Skip to main content

Security Advisories

Stay updated on the latest vulnerability disclosures, CVE tracking, and security advisories affecting enterprise systems and applications.

Latest Security Advisories

Informational May 16, 2010

Huawei EchoLife HG520c Information Disclosure

Huawei EchoLife HG520 modems are vulnerable to an information disclosure vulnerability. Sensitive modem information can be accessed using a public URL in modems with the web interface activated.

Severity:
CVSS: 0.0
View advisory
Informational May 13, 2010

Huawei EchoLife HG520 Remote Information Disclosure

Huawei EchoLife HG520 modems are vulnerable to a remote information disclosure vulnerability. This vulnerability can be exploited by sending a specially crafted UDP packet that causes the modems to return sensitive information in clear text form.

Severity:
CVSS: 0.0
View advisory
Informational May 13, 2010

Huawei EchoLife HG520c Denial of Service & Unauthorized Factory Reset

Huawei EchoLife HG520c modems are vulnerable to unauthorized device reset and denial of service vulnerabilities.

Severity:
CVSS: 0.0
View advisory
Informational May 10, 2010

Croogo CMS 1.3 'Contact' and 'User' Module HTML Injection

Croogo CMS is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input.

Severity:
CVSS: 0.0
View advisory
Informational February 27, 2010

Croogo CMS 1.2 Cross Site Scripting Vulnerabilities

Croogo CMS 1.2 Cross Site Scripting Vulnerabilities

Severity:
CVSS: 0.0
View advisory
Informational November 26, 2009

OPENCONF CE 3.41 MULTIPLE XSS AND SQL

OpenConf CE 3.41 contains multiple Cross-site Scripting vulnerabilities and an SQL injection vulnerability.

Severity:
CVSS: 0.0
View advisory
Informational November 16, 2009

ZenCart 1.3.8a Multiple XSS in Admin Interface

ZenCart 1.3.8a has a persistent XSS in 'Admin Home' in 'Last Name' parameter. Another Cross Site Scripting vulnerability exists in 'nogrants' parameter in sqlpatch.php.

Severity:
CVSS: 0.0
View advisory
Informational November 15, 2009

D-Link WBR-1310 Router is susceptible to XSS, allowing an attacker to change the Admins password...

Severity:
CVSS: 0.0
View advisory
Informational November 1, 2009

2Wire Remote Denial of Service

The remote management interface on tcp/50001 of various 2Wire devices suffer from a remote denial of service vulnerability.

Severity:
CVSS: 0.0
View advisory
Informational October 13, 2009

Commonspot CMS 5.1.0.x Cross Site Scripting vulnerabilities

XSS vulnerabilities in Commonspot CMS

Severity:
CVSS: 0.0
View advisory
Informational October 12, 2009

2Wire Authentication Bypass and Unauthorized Password Reset

Some 2Wire devices are vulnerable to authentication bypass and remote password reset attacks that allow drive by pharming.

Severity:
CVSS: 0.0
View advisory