Responsive Filemanager 9.8.1 Reflected Cross Site Scripting (XSS)

2018-10-09 Thread yavuz atlas
://vulmon.com/vulnerabilitydetails?qid=CVE-2018-18062 V. CREDIT - Yavuz Atlas of Biznet Bilisim http://www.biznet.com.tr/biznet-guvenlik-duyurulari VI. DESCRIPTION - Responsive Filemanager version 9.8.1 is vulnerable to cross-site scripting. A remote

Responsive Filemanager 9.8.1 Authentication Bypass

2018-10-09 Thread yavuz atlas
/vulnerabilitydetails?qid=CVE-2018-18061 V. CREDIT - Yavuz Atlas of Biznet Bilisim http://www.biznet.com.tr/biznet-guvenlik-duyurulari VI. DESCRIPTION - Responsive Filemanager version 9.8.1 allows remote attackers to bypass authentication. The vulnerability

Samsung Web Viewer for Samsung DVR Reflected Cross Site Scripting (XSS) CVE-2018-11689

2018-06-13 Thread yavuz atlas
- Yavuz Atlas - Biznet Bilisim http://www.biznet.com.tr/biznet-guvenlik-duyurulari V. DESCRIPTION - Samsung Web Viewer for Samsung DVR devices (Samsung Smart Viewer) is vulnerable to cross-site scripting. The vulnerability allows remote attackers to inject

Gridbox extension for Joomla! <= 2.4.0 Reflected Cross Site Scripting (XSS)

2018-06-11 Thread yavuz atlas
DIT ----- Yavuz Atlas of Biznet Bilisim http://www.biznet.com.tr/biznet-guvenlik-duyurulari VII. DESCRIPTION - Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting. A remote attacker could exploit t

Ignite Realtime Openfire Version 3.7.1 Reflected Cross Site Scripting (CVE-2018-11688)

2018-06-06 Thread yavuz atlas
II. CREDIT ----- Yavuz Atlas - @yavuzatlas_ http://www.biznet.com.tr/biznet-guvenlik-duyurulari

Ruckus (Brocade) ICX7450-48 Reflected Cross Site Scripting

2018-05-24 Thread Yavuz Atlas
Connection: close Upgrade-Insecure-Requests: 1 Cache-Control: max-age=0 Response: Object Not Found Object Not Found The requested URL '/alert(1)' was not found on the asdf_ICX. Return to last page VI. CREDIT ----- Yavuz Atlas - @yavuzatlas_ http://www.biznet.com.