[Canvas] Gleg Agora, SCADA, Def, Med, ZDA updates are out

YG audit at gleg.net
Wed Jan 19 14:54:27 UTC 2022


Dear colleagues, new modules available for download.

Agora 3.20
  - Atlassian Jira Server/Data Center 8.16.0 Cross-Site Scripting.  
CVE-2021-26078
  - GitLab 13.10.2 rce CVE-2021-22205
  - CVE-2021-28164 Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224  infoleak
  - GLPI 9.5 Authenticated SQL Injection. [1Day]

DefPack 1.74:
  - Bosch Security Systems VideoSDK RCE [1day]
  - Ricon Industrial Cellular Router S9922XL RCE. pub
  - SonicWall SMA 10.2.1.0-17sv Password Reset CVE-2021-20034
  - Edimax EW-7438RPn Infoleak. pub
  - ESCAM QD-900 WIFI HD Camera Remote Configuration Disclosure. pub
  more

SCADA 2.21 :
- Brainchild Electronic Panel Studio Generated Projects Network DoS [1Day]
  - LEADTOOLS IltmmCapture 17.5 Arbitrary File Overwrite Vulnerability [1Day]
  - Mitsubishi Electric & INEA SmartRTU Source Code Disclose CVE-2021-40382
and more

ZDA 1.40 :
  - Samsung SmartViewer 3.0 Remote Buffer Overflow [0Day]
  - ExifTool versions 7.44 arbitrary code execution CVE-2021-22204
  - HD-Network Real-time Monitoring System 2.0 Local File Inclusion  
CVE-2021-45043
  - Pinkie network troubleshooting tools DirTrav [0Day]
Happy pentesting,

Gleg Security team
Follow us on https://twitter.com/GlegExploitPack



More information about the Canvas mailing list