://cxsecurity.com/images/wlb/wlblogo.png CXSECURITY Database RSS Feed - World Laboratory of Bugtraq 2 (WLB2) Linux 6.6 Race Condition https://cxsecurity.com/issue/WLB-2024110041 WLB-2024110041 2024-11-25 22:05:28 CET Jann Horn Topic: Linux 6.6 Race Condition Risk: Medium Text:Summary I found a security-relevant race between mremap() and THP code. Reaching the buggy code typically requires the abili... Mon, 25 Nov 2024 22:05:28 +0000 fronsetia 1.1 XML Injection https://cxsecurity.com/issue/WLB-2024110040 WLB-2024110040 2024-11-25 22:05:14 CET Andrey Stoykov Topic: fronsetia 1.1 XML Injection Risk: Medium Text:# Exploit Title: XXE OOB - fronsetiav1.1 # Date: 11/2024 # Exploit Author: Andrey Stoykov # Version: 1.1 # Tested on: Debia... Mon, 25 Nov 2024 22:05:14 +0000 fronsetia 1.1 Cross Site Scripting https://cxsecurity.com/issue/WLB-2024110039 WLB-2024110039 2024-11-25 22:04:53 CET Andrey Stoykov Topic: fronsetia 1.1 Cross Site Scripting Risk: Low Text:# Exploit Title: Reflected XSS - fronsetiav1.1 # Date: 11/2024 # Exploit Author: Andrey Stoykov # Version: 1.1 # Tested on:... Mon, 25 Nov 2024 22:04:53 +0000 Kyptronix LLP - Sql Injection https://cxsecurity.com/issue/WLB-2024110038 WLB-2024110038 2024-11-25 22:04:42 CET behrouz mansoori Topic: Kyptronix LLP - Sql Injection Risk: Medium Text:********************************************************* #Exploit Title: Kyptronix LLP - Sql Injection #Date: 2024-11-22 #E... Mon, 25 Nov 2024 22:04:42 +0000 Kyptronix LLP - Blind Sql Injection Vulnerability https://cxsecurity.com/issue/WLB-2024110037 WLB-2024110037 2024-11-25 22:04:20 CET behrouz mansoori Topic: Kyptronix LLP - Blind Sql Injection Vulnerability Risk: Medium Text:********************************************************* #Exploit Title: Kyptronix LLP - Blind Sql Injection Vulnerability #... Mon, 25 Nov 2024 22:04:20 +0000 Korenix JetPort 5601 1.2 Path Traversal https://cxsecurity.com/issue/WLB-2024110036 WLB-2024110036 2024-11-25 22:03:58 CET Hierzer Topic: Korenix JetPort 5601 1.2 Path Traversal Risk: Medium Text:St. Plten UAS 20241118-1 - title| Path Traversal product| Korenix Je... Mon, 25 Nov 2024 22:03:57 +0000 Apple Web Content Filter Bypass https://cxsecurity.com/issue/WLB-2024110035 WLB-2024110035 2024-11-25 22:03:34 CET Nosebeard Topic: Apple Web Content Filter Bypass Risk: Low Text:Dear colleagues, Nosebeard Labs is pleased to share its latest advisory, detailing a bypass of Apple's system wide web con... Mon, 25 Nov 2024 22:03:34 +0000 Microsoft Windows Defender TrojanWin32Powessere.G / Detection Mitigation Bypass https://cxsecurity.com/issue/WLB-2024110034 WLB-2024110034 2024-11-18 16:25:19 CET hyp3rlinx Topic: Microsoft Windows Defender TrojanWin32Powessere.G / Detection Mitigation Bypass Risk: High Text:Another trivial Windows Defender TrojanWin32Powessere.G Detection Mitigation Bypass C:Usersgg>rundll32.exe javascript:"..m... Mon, 18 Nov 2024 16:25:19 +0000 © 2024 Human Resource Management-1.0-HRM-1.0 Cross-site scripting (reflected) https://cxsecurity.com/issue/WLB-2024110033 WLB-2024110033 2024-11-18 16:25:05 CET nu11secur1ty Topic: © 2024 Human Resource Management-1.0-HRM-1.0 Cross-site scripting (reflected) Risk: Low Text:## Titles: © 2024 Human Resource Management-1.0-HRM-1.0 Cross-site scripting (reflected) ## Author: nu11secur1ty ## Date: 1... Mon, 18 Nov 2024 16:25:05 +0000 Blue sun info - Blind Sql Injection Vulnerability https://cxsecurity.com/issue/WLB-2024110032 WLB-2024110032 2024-11-18 16:24:37 CET behrouz mansoori Topic: Blue sun info - Blind Sql Injection Vulnerability Risk: Medium Text:********************************************************* #Exploit Title: Blue sun info - Blind Sql Injection Vulnerability #... Mon, 18 Nov 2024 16:24:34 +0000 Pyload Remote Code Execution https://cxsecurity.com/issue/WLB-2024110031 WLB-2024110031 2024-11-18 16:23:56 CET Spencer McIntyre Topic: Pyload Remote Code Execution Risk: High Text:## # This module requires Metasploit: https://metasploit.com/download # Current source: https://github.com/rapid7/metasploit-... Mon, 18 Nov 2024 16:23:55 +0000 Heatmiser Wifi Thermostat 1.7 - Cross-Site Request Forgery https://cxsecurity.com/issue/WLB-2024110030 WLB-2024110030 2024-11-17 21:31:18 CET parsa rezaie khiabanloo Topic: Heatmiser Wifi Thermostat 1.7 - Cross-Site Request Forgery Risk: Low Text:# Exploit Title: Heatmiser Wifi Thermostat 1.7 - Cross-Site Request Forgery ( CSRF ) # Dork: intitle:"Heatmiser Wifi Thermosta... Sun, 17 Nov 2024 21:31:18 +0000 Calibre-web 0.6.21 Stored XSS https://cxsecurity.com/issue/WLB-2024110029 WLB-2024110029 2024-11-17 21:30:50 CET Pentest-Tools Topic: Calibre-web 0.6.21 Stored XSS Risk: Low Text:# Exploit Title: Stored XSS in Calibre-web # Date: 07/05/2024 # Exploit Authors: Pentest-Tools.com (Catalin Iovita & Alexandr... Sun, 17 Nov 2024 21:30:50 +0000 SOPlanning 1.52.01 (Simple Online Planning Tool) Remote Code Execution (RCE) (Authenticated) https://cxsecurity.com/issue/WLB-2024110028 WLB-2024110028 2024-11-17 21:30:26 CET Ardayfio Samuel Nii Aryee Topic: SOPlanning 1.52.01 (Simple Online Planning Tool) Remote Code Execution (RCE) (Authenticated) Risk: High Text:# Exploit Title: SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (RCE) (Authenticated) # Date: 6th Oc... Sun, 17 Nov 2024 21:30:26 +0000 Proteus Home P1B - Default Password and Broken Access Control https://cxsecurity.com/issue/WLB-2024110027 WLB-2024110027 2024-11-17 21:30:04 CET parsa rezaie khiabanloo Topic: Proteus Home P1B - Default Password and Broken Access Control Risk: Medium Text:# Exploit Title: Proteus Home P1B - Default Password and Broken Access Control # Date: 11/15/2024 # Exploit Author: parsa rez... Sun, 17 Nov 2024 21:30:04 +0000 EXPLOIT FINDER WordPress User Enumeration https://cxsecurity.com/issue/WLB-2024110026 WLB-2024110026 2024-11-17 21:29:53 CET E1.Coders Topic: EXPLOIT FINDER WordPress User Enumeration Risk: Low Text:With this code, you can search Google and isolate the sites that have this security issue and test which ones have the WP JSON/... Sun, 17 Nov 2024 21:29:53 +0000 Proteus Home P1B - Default Password and Broken Access Control https://cxsecurity.com/issue/WLB-2024110025 WLB-2024110025 2024-11-17 21:29:36 CET parsa rezaie khiabanloo Topic: Proteus Home P1B - Default Password and Broken Access Control Risk: Medium Text:# Exploit Title: Proteus Home P1B - Default Password and Broken Access Control # Date: 11/16/2024 # Exploit Author: parsa rez... Sun, 17 Nov 2024 21:29:36 +0000 OmenTec Proteus Home P1B - Default Password and Broken Access Control https://cxsecurity.com/issue/WLB-2024110024 WLB-2024110024 2024-11-17 21:29:10 CET parsa rezaie khiabanloo Topic: OmenTec Proteus Home P1B - Default Password and Broken Access Control Risk: Medium Text:# Exploit Title: OmenTec Proteus Home P1B - Default Password and Broken Access Control # Date: 11/15/2024 # Exploit Author: p... Sun, 17 Nov 2024 21:28:39 +0000 © 2024 Human Resource Management-1.0-HRM-1.0 Multiple-SQLi https://cxsecurity.com/issue/WLB-2024110023 WLB-2024110023 2024-11-14 21:41:59 CET nu11secur1ty Topic: © 2024 Human Resource Management-1.0-HRM-1.0 Multiple-SQLi Risk: High Text:## Titles: © 2024 Human Resource Management-1.0-HRM-1.0 Multiple-SQLi ## Author: nu11secur1ty ## Date: 11/13/2024 ## Vendo... Thu, 14 Nov 2024 21:41:59 +0000 TX Text Control .NET Server For ASP.NET Arbitrary File Read / Write https://cxsecurity.com/issue/WLB-2024110022 WLB-2024110022 2024-11-14 21:41:37 CET Filip Palian Topic: TX Text Control .NET Server For ASP.NET Arbitrary File Read / Write Risk: Medium Text:Hej, Let's keep it short ... == Intro == A "sudo make me a sandwich" security issue has been identified in... Thu, 14 Nov 2024 21:41:37 +0000 Siemens Energy Omnivise T3000 8.2 SP3 Privilege Escalation / File Download https://cxsecurity.com/issue/WLB-2024110021 WLB-2024110021 2024-11-14 21:41:06 CET Andreas Kolbeck Topic: Siemens Energy Omnivise T3000 8.2 SP3 Privilege Escalation / File Download Risk: Medium Text:SEC Consult Vulnerability Lab Security Advisory < 20241112-0 > == title: Multiple vulner... Thu, 14 Nov 2024 21:41:06 +0000 TestRail CLI FieldsParser eval Injection https://cxsecurity.com/issue/WLB-2024110020 WLB-2024110020 2024-11-12 22:37:42 CET Devin Topic: TestRail CLI FieldsParser eval Injection Risk: Medium Text:This is not a very exciting vulnerability, but I had already publicly disclosed it on GitHub at the request of the vendor. Sin... Tue, 12 Nov 2024 22:37:42 +0000 Positive E Solutions Inc - Sql Injection https://cxsecurity.com/issue/WLB-2024110019 WLB-2024110019 2024-11-12 22:36:58 CET behrouz mansoori Topic: Positive E Solutions Inc - Sql Injection Risk: Medium Text:********************************************************* #Exploit Title: Positive E Solutions Inc - Sql Injection #Date: 202... Tue, 12 Nov 2024 22:36:58 +0000 Positive E Solutions Inc - Blind Sql Injection Vulnerability https://cxsecurity.com/issue/WLB-2024110018 WLB-2024110018 2024-11-12 22:36:45 CET behrouz mansoori Topic: Positive E Solutions Inc - Blind Sql Injection Vulnerability Risk: Medium Text:********************************************************* #Exploit Title: Positive E Solutions Inc - Blind Sql Injection Vulne... Tue, 12 Nov 2024 22:36:45 +0000 Online Complete - Sql Injection https://cxsecurity.com/issue/WLB-2024110017 WLB-2024110017 2024-11-12 22:36:06 CET behrouz mansoori Topic: Online Complete - Sql Injection Risk: Medium Text:********************************************************* #Exploit Title: Online Complete - Sql Injection #Date: 2024-11-12 ... Tue, 12 Nov 2024 22:36:05 +0000 POMS-PHP (by: oretnom23 ) v1.0, Copyright © 2024. All rights reserved - File Upload Vulnerability exploit https://cxsecurity.com/issue/WLB-2024110016 WLB-2024110016 2024-11-11 05:11:33 CET nu11secur1ty Topic: POMS-PHP (by: oretnom23 ) v1.0, Copyright © 2024. All rights reserved - File Upload Vulnerability exploit Risk: High Text:## Titles: POMS-PHP (by: oretnom23 ) v1.0, Copyright © 2024. All rights reserved - File Upload Vulnerability exploit ## Autho... Mon, 11 Nov 2024 05:11:33 +0000 POMS-PHP (by: oretnom23 ) v1.0, Copyright © 2024. All rights reserved - SQLi Bypass Authentication https://cxsecurity.com/issue/WLB-2024110015 WLB-2024110015 2024-11-11 05:10:59 CET nu11secur1ty Topic: POMS-PHP (by: oretnom23 ) v1.0, Copyright © 2024. All rights reserved - SQLi Bypass Authentication Risk: Medium Text:## Titles: POMS-PHP (by: oretnom23 ) v1.0, Copyright © 2024. All rights reserved - SQLi Bypass Authentication ## Author: nu1... Mon, 11 Nov 2024 05:10:59 +0000 WebSenor InfoTech - Blind Sql Injection Vulnerability https://cxsecurity.com/issue/WLB-2024110014 WLB-2024110014 2024-11-11 05:10:44 CET behrouz mansoori Topic: WebSenor InfoTech - Blind Sql Injection Vulnerability Risk: Medium Text:********************************************************* #Exploit Title: WebSenor InfoTech - Blind Sql Injection Vulnerabilit... Mon, 11 Nov 2024 05:10:44 +0000 BALC Media - Sql Injection https://cxsecurity.com/issue/WLB-2024110013 WLB-2024110013 2024-11-11 05:10:22 CET behrouz mansoori Topic: BALC Media - Sql Injection Risk: Medium Text:********************************************************* #Exploit Title: BALC Media - Sql Injection #Date: 2024-11-08 #Expl... Mon, 11 Nov 2024 05:09:37 +0000 WebSenor InfoTech Sql Injection https://cxsecurity.com/issue/WLB-2024110012 WLB-2024110012 2024-11-06 22:21:38 CET behrouz mansoori Topic: WebSenor InfoTech Sql Injection Risk: Medium Text:********************************************************* #Exploit Title: WebSenor InfoTech Sql Injection #Date: 2024-11-04 ... Wed, 06 Nov 2024 22:21:38 +0000 Vibgyor Media Info Solutions - Blind Sql Injection Vulnerability https://cxsecurity.com/issue/WLB-2024110011 WLB-2024110011 2024-11-06 22:21:14 CET behrouz mansoori Topic: Vibgyor Media Info Solutions - Blind Sql Injection Vulnerability Risk: Medium Text:********************************************************* #Exploit Title: Vibgyor Media Info Solutions - Blind Sql Injection V... Wed, 06 Nov 2024 22:21:14 +0000 Vibgyor Media Info Solutions Sql Injection https://cxsecurity.com/issue/WLB-2024110010 WLB-2024110010 2024-11-06 22:20:53 CET behrouz mansoori Topic: Vibgyor Media Info Solutions Sql Injection Risk: Medium Text:********************************************************* #Exploit Title: Vibgyor Media Info Solutions Sql Injection #Date: 2... Wed, 06 Nov 2024 22:20:53 +0000 IBM Security Verify Access Appliance Insecure Transit / Hardcoded Passwords https://cxsecurity.com/issue/WLB-2024110009 WLB-2024110009 2024-11-06 22:20:35 CET Pierre Kim Topic: IBM Security Verify Access Appliance Insecure Transit / Hardcoded Passwords Risk: Low Text: --BEGIN PGP SIGNED MESSAGE -- Hash: SHA512 ## Advisory Information Title: 4 vulnerabilities in ibmsecurity Advisory UR... Wed, 06 Nov 2024 22:20:35 +0000 ESET NOD32 Antivirus 18.0.12.0 Unquoted Service Path https://cxsecurity.com/issue/WLB-2024110008 WLB-2024110008 2024-11-06 22:20:14 CET Milad Karimi Topic: ESET NOD32 Antivirus 18.0.12.0 Unquoted Service Path Risk: Medium Text:# Exploit Title: ESET NOD32 Antivirus 18.0.12.0 - "ESET Service" Unquoted Service Path # Exploit Author: Milad Karimi (Ex3pti... Wed, 06 Nov 2024 22:20:14 +0000 SQLite3 generate_series Stack Buffer Underflow https://cxsecurity.com/issue/WLB-2024110007 WLB-2024110007 2024-11-06 22:19:59 CET Google Security Research Topic: SQLite3 generate_series Stack Buffer Underflow Risk: High Text:Vulnerability details static int seriesBestIndex( sqlite3_vtab *pVTab, sqlite3_index_info *pIdxInfo ){ int i, j; ... Wed, 06 Nov 2024 22:19:59 +0000 ABB Cylon Aspect 3.08.00 Off-By-One https://cxsecurity.com/issue/WLB-2024110006 WLB-2024110006 2024-11-06 22:19:25 CET LiquidWorm Topic: ABB Cylon Aspect 3.08.00 Off-By-One Risk: Low Text:ABB Cylon Aspect 3.08.00 (log(Mix/Yum)Lookup.php) Off-by-One Error in Log Parsing Vendor: ABB Ltd. Product web page: http... Wed, 06 Nov 2024 22:18:41 +0000 Qualitor 8.24 Server-Side Request Forgery https://cxsecurity.com/issue/WLB-2024110005 WLB-2024110005 2024-11-02 22:50:15 CET OpenXP Research Team Topic: Qualitor 8.24 Server-Side Request Forgery Risk: Low Text:# CVE-2024-48360 | Qualitor < = v8.24 Unauthenticated SSRF ## Description Qualitor is a platform for business process mana... Sat, 02 Nov 2024 22:50:14 +0000 Xlibre Xnest 24.1.0 / 24.2.0 Buffer Overflow https://cxsecurity.com/issue/WLB-2024110004 WLB-2024110004 2024-11-02 22:49:43 CET Enrico Weigelt Topic: Xlibre Xnest 24.1.0 / 24.2.0 Buffer Overflow Risk: High Text:XLibre project security advisory As Xlibre Xnest is based on Xorg, it is affected by some security issues whic... Sat, 02 Nov 2024 22:49:42 +0000 SmartAgent 1.1.0 Remote Code Execution https://cxsecurity.com/issue/WLB-2024110003 WLB-2024110003 2024-11-02 22:49:24 CET Alter Prime Topic: SmartAgent 1.1.0 Remote Code Execution Risk: High Text:# Exploit Title: SmartAgent v1.1.0 - Unauthenticated Remote Code Execution # Date: 01-10-2024 # Exploit Author: Alter Prime ... Sat, 02 Nov 2024 22:49:23 +0000 SmartAgent 1.1.0 Server-Side Request Forgery https://cxsecurity.com/issue/WLB-2024110002 WLB-2024110002 2024-11-02 22:49:12 CET Alter Prime Topic: SmartAgent 1.1.0 Server-Side Request Forgery Risk: Low Text:# Exploit Title: SmartAgent v1.1.0 - Server-Side Request Forgery (SSRF) # Date: 01-10-2024 # Exploit Author: Alter Prime # V... Sat, 02 Nov 2024 22:49:10 +0000