The goal of this project is to make virtual world a safer and better place without child pornography, major computer crime and RIAA.
Login As
You can log in if you are registered at one of these services:
Security Bulletins
Latest Malware Updates

Infostealer.Posteal

02/26/2015

Downloader.Busadom

02/26/2015

Trojan.Ladocosm

02/26/2015

SONAR.SuspDocRun

02/25/2015

SONAR.SuspHelpRun

02/25/2015
07/13/2013

BMC Service Desk Express 10.2.1.95 - Multiple Vulnerabilities

Classification: NON SENSITIVE INFORMATION RELEASABLE TO THE PUBLIC

Multiple vulnerabilities in BMC SERVICE DESK EXPRESS (SDE) Version
10.2.1.95

Affected Product:
BMC SERVICE DESK EXPRESS (SDE) Version 10.2.1.95

Timeline:
07 June 2013      - Vulnerability found
12 June 2013      - Vendor informed
17 June 2013      - Vendor replied/confirmed & opened service ticket

Credits:
Nuri Fattah   of NATO / NCIRC (www.ncirc.nato.int)

CVE: To be assigned

NCIRC ID: NCIRC-2013127-02

Description:
Multiple vulnerabilities, including Cross-Site Scripting(XSS) and SQL
injection were identified in the latest version of BMC SERVICE DESK
EXPRESS

Vulnerability Details:

1. SQL injection
a. /SDE/DashBoardGUI.aspx
vuln parameter: [ASPSESSIONIDASSRATTQ cookie]

b. /SDE/DashBoardGUI.aspx
vuln parameter: [TABLE_WIDGET_1 cookie]
c. /SDE/DashBoardGUI.aspx
vuln parameter: [TABLE_WIDGET_2 cookie]
d. SDE/DashBoardGUI.aspx
vuln parameter: [browserDateTimeInfo cookie]
e. /SDE/DashBoardGUI.aspx
vuln parameter: [browserNumberInfo cookie]
f. /SDE/login.aspx
vuln parameter: [UID]

2. Reflected XSS
a. /SDE/QV_admin.aspx
vuln parameter: [SelTab]
b. /SDE/QV_grid.aspx
vuln parameter: [CallBack]
c. /SDE/commonhelp.aspx
vuln parameter: [HelpPage]

example:
GET
/SDE/QV_grid.aspx?QuerySeq=1068&CondVal=1%40V1%40ADMINISTRATION%401&Call
Back=parent.parent.frames.TmInputs.callBack(doGridDataCallBack.arguments
[0]);</script><script>alert(99817)</script>&ViewType=g&bRefresh=
HTTP/1.1

Solution:
No Solution has yet been provided.
Please contact the vendor.

Security Advisories Database

Remote Code Execution Vulnerability in Microsoft OpenType Font Driver

A remote attacker can execute arbitrary code on the target system.

07/21/2015

SQL Injection Vulnerability in Piwigo

SQL inection vulnerability has been discovered in Piwigo.

02/05/2015

Cross-site Scripting Vulnerability in DotNetNuke

A cross-site scripting (XSS) vulnerability has been discovered in DotNetNuke.

02/05/2015

Cross-site Scripting Vulnerability in Hitachi Command Suite

A cross-site scripting vulnerability was found in Hitachi Command Suite.

02/02/2015

Denial of service vulnerability in FreeBSD SCTP RE_CONFIG Chunk Handling

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Apache Traffic Server HTTP TRACE Max-Forwards

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in MalwareBytes Anti-Exploit &quot;mbae.sys&quot;

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Linux Kernel splice

An attacker can perform a denial of service attack.

01/29/2015

Denial of service vulnerability in Python Pillow Module PNG Text Chunks Decompression

An attacker can perform a denial of service attack.

01/20/2015