AirPhoto WebDisk v4.1.0 iOS - Code Execution Vulnerability

2014-04-23 Thread Vulnerability Lab
Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab

Depot WiFi v1.0.0 iOS - Multiple Web Vulnerabilities

2014-04-25 Thread Vulnerability Lab
as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental

Paypal Inc Bug Bounty #109 MOS - Bypass Persistent Vulnerability

2014-05-15 Thread Vulnerability Lab
: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its

NG WifiTransfer Pro 1.1 - File Include Vulnerability

2014-06-03 Thread Vulnerability Lab
: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its

Files Desk Pro v1.4 iOS - File Include Web Vulnerability

2014-06-03 Thread Vulnerability Lab
: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims

AllReader v1.0 iOS - Multiple Web Vulnerabilities

2014-06-03 Thread Vulnerability Lab
is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect

Privacy Pro v1.2 HZ iOS - File Include Web Vulnerability

2014-06-03 Thread Vulnerability Lab
) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability

TigerCom My Assistant v1.1 iOS - File Include Vulnerability

2014-06-03 Thread Vulnerability Lab
in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct

Bluetooth Photo-File Share v2.1 iOS - Multiple Web Vulnerabilities

2014-06-03 Thread Vulnerability Lab
] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including

iScan Online Mobile 2.0.1 iOS - Command Inject Vulnerability

2014-06-03 Thread Vulnerability Lab
in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including

Paypal Inc Bug Bounty #36 - SecurityKey Card Serialnumber Module Vulnerability

2014-06-18 Thread Vulnerability Lab
: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case

Secunia CSI/VIM - Filter Bypass Persistent Validation Vulnerabilities

2014-06-18 Thread Vulnerability Lab
: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its

PayPal Inc Bug Bounty #74 - Persistent Core Backend Vulnerability

2014-07-07 Thread Vulnerability Lab
...@vulnerability-lab.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties

Paypal Inc Bug Bounty #109 Multi Shipping Application API - Filter Bypass Persistent Vulnerability

2014-07-07 Thread Vulnerability Lab
-lab.com) Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular

Yahoo! Bug Bounty #25 Flickr API - Persistent Service Vulnerability

2014-07-07 Thread Vulnerability Lab
Research team discovered a persistent input validation web vulnerability in the official Yahoo Flickr! website web-application and api. Vulnerability Disclosure Timeline: == 2013-11-03: Researcher Notification Coordination (Ateeq ur Rehman Khan - Vulnerability Lab

Photo Org WonderApplications v8.3 iOS - File Include Vulnerability

2014-07-07 Thread Vulnerability Lab
is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect

Yahoo! Bug Bounty #29 YM - Filter Bypass Persistent Web Vulnerability

2014-07-10 Thread Vulnerability Lab
. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business

Yahoo! Bug Bounty #30 YM - Application-Side Mail Encoding (File Attachment) Vulnerability

2014-07-10 Thread Vulnerability Lab
Laboratory [Research Team] - Ateeq ur Rehman Khan (at...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed

Barracuda Networks Message Archiver 650 - Persistent Input Validation Vulnerability (BNSEC 703)

2014-07-18 Thread Vulnerability Lab
] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose

Microsoft MSN HBE - Blind SQL Injection Vulnerability

2014-07-18 Thread Vulnerability Lab
] (@OhTheITGuy) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability

Barracuda Networks SpamVirus Firewall v6.0.2 (600 Vx) - Client Side Cross Site Vulnerability

2014-07-22 Thread Vulnerability Lab
Authors: == Vulnerability Laboratory [Research Team] - Ebrahim Hegazy [ebra...@evolution-sec.com] (www.vulnerability-lab.com) Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab

Barracuda Networks #35 Web Firewall 610 v6.0.1 - Filter Bypass Persistent Vulnerability

2014-07-23 Thread Vulnerability Lab
] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose

Barracuda Networks Firewall 6.1.2 #36 - Filter Bypass Exception Handling Vulnerability + PoC Video BNSEC-2398

2014-07-24 Thread Vulnerability Lab
in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct

Barracuda Networks Firewall 6.1.5 - Filter Bypass Persistent Vulnerabilities

2014-07-25 Thread Vulnerability Lab
as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental

Barracuda Networks SpamVirus Firewall v5.1.3 - Client Side Cross Site Vulnerability

2014-07-28 Thread Vulnerability Lab
(at...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability

WiFi HD v7.3.0 iOS - Multiple Web Vulnerabilities

2014-07-30 Thread Vulnerability Lab
: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its

Barracuda Networks Web Application Firewall v6.1.5 LoadBalancer v4.2.2 #37 - Filter Bypass Multiple Vulnerabilities

2014-07-30 Thread Vulnerability Lab
Document Title: === Barracuda Networks Web Application Firewall v6.1.5 LoadBalancer v4.2.2 #37 - Filter Bypass Multiple Vulnerabilities References (Source): http://www.vulnerability-lab.com/get_content.php?id=1103 Barracuda Networks Security ID (BNSEC):

TigerCom iFolder+ v1.2 iOS - Multiple Vulnerabilities

2014-08-01 Thread Vulnerability Lab
is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct

Photo WiFi Transfer 1.01 - Directory Traversal Vulnerability

2014-08-01 Thread Vulnerability Lab
] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose

Video WiFi Transfer 1.01 - Directory Traversal Vulnerability

2014-08-04 Thread Vulnerability Lab
-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular

FreeDisk v1.01 iOS - Multiple Web Vulnerabilities

2014-08-04 Thread Vulnerability Lab
) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability

Ebay Inc Magento ProStore CP #4 - Filter Validation Bypass Persistent (Payment Information) Vulnerability

2014-08-05 Thread Vulnerability Lab
: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [ad...@vulnerability-lab.com] [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims

PhotoSync Wifi Bluetooth v1.0 - File Include Vulnerability

2014-08-06 Thread Vulnerability Lab
: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable

PhotoSync v2.2 iOS - Command Inject Web Vulnerability

2014-08-06 Thread Vulnerability Lab
-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability

Easy FTP Pro v4.2 iOS - Command Inject Vulnerabilities

2014-08-08 Thread Vulnerability Lab
...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties

Barracuda Networks Web Security Flex Appliance Application v4.x - Filter Bypass Persistent Vulnerabilities (BNSEC 707)

2014-08-25 Thread Vulnerability Lab
) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular

Barracuda Networks Web Security Flex v4.1 - Persistent Vulnerabilities (BNSEC-699)

2014-08-25 Thread Vulnerability Lab
. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss

Avira License Application - Cross Site Request Forgery Vulnerability

2014-09-01 Thread Vulnerability Lab
=Mazen%20Gamal Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability

WWW File Share Pro v7.0 - Denial of Service Vulnerability

2014-09-01 Thread Vulnerability Lab
. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss

Apple iOS v7.1.2 - Merge Apps Service Local Bypass Vulnerability

2014-09-02 Thread Vulnerability Lab
: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties

PhotoSync v2.2 iOS - Command Inject Web Vulnerability

2014-09-11 Thread Vulnerability Lab
-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability

Photorange v1.0 iOS - File Include Web Vulnerability

2014-09-11 Thread Vulnerability Lab
Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab

Briefcase 4.0 iOS - Code Execution File Include Vulnerability

2014-09-15 Thread Vulnerability Lab
provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage

USBWiFi Flash Drive v1.3 iOS - Code Execution Vulnerability

2014-09-17 Thread Vulnerability Lab
) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability

Oracle Corporation MyOracle - Persistent Vulnerability

2014-09-19 Thread Vulnerability Lab
as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental

GS Foto Uebertraeger v3.0 iOS - File Include Vulnerability

2014-09-26 Thread Vulnerability Lab
] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose

Paypal Inc Bug Bounty #32 - Multiple Persistent Vulnerabilities

2014-09-26 Thread Vulnerability Lab
in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct

Paypal Inc Bug Bounty #16 - Persistent Mail Encoding Vulnerability

2014-09-26 Thread Vulnerability Lab
in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage

Oracle Corporation MyOracle - Persistent Vulnerability

2014-09-26 Thread Vulnerability Lab
...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties

PayPal Inc Bug Bounty #59 - Persistent Mail Encoding Vulnerability

2014-10-01 Thread Vulnerability Lab
] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including

PayPal Inc Bug Bounty #71 PPM - Persistent Filter Vulnerability

2014-10-01 Thread Vulnerability Lab
-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular

All In One Wordpress Firewall 3.8.3 - Persistent Vulnerability

2014-10-01 Thread Vulnerability Lab
] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including

BulletProof Security Wordpress v50.8 - POST Inject Vulnerability

2014-10-03 Thread Vulnerability Lab
: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims

HTTP Commander AJS v3.1.9 - Client Side Exception Vulnerability

2014-10-03 Thread Vulnerability Lab
-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular

PayPal Inc Bug Bounty Issue #70 France - Persistent (Escape Shopping) Mail Vulnerability

2014-10-03 Thread Vulnerability Lab
] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose

Paypal Inc Bug Bounty #30 - Filter Bypass Persistent Vulnerabilities

2014-10-07 Thread Vulnerability Lab
as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental

PayPal Inc Bug Bounty #53 - Multiple Persistent Vulnerabilities

2014-10-07 Thread Vulnerability Lab
Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied

PayPal Inc #86 iOS 4.6 - Validation Design Vulnerability

2014-10-14 Thread Vulnerability Lab
: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all

PayPal Inc BB #85 MB iOS 4.6 - Auth Bypass Vulnerability

2014-10-14 Thread Vulnerability Lab
Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability

PayPal Inc BB #96 - Persistent Tags Vulnerability

2014-10-14 Thread Vulnerability Lab
: == An independent vulnerability lab researcher discovered a persistent web vulnerability in the official PayPal Inc Community web-application. Vulnerability Disclosure Timeline: == 2014-10-08: Public Disclosure (Vulnerability

PayPal Inc BB #98 MOS - Persistent Settings Vulnerability

2014-10-15 Thread Vulnerability Lab
: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable

PayPal Inc #90 PDF Mailer - Buffer Overflow Vulnerability

2014-10-15 Thread Vulnerability Lab
: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@vulnerability-lab.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab

Indeed Job Search 2.5 iOS API - Multiple Vulnerabilities

2014-10-15 Thread Vulnerability Lab
] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose

Paypal Inc MultiOrderShipping API - Filter Bypass Persistent XML Vulnerability

2014-10-15 Thread Vulnerability Lab
. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss

Files Document PDF 2.0.2 iOS - Multiple Vulnerabilities

2014-10-21 Thread Vulnerability Lab
. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business

FileBug v1.5.1 iOS - Path Traversal Web Vulnerability

2014-10-21 Thread Vulnerability Lab
-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular

iFunBox Free v1.1 iOS - File Include Vulnerability

2014-10-22 Thread Vulnerability Lab
] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose

File Manager v4.2.10 iOS - Code Execution Vulnerability

2014-10-22 Thread Vulnerability Lab
is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct

Dell SonicWall GMS v7.2.x - Persistent Web Vulnerability

2014-10-24 Thread Vulnerability Lab
of the input values in the message body context Filter and restrict context of send mails through the application and the web-server of the sonicwall gms appliance. The issue has already been patched by the dell security team in cooperation with the vulnerability-lab during the year 2014. Security Risk

File Manager v4.2.10 iOS - Code Execution Vulnerability

2014-10-24 Thread Vulnerability Lab
is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct

WebDisk+ v2.1 iOS - Code Execution Vulnerability

2014-10-28 Thread Vulnerability Lab
: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties

iFileExplorer v6.51 iOS - File Include Web Vulnerability

2014-10-28 Thread Vulnerability Lab
Laboratory [Research Team] - Katharin S. L. (CH) (resea...@vulnerability-lab.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties

Apple iOS v8.0.2 - Silent Contact Denial of Service Vulnerability

2014-10-28 Thread Vulnerability Lab
is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct

Folder Plus v2.5.1 iOS - Persistent Item Vulnerability

2014-10-28 Thread Vulnerability Lab
) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability

Google Youtube - Filter Bypass Persistent Vulnerability [9-5942000004564] (PoC Video Demonstration)

2014-10-28 Thread Vulnerability Lab
: == Jasminder Pal Singh - @singh_jasminder [http://jasminderpalsingh.info] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including

SeasonApps iTransfer 1.1 - Persistent UI Vulnerability

2014-11-09 Thread Vulnerability Lab
Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including

BookFresh - Persistent Clients Invite Vulnerability

2014-11-09 Thread Vulnerability Lab
) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability

PayPal Inc BugBounty #107 MultiOrder Shipping (API) - Persistent History Vulnerability

2014-11-09 Thread Vulnerability Lab
Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability

NASA Orion Mars Program - Bypass, Persistent Issue Embed Code Execution Vulnerability (Boarding Pass)

2014-12-05 Thread Vulnerability Lab
: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers

iWifi for Chat v1.1 iOS - Denial of Service Vulnerability

2014-12-16 Thread Vulnerability Lab
Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business profits

Fuzzylime v3.03b CMS - CS Cross Scripting Vulnerability

2014-12-16 Thread Vulnerability Lab
: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab

Konakart v7.3.0.1 CMS - CS Cross Site Web Vulnerability

2014-12-16 Thread Vulnerability Lab
: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab

Bird Feeder v1.2.3 WP Plugin - CSRF XSS Vulnerability

2014-12-17 Thread Vulnerability Lab
: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any

Morfy CMS v1.05 - Command Execution Vulnerability

2014-12-17 Thread Vulnerability Lab
-application is estimated as high. (CVSS 6.2) Credits Authors: == Paulos Yibelo [Independent Vulnerability Researcher] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all

Jease CMS v2.11 - Persistent UI Web Vulnerability

2014-12-17 Thread Vulnerability Lab
as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect

Apple iOS v8.x - Message Context Privacy Vulnerability

2014-12-18 Thread Vulnerability Lab
as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental

Facebook Bug Bounty #16 (Studio) - Persistent Vulnerability

2014-12-18 Thread Vulnerability Lab
Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business profits

E-Journal CMS (ID) - Multiple Web Vulnerabilities

2014-12-18 Thread Vulnerability Lab
Zaoldyeck and Winda Utari Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability

iTwitter v0.04 WP Plugin - XSS CSRF Web Vulnerability

2014-12-18 Thread Vulnerability Lab
://in.linkedin.com/in/manideepk] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability

iBackup v10.0.0.45 - Privilege Escalation Vulnerability

2014-12-19 Thread Vulnerability Lab
vulnerability in the root path is estimated as high. (CVSS 6.2) Credits Authors: == Hadji Samir s...@hotmail.fr Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all

Mobilis MobiConnect 3G ZDServer v1.0.1.2 - Privilege Escalation Vulnerability

2014-12-19 Thread Vulnerability Lab
is estimated as high. (CVSS 6.4) Credits Authors: == Hadji Samir s...@hotmail.fr Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed

Facebook BB #18 - IDOR Issue Privacy Vulnerability

2014-12-19 Thread Vulnerability Lab
: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers

Mobilis MobiConnect 3G ZDServer 1.x - Privilege Escalation Vulnerability

2014-12-25 Thread Vulnerability Lab
is estimated as high. (CVSS 6.4) Credits Authors: == Hadji Samir s...@hotmail.fr Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed

ZTE Ucell 3G Modem App - Privilege Escalation Vulnerability

2014-12-25 Thread Vulnerability Lab
: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable

Pimcore v3.0 v2.3.0 CMS - SQL Injection Vulnerability

2014-12-25 Thread Vulnerability Lab
Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability

PHPLIST v3.0.6 v3.0.10 - SQL Injection Vulnerability

2014-12-25 Thread Vulnerability Lab
: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable

Lazarus Guestbook v1.22 - Multiple Web Vulnerabilities

2014-12-25 Thread Vulnerability Lab
Authors: == TaurusOmar - @TaurusOmar_ (taurusoma...@gmail.com) [overhat.blogspot.com] Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either

Wickr Desktop v2.2.1 Windows - Denial of Service Vulnerability

2014-12-25 Thread Vulnerability Lab
in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct

PhotoSync v1.1.3 Android - Command Inject Vulnerability

2015-01-22 Thread Vulnerability Lab
vulnerability in the photosync application is estimated as medium. (CVSS 5.2) Credits Authors: == Hadji Samir s...@hotmail.fr Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab

Remote Desktop v0.9.4 Android - Multiple Vulnerabilities

2015-01-22 Thread Vulnerability Lab
: == Hadji Samir s...@hotmail.fr Disclaimer Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability

<    1   2   3   4   5   6   7   8   9   >