From audit at gleg.net Tue Feb 26 09:41:25 2019 From: audit at gleg.net (Yuriy Gurkin) Date: Tue, 26 Feb 2019 09:41:25 -0000 Subject: [Canvas] SCADA+ pack 1.87 is out Message-ID: Hi, List, 1.87 ver. of SCADA+ contains 5 modules. List: - Tibbo AggreGate SCADA Denial of Service [1Day] - Advantech WebAccess blind SQL injection [1Day] - Advantech WebAccess allows to retrieve arbitrary files from target [1Day] - QuickHMI Server v3 Antelope Denial of Service [1Day] - Reliance 4 Control Server Denial of Service [1Day] Happy pentesting, Gleg`s Security team Follow us on Twitter: GlegExploitPack -------------- next part -------------- An HTML attachment was scrubbed... URL: From audit at gleg.net Tue Feb 26 09:39:54 2019 From: audit at gleg.net (Yuriy Gurkin) Date: Tue, 26 Feb 2019 09:39:54 -0000 Subject: [Canvas] DefPack pack 1.40 is out Message-ID: Hi, List, 1.40 ver. of DefPack contains 3 modules. List: - Foscam ip camera IPCWebComponents ActiveX Control Remote DoS Vulnerability. [1Day] - devolo firmware 'hidden' services enable. [ZSL-2019-5508] - Fortinet FortiOS unauth LDAP server login. [CVE-2018-13374] Happy pentesting, Gleg`s Security team Follow us on Twitter: GlegExploitPack -------------- next part -------------- An HTML attachment was scrubbed... URL: From audit at gleg.net Tue Feb 26 09:38:05 2019 From: audit at gleg.net (Yuriy Gurkin) Date: Tue, 26 Feb 2019 09:38:05 -0000 Subject: [Canvas] Agora pack 2.86 is out Message-ID: Hi, List, 2.86 ver. of Agora contains 3 modules. List: - SAS GRAPH Control Remote Arbitrary File Overwrite. [1day] - Blueimp's JQuery Fileupload AFU. [CVE-2018-9206] - Adobe ColdFusion 2018. [CVE-2018-15961] Happy pentesting, Gleg`s Security team Follow us on Twitter: GlegExploitPack -------------- next part -------------- An HTML attachment was scrubbed... URL: From audit at gleg.net Tue Feb 26 09:36:55 2019 From: audit at gleg.net (Yuriy Gurkin) Date: Tue, 26 Feb 2019 09:36:55 -0000 Subject: [Canvas] MedPack 1.28 is out Message-ID: Hi, List, 1.28 ver. of MedPack contains 1 module. List: - VCE Virtual Collaborative Environment DoS [1Day] Happy pentesting, Gleg`s Security team Follow us on Twitter: GlegExploitPack -------------- next part -------------- An HTML attachment was scrubbed... URL: From admin at vulndisco.cc Mon Feb 11 15:59:13 2019 From: admin at vulndisco.cc (Evgeny Legerov) Date: Mon, 11 Feb 2019 15:59:13 -0000 Subject: [Canvas] VulnDisco Pack Professional 10.64 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hello, Version 10.64 is out with new Telegram exploit. Enjoy! regards, - -e -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.22 (GNU/Linux) iQIbBAEBAgAGBQJcYZvGAAoJEPHiK/cZdSp4bEcP+Mn4ImJ+AbRsm8PRCbcLTSan UCWIR2GDAbLFljJ6dvwi/yXqlDExN9Nb4ry64SSPbBqkx8aoYKD6yA9zonbr5x2O XKhZA8YbcM7X+dyMNLkw1+qxUVp7G8N14MZF4bU4MYduyFgPBIBu+NIwhkcn9BZV HsIWl0qQDh7k1kr+1ibyitdWZRywZncGZzXm5m36up8dAAlMgOzC76XVySSoZiwj 6UpzRs5abuvFmnPsRnPZJDEif9SWDoyUCf64NEKnJXie6nAJeSvJrOenw2ublbow VQ3cuL3V1DZoVLQfEgs85Dac5b7/mQe5U3mZa7MU3ZzzfhIfHH+vFfq6ArVU5LAC 9GwPXYTT0IO6YivfQHYcqZp8LWsevU7nHtmR+SuOsxKuitjeKABwAElHMeJ8SgLO M/vy9D6QUzEIhS+a6Fu9PNX5qNHV6C/dBI3v2E6Km8sWzTzlf0U5lGsx1QWK/z5K 8asZDo63c8Cxt3Nyah/CdAERQgWUjvVFPMpW1WJbooUX1VketNYRuR/CcvH1URb+ HxX1z1pf2t4U9oPEGq+fDJLkyGpCPFkPXIhRY0eM4oiDXCICQd/z0mWDc/SDsWP5 +ugIjnUgzUOUc5Q4B3xGFe10jFoTdx8qwkabM0eiZbO22wfevklrfFHhSOSqQyvW W+F6opJRcXDXhxFRFL0= =5jkk -----END PGP SIGNATURE-----