secuvera-SA-2018-03: Command Injection, Broken Access Control and Evil-Twin-Attack in Microsoft Wireless Display Adapter V2 - CVE-2018-8306

2018-07-30 Thread Tobias Glemser
ic/wsc_best_practices_v2_0_1.pdf/8188 Credits: Tobias Glemser tglem...@secuvera.de secuvera GmbH https://www.secuvera.de Simon Winter simon.winte...@web.de Aalen University https://www.hs-aalen.de/en Discla

secuvera-SA-2014-01: Reflected XSS in W3 Total Cache

2014-12-17 Thread Tobias Glemser
ing a first patch preview 2014/10/14 notified vendor the patch does not address the issue 2014/10/24 vendor sent a second patch preview 2014/12/10 vendor published 0.9.4.1 release 2014/12/16 public disclosure Credits: Tobias Glemser, secuvera GmbH tglem...@secuvera.de http

TC-SA-2012-01: Multiple web-vulnerabilities in ownCloud 3.0.0

2012-04-18 Thread Tobias Glemser
rsion 3.0.2 2012/04/18 public disclosure Credits: Tobias Glemser (tglem...@tele-consulting.com) Tele-Consulting security networking training GmbH, Germany www.tele-consulting.com Disclaimer: All information is provided without warranty. The intent is to provide information t

TC-SA-2011-02: Multiple web-vulnerabilities in iTop version 1.1.181

2011-11-23 Thread Tobias Glemser
ggest_pwd=%22%20onmouse over%3dprompt%28972137%29%20bad%3d%22 Possible solutions: - use version 1.2 final Disclosure Timeline: 2011/08/09 vendor contacted via cont...@combodo.com 2011/08/09 inital vendor response 2011/09/06 first patch by the vendor 2011/09/12 second patch by th

TC-SA-2011-01: Multiple vulnerabilities in OmniTouch Instant Communication Suite

2011-10-24 Thread Tobias Glemser
sent an updated internal advisory to business partners addressing all issues 2011/10/24 coordinated public disclosure Credits: Tobias Glemser (tglem...@tele-consulting.com) Tele-Consulting security networking training GmbH, Germany www.tele-consulting.com Disclaimer: All inform

CfP for 4th OWASP Day Germany 2011 now open

2011-08-10 Thread Tobias Glemser
ty of Munich this November. Regards Tobias Glemser OWASP German Chapter P.S.: Early Bird for registration also started! Be sure to get your ticket right now and check: http://www.german-owasp-day.owasp.de

OWASP Appsec Germany Call for Papers

2010-07-15 Thread Tobias Glemser
including all details here (closes 01 August 2010): http://www.owasp.org/index.php/OWASP_AppSec_Germany_2010_Conference#tab=Call_for_Papers_-_English_Version Cheers Tobias Glemser Board Member German Chapter OWASP