Published Vulnerabilities

Thu
12
Feb

Pandora FMS v5.1 SP1 starts to fix SQL Injection Vulnerability

Pandora FMS v5.1 SP1 starts to fix SQL Injection Vulnerability

The vulnerability laboratory research team discovered during the week a sql injection vulnerability in the pandora fms v5.1 sp1 monitoring web-application. The severity of the vulnerability is high. Pandora FMS is a monitoring web-application by artica.

The vulnerability is located in the offset value of the index list context module. Remote attackers and low privileged application user accounts are able to execute own sql commands via GET method request. The attacker can prepare a request through the `agentes` module to inject own sql commands on the affected web-application dbms.

Fri
30
Jan

Glibc Ghost Vulnerability (CVE-2015-0235) - How to Secure ?

Glibc Ghost Vulnerability (CVE-2015-0235) - How to Secure ?

The security researcher and analyst of Akati Consulting Pvt Ltd  (Rajivarnan R.) discovered a prevention white-paper that explains the impact of the Glibc (Linux) Ghost Vulnerability.

[CVE-ID 2015-0235]

A Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST." The GHOST vulnerability is a serious weakness in the Linux glibc library. It allows attackers to remotely take complete control of the victim system without having any prior knowledge of system credentials. CVE-2015-0235 has been assigned to this issue.

Pages

Subscribe to RSS - Published Vulnerabilities