The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the application programmable interface (API). An attacker could log in using account credentials available through a request generated by an internal user and then manipulate the visitor-id within the web API to access the personal data of other users. There is no limit on the number of requests that can be made to the HID SAFE Web Server, so an attacker…
By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account.
The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.
Before importing a project into Vuforia, a user could modify the “resourceDirectory� attribute in the appConfig.json file to be a different path.
A user could use the “Upload Resource� functionality to upload files to any location on the disk.
An attacker with local access to the machine could record the traffic, which could allow them to resend requests without the server authenticating that the user or session are valid.
Ноутбуки есть вероятно, у большинства читателей Хабра. Кто-то привык работать с ноутбуком без дополнительных экранов, кто-то подключает 1, 2 и больше дисплеев. Ну а кто-то покупает устройство с дополнительными экранами. Такие устройства есть, их нельзя назвать очень уж распространенными, но все же они продаются. О них сегодня и поговорим. Читать дальше →
SABnzbd is an open source automated Usenet download tool. A design flaw was discovered in SABnzbd that could allow remote code execution. Manipulating the Parameters setting in the Notification Script functionality allows code execution with the privileges of the SABnzbd process. Exploiting the vulnerabilities requires access to the web interface. Remote exploitation is possible if users[exposed their setup to the internet or other untrusted networks without setting a username/password. By default SABnzbd…
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could allow a privileged user to obtain highly sensitive information by enabling debug mode. IBM X-Force ID: 257104.
RenderDoc through 1.26 allows an Integer Overflow with a resultant Buffer Overflow (issue 1 of 2).