[MajorSecurity Advisory #42]webblizzard CMS - Cross Site Scripting and Session fixation Issues

2007-04-07 Thread Securityaudit
[MajorSecurity Advisory #42]webblizzard CMS - Cross Site Scripting and Session fixation Issues Details === Product: webblizzard CMS Remote-Exploit: yes Vendor-URL: http://www.webblizzard.de/ Vendor-Status: informed Advisory-Status: published Credits Discovered by: David Vieira-K

[MajorSecurity Advisory #41]onelook courts online - Session fixation Issue

2007-04-06 Thread Securityaudit
[MajorSecurity Advisory #41]onelook courts online - Session fixation Issue Details === Product: courts online Remote-Exploit: yes Vendor-URL: http://www.onebyone.ch/ Vendor-Status: informed Advisory-Status: published Credits Discovered by: David Vieira-Kurz http://www.majorsecuri

[MajorSecurity Advisory #39]onelook onebyone CMS - Session fixation Issue

2007-04-06 Thread Securityaudit
[MajorSecurity Advisory #39]onelook onebyone CMS - Session fixation Issue Details === Product: onebyone CMS Remote-Exploit: yes Vendor-URL: http://www.onebyone.ch/ Vendor-Status: informed Advisory-Status: published Credits Discovered by: David Vieira-Kurz http://www.majorsecurity

[MajorSecurity Advisory #38]eXV2 CMS - Session fixation and Cross-Site-Scripting Issues

2007-04-06 Thread Securityaudit
[MajorSecurity Advisory #38]eXV2 CMS - Session fixation and Cross-Site-Scripting Issues Details === Product: eXV2 CMS <= 2.0.4.3 Severity: moderated Remote-Exploit: yes Vendor-URL: http://www.exv2.com/ Vendor-Status: informed Advisory-Status: published Credits Discovered by: Da

[MajorSecurity Advisory #40]onelook oboShop - Session fixation Issue

2007-04-06 Thread Securityaudit
[MajorSecurity Advisory #40]onelook oboShop - Session fixation Issue Details === Product: oboShop Remote-Exploit: yes Vendor-URL: http://www.onebyone.ch/ Vendor-Status: informed Advisory-Status: published Credits Discovered by: David Vieira-Kurz http://www.majorsecurity.de Origi

[MajorSecurity Advisory #37]HolaCMS - Cross Site Scripting Issue

2007-04-03 Thread SecurityAudit
[MajorSecurity Advisory #37]HolaCMS - Cross Site Scripting Issue Details === Product: holaCMS-1.4.10 Security-Risk: moderated Remote-Exploit: yes Vendor-URL: http://www.hola.com/ Vendor-Status: informed Advisory-Status: published Credits Discovered by: David Vieira-Kurz http://w