CVE-2016-5068
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests.
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests.
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 have weak passwords for admin, rauser, sconsole, and user.
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Hayes AT command injection.
Netikus EventSentry before 3.2.1.44 has XSS via SNMP.
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script. Versions before 8.5.12G might be affected in non-default configurations.
Opmantek NMIS before 8.5.12G has XSS via SNMP.
A was asked if I could share the files of my last diary entry: text-align:left”>You can find the files on my”>site here. And to teach you how to fish :-), here are the commands I used to produce these lists: margin-right:0px”>csv-cut.py -s t 1 emd.txt text-align:left”>My csv tools can be found on my text-align:left”>My assumption …
Read more “Domain Whitelisting With Alexa and Umbrella Lists – update, (Sun, Apr 9th)”
A was asked if I could share the files of my last diary entry: Domain Whitelisting With Alexa and Umbrella Lists. You can find the files on my site here. And to teach you how to fish :-), here are the commands I used to produce these lists: csv-cut.py -s t 1 emd.txt blacklist.txt csv-lookup.py …
Read more “Domain Whitelisting With Alexa and Umbrella Lists – update, (Sun, Apr 9th)”
LibTIFF 4.0.7 has an “outside the range of representable values of type short” undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.