<?xml version="1.0" encoding="windows-1251"?>
<rss version="2.0"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:media="http://search.yahoo.com/mrss/">
<channel>
<link>http://dsecrg.com/pages/vul/</link>
<title>Digital Security Research Group: Vulnerabilities</title>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=419</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=419</guid>
<title>vCenter Orchestrator - password disclosure</title>
<description>The vCenter Orchestrator (vCO) Web Configuration tool reflects back saved passwords as part of web page.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=418</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=418</guid>
<title>Oracle Application Server - multiple security vulnerabilities</title>
<description>Oracle Application Server Containers has multiple HTTP Response Splitting vulnerabilities.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=417</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=417</guid>
<title>ASUS Net4Switch ipswcom.dll ActiveX - buffer overflow vulnerability </title>
<description>ASUS Net4Switch contains ActiveX component ipswcom.dll which is vulnerable to buffer overflow attack.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=416</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=416</guid>
<title>SAP MessagingSystem - information disclosure</title>
<description>Information disclosure in MessagingSystem servlet.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=414</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=414</guid>
<title>SAP Internet Sales - XSS</title>
<description>SAP NetWeaver 7.0 Internet Sales (crm.b2b) has XSS vulnerability.
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=415</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=415</guid>
<title>SAP Adapter Monitor - information disclosure</title>
<description>Information disclosure in com.sap.aii.mdt.amt.web.AMTPageProcessor servlet.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=413</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=413</guid>
<title>SAP Application Administration - local file read</title>
<description>SAP NetWeaver 7.0 Application Administration  (com.sap.ipc.webapp.ipc) has local file read vulnerability.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=412</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=412</guid>
<title>SAP NetWeaver Internet Sales - local file read</title>
<description>SAP NetWeaver 7.0 Internet Sales (crm.b2b) has local file read  vulnerability.
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=411</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=411</guid>
<title>SAP NetWeaver Business Communication Broker - multiple XSS</title>
<description>SAP NetWeaver Business Communication Broker has multiple linked XSS vulnerabilies.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=410</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=410</guid>
<title>SAP TesContainerAdmin service - stored XSS</title>
<description>SAP NetWeaver contains a flaw in its Text Container Administration Application - stored XSS vulnerability. &lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=409</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=409</guid>
<title>SAP NetWeaver PFL_CHECK_OS_FILE_EXISTENCE - missing authorization check and SMB Relay vulnerability</title>
<description>Missing authorization check in FRC function PFL_CHECK_OS_FILE_EXISTENCE.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=408</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=408</guid>
<title> SAP NetWeaver RWB - unauthorized ac&#1089;ess</title>
<description>Unauthorized access is possible to some Runtime Workbench resources.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=407</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=407</guid>
<title>Tecomat PLC - Default passwords</title>
<description>Default passwords enabled for Tecomat PLC devices.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=406</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=406</guid>
<title>OPC Systems.NET FlexGrid 7.1 ActiveX - Buffer Overflow</title>
<description>Buffer overflow found in 3rd party ActiveX control.
&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=405</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=405</guid>
<title> wellintech KingSCADA 3.0 - Insecure password encryption</title>
<description>It is possible to obtain cleartext password to access KingSCADA because it is stored insecurely.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=404</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=404</guid>
<title>WAGO PLC 750 - CSRF password change [0-day]</title>
<description>It is possible to change password by forcing administrator to open malicious link.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=403</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=403</guid>
<title>WAGO PLC 750 - information disclosure [0-day]</title>
<description>It is possible to get some information from the PLC web interface without authentication.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=402</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=402</guid>
<title>WAGO PLC 750  - unauthorized firmware download [0-day]</title>
<description>It is possible to download firmware from web interface of the PLC without authentication.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=401</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=401</guid>
<title>WAGO PLC - default passwords [0-day]</title>
<description>Default passwords enabled for WAGO PLC devices.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=342</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=342</guid>
<title>VMware Update Manager - Directory Traversal </title>
<description>Directory traversal vulnerability discovered in the VMware Update Manager, which allows you to read any file on the OS without authentification. &lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=341</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=341</guid>
<title>SAP NetWeaver - Authentication bypass (Verb Tampering)</title>
<description>Authentication bypass vulnerability in SAP NetWeaver  CTC service can be exploited for unauthorized user management and OS command execution.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=340</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=340</guid>
<title>SAP NetWeaver SPML  - XML CSRF user creation </title>
<description>Attacker can create a new user in J2EE Engine using CSRF attack on SPML service.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=339</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=339</guid>
<title>SAP NetWeaver TH_GREP module - Code injection vulnerability (NEW)</title>
<description>TH_GREP report is vulnerable for command execution vulnerability which is working with previous patch (note 1433101). Remote OS command execution is possible&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=337</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=337</guid>
<title>SAP BW Doc - Multiple XSS</title>
<description>BW DOC metadata application in SAP NetWeaver is vulnerable to XSS attack.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=338</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=338</guid>
<title>SAP RSTXSCRP report - smb relay vulnerability</title>
<description>SAP RSTXSCRP Report has path traversal vulnerability which can lead to SMB relay attack and full control on system.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=336</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=336</guid>
<title>SAP NetWaver Virus Scan Interface   - multiple XSS</title>
<description>SAP Netweaver Virus Scan Interface has linked XSS vulnerabilities.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=335</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=335</guid>
<title>SAP GUI BAPI Explorer- Unauthorized execution of function</title>
<description>SAP GUI BAPI Explorer has stored XSS  which can be used to unauthorized code execution on server side&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=334</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=334</guid>
<title>SAP NetWeaver J2EE MeSync &ndash; information  disclose</title>
<description>Attacker can get information about mobile engine version and sometimes the name of the technical user. &lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=333</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=333</guid>
<title>SAP Crystal Report Server pubDBLogon - Linked &#1061;SS vulnerability</title>
<description>XSS vulnerability found in pubDBLogon.jsp page of SAP Crystal Report Server 2008.&lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
<item>
<link>http://dsecrg.com/pages/vul/show.php?id=332</link>
<guid>http://dsecrg.com/pages/vul/show.php?id=332</guid>
<title>SAP NetWeaver ipcpricing - information disclose</title>
<description>com.sap.ipc.webapp.ipcpricing application has information disclose vulnerability &lt;hr&gt;Digital Secruity Research Group &amp;mdash; &lt;a href=&quot;http://dsecrg.com&quot;&gt;www.dsecrg.com&lt;/a&gt;&lt;br&gt;Rss: &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_vuln&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_expl&quot;&gt;Exploits&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_news&quot;&gt;News&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_pub&quot;&gt;Publications&lt;/a&gt;, &lt;a href=&quot;http://feeds2.feedburner.com/dsecrg_sum&quot;&gt;Summary&lt;/a&gt;</description>
</item>
</channel>
</rss>

