Re: [Full-disclosure] Canadian ISP Website - SQL Injection Vulnerability

2011-10-05 Thread MG
Maybe we will post 20-40 pages per day in which we find critical vulnerabilities ? MG Wiadomość napisana przez resea...@vulnerability-lab.com w dniu 4 paź 2011, o godz. 16:46: > Title: > == > Canadian ISP Website - SQL Injection Vulnerability > > > Date: &g

[Full-disclosure] Addition to CVE-2012-0872 oxwall

2012-02-21 Thread MG
Our addition to yesterday YGn advisory: # CVE-2012-0872 { Ariko-Security - Advisory #2/2/2012 } = OxWall Cross-site scripting (XSS) Vendor's description of software and download: # Oxwall Foundation http://www.oxwall.org/ Dork: # N/a Application Info: #OxWall 1.1.1

Re: [Full-disclosure] SQL injection on the UN website

2011-05-30 Thread MG
Over year in DB multiple.. http://www.vs-db.info/?s=un.org MG. Wiadomość napisana przez Sihan w dniu 2011-05-30, o godz. 03:50: > Just saw this earlier: > http://www.un.org/chinese/News/archive.asp?month=5&year=2010' > > ___ &

[Full-disclosure] Where and how to report Dropbox vulnerabilities. (FUN)

2013-07-24 Thread MG
We have sent info about vulnerabilities using all forms, also direct e-mail supp...@dropbox.com, we had chat…. After 2 weeks we have got answer from robot: --- You can add a response by replying to this email. Please be sure to

Re: [Full-disclosure] Where and how to report Dropbox vulnerabilities. (FUN)

2013-07-24 Thread MG
Operations Network infrastructure >SECURITY Network SecuritySecurity bulletins or queries > > perhaps give them a try? > > Thanks and kind regards > Feighen > > > On 24 July 2013 11:29, MG wrote: > > > We have sent info about vulnerabilitie