VU#706359: Aternity version 9 vulnerable to cross-site scripting and remote code execution

The Aternity webserver,version 9 and prior,is reportedly vulnerable to cross-site scripting(XSS)on several web pages,and remote code execution via inclusion of untrusted functionality by default due to improper authentication before execution. Continue reading VU#706359: Aternity version 9 vulnerable to cross-site scripting and remote code execution

VU#667480: AVer Information EH6108H+ hybrid DVR contains multiple vulnerabilities

AVer Information EH6108H+hybrid DVR,version X9.03.24.00.07l and possibly earlier,reportedly contains multiple vulnerabilities,including undocumented privileged accounts,authentication bypass,and information exposure. Continue reading VU#667480: AVer Information EH6108H+ hybrid DVR contains multiple vulnerabilities

VU#619767: Open Dental uses blank database password by default

Open Dental is medical dental records management software. Open Dental version 16.1,and previous versions,installs with a blank root database(MySQL)password by default.. An attacker with network access to an Open Dental MySQL database could read,modify,or delete data. This Vulnerability Note initially,and incorrectly,stated that Open Dental used hard coded credentials. The Impact section also implied that in its default configuration,the Open Dental database was available over remote networks such as the internet. An Open Dental database would need to be specifically configured to allow remote network access. Continue reading VU#619767: Open Dental uses blank database password by default

VU#294272: ReadyDesk contains multiple vulnerabilities

ReadyDesk,version 9.1 and possibly others,contains SQL injection,path traversal,hard-coded cryptographic key,and arbitrary file upload vulnerabilities that may be leveraged to expose sensitive data and execute arbitrary code in the context of the vulnerable software. Continue reading VU#294272: ReadyDesk contains multiple vulnerabilities

VU#905344: HTTP CONNECT and 407 Proxy Authentication Required messages are not integrity protected

HTTP CONNECT requests and 407 Proxy Authentication Required messages are not integrity protected and are susceptible to man-in-the-middle attacks. WebKit-based applications are additionally vulnerable to arbitrary HTML markup and JavaScript execution in the context of the originally requested domain. Continue reading VU#905344: HTTP CONNECT and 407 Proxy Authentication Required messages are not integrity protected