• CENTRE D’URGENCE | 24/7
  • Vous êtes victime d’une cyberattaque ?
  • Contactez notre centre d’urgence cyber :
  • +33 (0)1 83 07 00 06
 

Actualités

Recevez toute l'actualité en avant-première

 

Nos Actualites

Communique de presse, et dernieres actualites...

[CVE-2017-5868] OpenVPN Access Server : CRLF injection with Session fixation

mai 5, 2017

We found a CRLF injection vulnerability, combined with session fixation, in OpenVPN Access Server, a commercial component of the famous TLS VPN, open-source, software solution.

En savoir plus
[CVE-2017-5870] Multiple XSS vulnerabilities in ViMbAdmin

mai 3, 2017

We found multiple XSS vulnerabilities in ViMbAdmin, a Web front-end to manage virtual domains, mailboxes and aliases.

En savoir plus
[CVE-2017-6086] Multiple CSRF vulnerabilities in ViMbAdmin version 3.0.15

mai 3, 2017

We found multiple CSRF vulnerabilities in ViMbAdmin, a Web front-end to manage virtual domains, mailboxes and aliases.

En savoir plus
[CVE-2017-5869] Nuxeo Platform remote code execution

mars 23, 2017

We found a file upload vulnerability in the Nuxeo CMS. Through the web interface, we managed to abuse the file upload vulnerability to execute arbitrary code and take over the...

En savoir plus
[CVE-2017-6088] EON 5.0 Multiple SQL Injection

mars 14, 2017

EyesOfNetwork (« EON ») is an OpenSource network monitoring solution. We found an SQL injection vulnerability in the authenticated part of the application. Successful exploitation would lead to a complete database dump...

En savoir plus
[CVE-2017-6087] EON 5.0 Remote Code Execution

mars 14, 2017

EyesOfNetwork (« EON ») is an OpenSource network monitoring solution. We found a vulnerability caused by incorrect filtering of inbound parameters of the Web component. It leads to remote code execution. In...

En savoir plus
Riverbed RiOS insecure cryptographic storage (CVE-2017-5670)

février 15, 2017

We found vulnerabilities on Riverbed appliance, and specifically in the way the secure vault is protecting TLS private keys. Such appliances are often found in sensitive environments, where they compress...

En savoir plus
CVE-2016-3403 : Multiple CSRF in Zimbra Administration interface

janvier 12, 2017

We found Multiple CSRF vulnerabilities in the administration interface of Zimbra, giving possibilities like adding, modifying and removing admin accounts.

En savoir plus
SPIP 3.1.2 Server Side Request Forgery (CVE-2016-7999)

octobre 19, 2016

SPIP is a publishing system for the Internet, which put importance on collaborative working, multilingual environments and ease of use. It is free software, distributed under the GNU/GPL licence. It’s...

En savoir plus

CENTRE D’URGENCE | 24/7

Vous êtes victime d’une cyberattaque ?
Contactez notre centre d’urgence cyber
| 01 83 07 00 06

Contactez-nous