SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.
Metasploit Module – BisonFTP Server Remote Buffer Overflow Vulnerability
AT-TFTP Server v1.8 Remote Denial of Service Vulnerability
CVE Research
AT-TFTP Server v1.8 Remote Denial of Service Vulnerability
SecPod Research Team member (Antu Sanadi) has found a Denial of Service vulnerability in Allied Telesyn TFTP Server. The vulnerability is caused by an error in the “TFTPD.EXE”, which causes the server to crash when no acknowledgment response is sent back to the server after a successful ‘read’. The ...
Habari Installation Path Disclosure Vulnerability
MYRE Real Estate Software Multiple XSS and SQL Injection Vulnerabilities
CVE Research
MYRE Real Estate Software Multiple XSS and SQL Injection Vulnerabilities
SecPod Research Team member (Sooraj K.S) has found Multiple XSS and SQL Injection Vulnerabilities in MYRE Real Estate Software. The vulnerability is caused by improper validation of various parameters in several pages. This may allow an attacker to steal cookie-based authentication credentials, comp...
GoAhead WebServer Multiple Cross Site Scripting Vulnerabilities
CVE Research
GoAhead WebServer Multiple Cross Site Scripting Vulnerabilities
SecPod Research Team member (Prabhu S Angadi) has found Multiple Cross-Site Scripting Vulnerabilities in GoAhead WebServer. The vulnerability is caused by improper validation of input to ‘name’ & ‘address’ parameters in /goform/formTest page. This may allow an attacker to steal cookie-based authenti...
Apache ActiveMQ Source Code Disclosure Vulnerability
CVE Research
Apache ActiveMQ Source Code Disclosure Vulnerability
SecPod Research Team member (Veerendra G.G) has found information disclosure vulnerability in Apache ActiveMQ. The flaws are caused due to input validation errors while processing URL, which can be exploited to view the source code of a visited page and leads to further attacks.
S40 Content Management System (CMS) v0.4.2 beta Cross-Site Scripting Vulnerability
CVE Research
S40 Content Management System (CMS) v0.4.2 beta Cross-Site Scripting Vulnerability
SecPod Research Team member (Antu Sanadi) has found a cross-site scripting vulnerability in S40 Content Management System (CMS). Input passed via the ‘gsearchfield’ parameter in ‘index.php’ is not properly verified before it is returned to the user. This may allow an attacker to steal cookie-based a...
appRain Quick Start Edition Core Edition Multiple Persistence Cross-Site Scripting Vulnerabilities.
CVE Research
appRain Quick Start Edition Core Edition Multiple Persistence Cross-Site Scripting Vulnerabilities.
SecPod Research Team member (Antu Sanadi) has found multiple persistence cross-site scripting vulnerabilities in appRain Quick Start Edition Core Edition. The vulnerability is caused by improper validation of various parameters. This may allow an attacker to steal cookie-based authentications or inj...
Pecio CMS Cross-Site scripting Vulnerability
CVE Research
Pecio CMS Cross-Site scripting Vulnerability
Folks, SecPod Research Team member (Antu Sanadi) found persistent XSS flaw in Pecio CMS, which can be used to gain sensitive information and launch further attacks. The flaw lies in search parameters while the web Application processes the user-supplied input and renders the content back to the clie...
