Published Vulnerabilities

Fri
22
Aug

Web Security Flex v4.x (BNSEC707) - Filter Bypass & Persistent Vulnerabilities

Filter Bypass & Persistent Vulnerabilities in Shared Secret & Bypass Password patched!

Barracuda Networks announced a patch in the official web security flex appliance web-application. The two security issues has been reported by the vulnerability laboratory team. Barracuda has already resolved the issues and will soon publish a final security bulletin which will be connected to our advisory.

Wed
04
Jun

Local Command Inject Vulnerability discovered in iScan Online Mobile v2.0.1 (iOS)

Local Command Inject Vulnerability discovered in iScan Online Mobile v2.0.1 (iOS - Apple)

Yesterday the Vulnerability Laboratory Research Team discovered a local command inject web vulnerability in the official IScan Online Mobile v2.0.1 iOS web-application.

The iscan software checks if your iOS device has been jailbroken, scans standard apps for manipulation, misconfigurations, makes a proof of the firmware version.

The vulnerability is located in the vulnerable `devicename` value of the `Settings` module. Local attackers are able to inject own malicious system specific commands or path value requests in the vulnerable `devicename` value. The execution of the local command inject occurs in the `Device Settings` module of the iscan online mobile application.

Pages

Subscribe to RSS - Published Vulnerabilities