SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.
GoAhead WebServer Multiple Cross Site Scripting Vulnerabilities
CVE Research
GoAhead WebServer Multiple Cross Site Scripting Vulnerabilities
SecPod Research Team member (Prabhu S Angadi) has found Multiple Cross-Site Scripting Vulnerabilities in GoAhead WebServer. The vulnerability is caused by improper validation of input to ‘name’ & ‘address’ parameters in /goform/formTest page. This may allow an attacker to steal cookie-based authenti...
Apache ActiveMQ Source Code Disclosure Vulnerability
CVE Research
Apache ActiveMQ Source Code Disclosure Vulnerability
SecPod Research Team member (Veerendra G.G) has found information disclosure vulnerability in Apache ActiveMQ. The flaws are caused due to input validation errors while processing URL, which can be exploited to view the source code of a visited page and leads to further attacks.
S40 Content Management System (CMS) v0.4.2 beta Cross-Site Scripting Vulnerability
CVE Research
S40 Content Management System (CMS) v0.4.2 beta Cross-Site Scripting Vulnerability
SecPod Research Team member (Antu Sanadi) has found a cross-site scripting vulnerability in S40 Content Management System (CMS). Input passed via the ‘gsearchfield’ parameter in ‘index.php’ is not properly verified before it is returned to the user. This may allow an attacker to steal cookie-based a...
appRain Quick Start Edition Core Edition Multiple Persistence Cross-Site Scripting Vulnerabilities.
CVE Research
appRain Quick Start Edition Core Edition Multiple Persistence Cross-Site Scripting Vulnerabilities.
SecPod Research Team member (Antu Sanadi) has found multiple persistence cross-site scripting vulnerabilities in appRain Quick Start Edition Core Edition. The vulnerability is caused by improper validation of various parameters. This may allow an attacker to steal cookie-based authentications or inj...
Pecio CMS Cross-Site scripting Vulnerability
CVE Research
Pecio CMS Cross-Site scripting Vulnerability
Folks, SecPod Research Team member (Antu Sanadi) found persistent XSS flaw in Pecio CMS, which can be used to gain sensitive information and launch further attacks. The flaw lies in search parameters while the web Application processes the user-supplied input and renders the content back to the clie...
Remote OpenVAS check for MS09-050
MS08-067 (Conficker worm) detection – OpenVAS plugin
CVE Research
MS08-067 (Conficker worm) detection – OpenVAS plugin
Conficker worm variants A, B and C are dependent on vulnerability in Microsoft server service. Microsoft had released an advisory MS08-067 back in October 2008 to address the above vulnerability. As was expected at that time, number of attacks are spreading, major one being Conficker worm via the co...
Exploit Shield
CVE Research
Exploit Shield
In the arena of computer security and exploitation world, we come across many security tools. Some of them are quite useful; for some, you have to plug them in and out in a few days. However, the antivirus company F-Secure developed an application called Exploit Shield, which is mainly prioritizing ...
Microsoft Bulletins Plugins – Jul09
