SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.
Apache Struts Multiple Persistence Cross-Site Scripting Vulnerabilities
CVE Research
Apache Struts Multiple Persistence Cross-Site Scripting Vulnerabilities
SecPod Research Team member (Antu Sanadi) has found Multiple Persistence Cross-Site Scripting in Apache Struts Vulnerabilities. The vulnerability is caused by improper validation of various parameters in multiple pages. This may allow an attacker to steal cookie-based authentication credentials or i...
NetSarang Xlpd Printer Daemon Denial of Service Vulnerability
CVE Research
NetSarang Xlpd Printer Daemon Denial of Service Vulnerability
SecPod Research Team member (Prabhu S Angadi) has found Denial of Service Vulnerability in NetSarang Xlpd Printer Daemon. The vulnerability is caused due to improper validation of malicious LPD request sent to printer daemon. The flaw can be exploited to crash the service.
Oxide Webserver Remote Denial of Service Vulnerability
CVE Research
Oxide Webserver Remote Denial of Service Vulnerability
SecPod Research Team member (Antu Sanadi) has found a Denial Of Service Vulnerability in Oxide Webserver. The vulnerability is caused by an error in handling some crafted characters in HTTP GET requests, which allows remote attackers to crash the service.
Netmechanica NetDecision Traffic Grapher Server Information Disclosure Vulnerability
CVE Research
Netmechanica NetDecision Traffic Grapher Server Information Disclosure Vulnerability
SecPod Research Team member (Prabhu S Angadi) has found Information Disclosure Vulnerability in Netmechanica NetDecision Traffic Grapher Server. The vulnerability is caused due to improper validation of malicious HTTP GET request to Traffic Grapher Server ‘default.nd’ with invalid HTTP version numbe...
JAMWiki ‘num’ Parameter Cross Site Scripting Vulnerability
CVE Research
JAMWiki ‘num’ Parameter Cross Site Scripting Vulnerability
SecPod Research Team member (Sooraj K.S) has found Cross-Site Scripting Vulnerabilities in JAMWiki. The vulnerability is caused by improper validation of “num” parameter in “Special:AllPages” pages. This may allow an attacker to steal cookie-based authentication credentials or inject arbitrary HTML ...
OfficeSIP Server Denial Of Service Vulnerability
CVE Research
OfficeSIP Server Denial Of Service Vulnerability
SecPod Research Team member (Prabhu S Angadi) has found Denial Of Service Vulnerability in OfficeSIP Server. The vulnerability is caused due to improper validation of SIP/SIPS URI in the ‘To’ header of the request. The flaw can be exploited to crash the service.
ArticleSetup Multiple Persistence Cross-Site Scripting and SQL Injection Vulnerabilities
CVE Research
ArticleSetup Multiple Persistence Cross-Site Scripting and SQL Injection Vulnerabilities
SecPod Research Team member (Antu Sanadi) has found Multiple Persistence Cross-Site Scripting and SQL Injection Vulnerabilities in ArticleSetup. The vulnerability is caused by improper validation of various parameters in multiple pages. This may allow an attacker to steal cookie-based authentication...
Netmechanica NetDecision Dashboard Server Information Disclosure Vulnerability
CVE Research
Netmechanica NetDecision Dashboard Server Information Disclosure Vulnerability
SecPod Research Team member (Prabhu S Angadi) has found Information Disclosure Vulnerability in Netmechanica NetDecision Dashboard Server. The vulnerability is caused due to improper validation of malicious HTTP requests to the Dashboard server appended with ‘?’ character, which discloses the Dashbo...
Adiscon LogAnalyzer ‘highlight’ Parameter Cross Site Scripting Vulnerability
CVE Research
Adiscon LogAnalyzer ‘highlight’ Parameter Cross Site Scripting Vulnerability
SecPod Research Team member (Sooraj K.S) has found Cross-Site Scripting Vulnerabilities in Adiscon LogAnalyzer. The vulnerability is caused by improper validation of “highlight” parameter in “index.php”. This may allow an attacker to steal cookie-based authentication credentials or inject arbitrary ...
