DocuSign Phishing Campaign Uses COVID-19 as Bait

Enterprise Vulnerabilities
From DHS/US-CERT’s National Vulnerability Database CVE-2020-11531
PUBLISHED: 2020-05-08

The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authenticated attacker to execute code in the context of the product by writing a JSP file to the webroot di…

CVE-2020-11532
PUBLISHED: 2020-05-08

Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user.

CVE-2020-11530
PUBLISHED: 2020-05-08

A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary SQL queries in the context of the WP database user.

CVE-2020-6616
PUBLISHED: 2020-05-08

Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (PRNG) is used in situations where a Hardware Random Number Generator (HRNG) should have been used to prevent spoofing. This affects, for example, Samsung Galaxy S8, S8+, and Note8 d…

CVE-2020-11006
PUBLISHED: 2020-05-08

In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when information is fetched from backend. This has been patched in version 2.11.0.

Read More HERE

Leave a Reply