-
CVE-2019-9020 PHP xmlrpc_decode() Function Invalid Memory Access Vulnerability – 27th Feb 2019
Preface: xmlrpc_decode — Decodes XML into native PHP types Vulnerability detail: The vulnerability is due to improper input validation by the xmlrpc_decode() function of the affected software. Impact: A successful exploit could cause a heap out-of-bounds read or read-after-free condition, which could result in a complete system compromise. Remedy: PHP has released software updates at…
-
CVE-2019-1663 Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability – 27th Feb 2019
Preface: Huge rise in hack attacks as cyber-criminals target small businesses. For the Average Hacker, Your Small Business Is an Ideal Target . Vulnerability detail: Improper Restriction of Operations within the Bounds of a Memory Buffer. And therefore causes vulnerability encounter on Management Interface to trigger Remote Command Execution. Don’t become a botnet soldier! Cisco…
-
Critical PHP vulnerability alert – 27th Feb 2019! CVE-2019-9025 CVE-2019-9023
Preface: As of December 2017, PHP makes up over 83% of server side languages used on the internet. As of today, PHP looks running strong because a large amount of users, applications and also legacy applications. Vulnerability Details: CVE-2019-9025: PHP mb_split() Function Invalid Multibyte String Vulnerability Impact: A successful exploit could cause buffer over-read and…
-
Padding oracle в OpenSSL vulnerability – Stay alert! 26th Feb 2019
CVE ID: CVE-2019-1559 Operation vector: Remote Impact: Security restrictions bypass Vulnerable versions: OpenSSL version 1.0.2q, 1.0.2p, 1.0.2o, 1.0.2n, 1.0.2m, 1.0.2l, 1.0.2k, 1.0.2j, 1.0.2i, 1.0.2g, 1.0.2f, 1.0.2e, 1.0.2d, 1.0.2c, 1.0.2b, 1.0.2a, 1.0.2, 1.0.2h Official announcement: https://www.openssl.org/news/secadv/20190226.txt
-
Public safety: CVE-2019-9019 The design weakness of seat-back entertainment system in British Airway.
Preface: Linux-based airline seat-back entertainment system won the market since 2007. Background: Seat back entertainment system including Wi-Fi, movies and television shows, games and music. Some of it is built into an airline’s fleet, and some have options where you can bring your own devices and access in-flight entertainment options. Vulnerability details: A buffer overflow…
-
Have you heard Nazi Bell? World War II Secret weapon.
Preface: We heard close encounter of the 3rd kind. But tons of news report that people discovered UFO in the sky. Historical background: 1942, over Los Angeles, California.Initially, the target of the aerial barrage was thought to be an attacking force from Japan, but Secretary of the Navy Frank Knox, speaking at a press conference…
-
Splunk Web in Splunk has Persistent XSS Vulnerability – CVE-2019-5727
Splunk Web in Splunk Enterprise 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x before 6.1.14, and 6.0.x before 6.0.15 and Splunk Light before 6.6.0 has Persistent XSS Vulnerability – CVE-2019-5727 NVD Published Date: 02/20/2019 Preface: SIEM can enforce your cyber security protection meanwhile it is the potential target by hacker.…
-
ISC Releases security updates for Bind – Feb 2019
Preface: The Domain Name System (DNS) was standardized 30 years ago by IETF (RFC1034 and RFC1035). An additional standard, EDNS (RFC2671) was published in 1999 and updated in 2013 (RFC6891). Synopsis: As time goes by, EDNS, gained importance with the wide deployment of DNSSEC, among others, which has become an essential part of the DNS…
-
CVE-2019-7164 SQLAlchemy order_by Parameter SQL Injection Vulnerability – Feb 2019
Preface: SQLAlchemy is an open-source SQL toolkit and object-relational mapper (ORM) for the Python programming language released under the MIT License. Who is their customer? SQLAlchemy is used by organizations such as: Yelp! reddit DropBox The OpenStack Project Survey Monkey Modern programming languages are almost all object-oriented. While most object-oriented languages offer developer benefits such…
-
Microsoft IIS web server design weakness – causes resources exhaustion (20th Feb 2019)
Preface: Many companies do not plan to use the Microsoft IIS web server until MS SharePoint is born. MS SharePoint baseline design: If you decide to use SharePoint, IIS web server will be work with you forever. Indeed that SharePoint products are popular. And such away let people forget about IIS web server weakness. Perhaps…