Grandstream UCM62xx IP PBX WebSocket Blind SQL Injection Credential Dump

This module uses a blind SQL injection (CVE-2020-5724) affecting the Grandstream UCM62xx IP PBX to dump the users table. The injection occurs over a websocket at the websockify endpoint, and specifica ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

Improper Validation of Certificate with Host Mismatch in mellium.im/xmpp/websocket

If no TLS configuration is provided by the user, the websocket package constructs its own TLS configuration using recommended defaults.Read More ...

Continue Reading
nv-websocket-client allows attackers to spoof SSL/TLS servers via an arbitrary valid certificate

The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which a ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

CVE-2023-23602

A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from insi ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

Apache Tomcat Request Obfuscation Vulnerability

Apache Tomcat is a lightweight Web application server from the Apache Foundation. The application implements support for Servlet and JavaServer Page (JSP).Apache Tomcat suffers from a request obfuscat ...

Continue Reading

CVSS3 - HIGH

CVSS2 - HIGH

nv-websocket-client allows attackers to spoof SSL/TLS servers via an arbitrary valid certificate

The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which a ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - MEDIUM

July 7th 2022 Security Releases

# July 7th 2022 Security Releases By Rafael Gonzaga, 2022-07-07 ## _(Update 07-July-2022)_ Security releases available Updates are now available for the v18.x, v16.x, and v14.x Node.js release lines f ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Nutanix AOS : Multiple Vulnerabilities (NXSA-AOS-5.20.4.5)

The version of AOS installed on the remote host is prior to 5.20.4.5. It is, therefore, affected by multiple vulnerabilities as referenced in the NXSA-AOS-5.20.4.5 advisory. - zlib before 1.2.12 all ...

Continue Reading

Back to Main

Subscribe for the latest news: