RecoverPoint’s virtual appliance can be accessible via SSH with the default credentials of boxmgmt:boxmgmt; during testing, no password change option was found. Using these credentials, it’s possible to escape the management interface via command injection to drop into a shell and further take advantage of sudo privileged operations to read arbitrary files as root. It also may also be possible to execute arbitrary os commands as root, but this was not confirmed.
Continue reading SSD Advisory – EMC RecoverPoint for Virtual Machines (VMs) Restriction Bypass
Infinite Automation Systems is headquartered in Lafayette, Colorado.
The affected product, Mango Automation, is a centralized web-based SCADA/HMI and data acquisition software. According to Infinite Automation Systems, Mango Automation is deployed across several sectors including Commercial Facilities, Critical Manufacturing, Food and Agriculture, and Energy. Infinite Automation Systems estimates that these products are used worldwide.
Mango Automation version 2.5.0 through Version 2.6.0 beta (builds prior to 430)
Improper verification of uploaded image files allows arbitrary files to be uploaded, which may allow for the execution of malicious JSP script files. In addition, the application does not verify HTTP requests, causing it to be vulnerable to a cross site scripting vulnerability.
Continue reading SSD Advisory – Infinite Automation Systems Mango Cross Site Scripting and Arbitrary File Upload
A vulnerability in the way invoices are handled by eBay allows users that sell items on eBay to view other’s reseller’s invoices. Though access to the invoice is somewhat arbitrary, there is no easy way to find a specific invoice of a specific seller, it is possible to harvest a large amount of invoice and gather sensitive information from them. This information includes (though not in all invoices):
Continue reading SSD Advisory – eBay Arbitrary Invoice Disclosure
MediaWiki is a free software open source wiki package written in PHP, originally for use on Wikipedia. It is now also used by several other projects of the non-profit Wikimedia Foundation and by many other wikis, including this website, the home of MediaWiki.
Media Wiki version 1.24.1
The vulnerability has been addressed in Media Wiki version 1.24.2.
Continue reading SSD Advisory – Media Wiki SVG XSS