Skip to main content

Security Advisories

Stay updated on the latest vulnerability disclosures, CVE tracking, and security advisories affecting enterprise systems and applications.

Latest Security Advisories

Medium May 16, 2010

Huawei EchoLife HG520c Information Disclosure

Huawei EchoLife HG520 modems are vulnerable to an information disclosure vulnerability. Sensitive modem information can be accessed using a public URL in modems with the web interface activated.

Severity:
CVSS: 5.3
View advisory
Medium May 13, 2010

Huawei EchoLife HG520 Remote Information Disclosure

Huawei EchoLife HG520 modems are vulnerable to a remote information disclosure vulnerability. This vulnerability can be exploited by sending a specially crafted UDP packet that causes the modems to return sensitive information in clear text form.

Severity:
CVSS: 5.3
View advisory
High May 13, 2010

Huawei EchoLife HG520c Denial of Service & Unauthorized Factory Reset

Huawei EchoLife HG520c modems expose an unauthenticated factory-reset endpoint and an authenticated remote reboot page, letting an attacker on the LAN or via a malicious website disrupt service and wipe the device configuration.

Severity:
CVSS: 7.7
View advisory
Medium May 10, 2010

Croogo CMS 1.3 'Contact' and 'User' Module HTML Injection

Croogo CMS 1.3 fails to sanitize user-supplied input in the Contact and User modules, letting attackers inject HTML and JavaScript that runs in an administrator's browser and enables session theft or UI redressing.

Severity:
CVSS: 6.1
View advisory
Medium February 27, 2010

Croogo CMS 1.2 Cross Site Scripting Vulnerabilities

Croogo CMS 1.2 stores contact form titles and subjects without sanitisation, allowing an attacker to inject HTML or JavaScript that executes in the administrator's browser when the message is viewed, enabling session theft.

Severity:
CVSS: 6.1
View advisory
High November 26, 2009

OPENCONF CE 3.41 MULTIPLE XSS AND SQL

OpenConf CE 3.41 contains multiple stored and reflected cross-site scripting vulnerabilities and an SQL injection flaw in the conference chair interface, enabling session theft and direct database extraction.

Severity:
CVSS: 8.8
View advisory
Medium November 16, 2009

ZenCart 1.3.8a Multiple XSS in Admin Interface

ZenCart 1.3.8a has a persistent XSS in 'Admin Home' in 'Last Name' parameter. Another Cross Site Scripting vulnerability exists in 'nogrants' parameter in sqlpatch.php.

Severity:
CVSS: 5.4
View advisory
High November 15, 2009

The D-Link WBR-1310 router reflects unsanitised input in its ping diagnostic page. Because the password-change endpoint does not require the current password, the same XSS payload can silently reset the admin credential and take over the router.

Severity:
CVSS: 8.8
View advisory
High November 1, 2009

2Wire Remote Denial of Service

The remote management interface on tcp/50001 of various 2Wire devices suffer from a remote denial of service vulnerability.

Severity:
CVSS: 7.5
View advisory
Medium October 13, 2009

Commonspot CMS 5.1.0.x Cross Site Scripting vulnerabilities

Multiple reflected cross-site scripting vulnerabilities in PaperThin's CommonSpot CMS 5.0 and 5.1, reachable through loader.cfm, let an attacker hijack an administrator session or stage CSRF and phishing attacks against the platform.

Severity:
CVSS: 6.1
View advisory
High October 12, 2009

2Wire Authentication Bypass and Unauthorized Password Reset

Some 2Wire devices are vulnerable to authentication bypass and remote password reset attacks that allow drive-by pharming.

Severity:
CVSS: 8.8
View advisory