[Full-disclosure] Pitrinec MacroToolworks 7.5 - Buffer Overflow Vulnerability

2012-03-08 Thread resea...@vulnerability-lab.com
Title: == Pitrinec MacroToolworks 7.5 - Buffer Overflow Vulnerability Date: = 2012-03-08 References: === http://www.vulnerability-lab.com/get_content.php?id=466 VL-ID: = 466 Introduction: = Macro Toolworks is powerful all-in-one Windows automation macro softw

[Full-disclosure] Enterasys SecureStack Switch v6.x - Multiple Vulnerabilities

2012-03-08 Thread resea...@vulnerability-lab.com
Title: == Enterasys SecureStack Switch v6.x - Multiple Vulnerabilities Date: = 2012-03-08 References: === http://www.vulnerability-lab.com/get_content.php?id=443 VL-ID: = 443 Introduction: = The Enterasys C5 is a scalable, high-performance Gigabit Ethernet sw

[Full-disclosure] Barracuda WAF 660 v7.6.0.028 - Cross Site Vulnerability

2012-03-08 Thread resea...@vulnerability-lab.com
Title: == Barracuda WAF 660 v7.6.0.028 - Cross Site Vulnerability Date: = 2012-03-07 References: === http://www.vulnerability-lab.com/get_content.php?id=444 VL-ID: = 444 Introduction: = The Barracuda Web Application Firewall provides superior protection again

[Full-disclosure] HITB2011KUL - Satellite Telephony Security - Jim Geovedi

2012-03-07 Thread resea...@vulnerability-lab.com
Title: == HITB2011KUL - Satellite Telephony Security - Jim Geovedi Date: = 2012-03-07 References: === Download: http://www.vulnerability-lab.com/resources/videos/464.wmv View: http://www.youtube.com/watch?v=23FKGifzCJs VL-ID: = 464 Status: Publi

[Full-disclosure] LDAP Account Manager Pro v3.6 (lamp) - Multiple Vulnerabilities

2012-03-01 Thread resea...@vulnerability-lab.com
Title: == LDAP Account Manager Pro v3.6 - Multiple Vulnerabilities Date: = 2012-03-01 References: === http://www.vulnerability-lab.com/get_content.php?id=458 VL-ID: = 458 Introduction: = LDAP Account Manager Pro is an extended version of LAM which focuses on

[Full-disclosure] FlashFXP v4.1.8.1701 - Buffer Overflow Vulnerability

2012-03-01 Thread resea...@vulnerability-lab.com
Title: == FlashFXP v4.1.8.1701 - Buffer Overflow Vulnerability Date: = 2012-03-01 References: === http://www.vulnerability-lab.com/get_content.php?id=462 VL-ID: = 462 Introduction: = FlashFXP is a FTP (File Transfer Protocol) client for Windows, it offers you

[Full-disclosure] Wolf CMS v0.7.5 - Multiple Web Vulnerabilities

2012-02-27 Thread resea...@vulnerability-lab.com
Title: == Wolf CMS v0.7.5 - Multiple Web Vulnerabilities Date: = 2012-02-27 References: === http://www.vulnerability-lab.com/get_content.php?id=452 VL-ID: = 452 Introduction: = Wolf CMS is a content management system and is Free Software published under the

[Full-disclosure] OSQA CMS v3b - Multiple Persistent Vulnerabilities

2012-02-27 Thread resea...@vulnerability-lab.com
Title: == OSQA CMS v3b - Multiple Web Vulnerabilities Date: = 2012-02-27 References: === http://www.vulnerability-lab.com/get_content.php?id=461 VL-ID: = 461 Introduction: = OSQA is the Open Source Q&A System. It is free software licensed under the GPL, and

[Full-disclosure] Socusoft Photo 2 Video v8.05 - Buffer Overflow Vulnerability

2012-02-27 Thread resea...@vulnerability-lab.com
Title: == Socusoft Photo 2 Video v8.05 - Buffer Overflow Vulnerability Date: = 2012-02-27 References: === http://www.vulnerability-lab.com/get_content.php?id=460 VL-ID: = 460 Introduction: = Socusoft photo to video converter Professional allows you to create

[Full-disclosure] Microsoft AdCenter Service - Cross Site Vulnerabilities

2012-02-27 Thread resea...@vulnerability-lab.com
Title: == Microsoft AdCenter Service - Cross Site Vulnerabilities Date: = 2012-02-27 References: === http://www.vulnerability-lab.com/get_content.php?id=447 MSRC ID: 12223 VL-ID: = 447 Introduction: = Microsoft adCenter (formerly MSN adCenter), is the divis

[Full-disclosure] Endian UTM Firewall v2.4.x - Cross Site Vulnerabilities

2012-02-19 Thread resea...@vulnerability-lab.com
Title: == Endian UTM Firewall v2.4.x - Cross Site Vulnerabilities Date: = 2012-02-18 References: === http://www.vulnerability-lab.com/get_content.php?id=436 VL-ID: = 436 Introduction: = The Endian Firewall is an open source GNU/Linux distribution that special

[Full-disclosure] Skype v5.6.59.x - Memory Corruption Vulnerability

2012-02-17 Thread resea...@vulnerability-lab.com
Title: == Skype v5.6.59.x - Memory Corruption Vulnerability Date: = 2012-02-17 References: === http://www.vulnerability-lab.com/get_content.php?id=315 VL-ID: = 315 Introduction: = Skype is a software application that allows users to make voice and video calls

[Full-disclosure] Facebook NYClubs - Multiple Web Vulnerabilities

2012-02-17 Thread resea...@vulnerability-lab.com
Title: == Facebook NYClubs - Multiple Web Vulnerabilities Date: = 2012-02-17 References: === http://www.vulnerability-lab.com/get_content.php?id=440 VL-ID: = 440 Introduction: = The application is currently included and viewable by all facebook users. The ser

[Full-disclosure] Pandora FMS v4.0.1 - Local File Include Vulnerability

2012-02-17 Thread resea...@vulnerability-lab.com
Title: == Pandora FMS v4.0.1 - Local File Include Vulnerability Date: = 2012-02-17 References: === http://www.vulnerability-lab.com/get_content.php?id=435 VL-ID: = 435 Introduction: = Pandora FMS is a monitoring Open Source software. It watches your systems a

[Full-disclosure] eFront Community++ v3.6.10 - SQL Injection Vulnerability

2012-02-12 Thread resea...@vulnerability-lab.com
Title: == eFront Community++ v3.6.10 - SQL Injection Vulnerability Date: = 2012-02-11 References: === http://www.vulnerability-lab.com/get_content.php?id=422 VL-ID: = 422 Introduction: = Tailored with larger organizations in mind, eFront Community ++ offers

[Full-disclosure] Yahoo! Messenger v11.5 - Buffer Overflow Vulnerability

2012-02-12 Thread resea...@vulnerability-lab.com
Title: == Yahoo! Messenger v11.5 - Buffer Overflow Vulnerability Date: = 2012-02-11 References: === http://www.vulnerability-lab.com/get_content.php?id=434 VL-ID: = 434 Introduction: = Der Yahoo Messenger (eigene Schreibung Yahoo! Messenger, kurz auch Y!M, YI

[Full-disclosure] Yahoo Messenger - Buffer Overflow Vulnerability [Video]

2012-02-11 Thread resea...@vulnerability-lab.com
Title: == Yahoo Messenger - Buffer Overflow Vulnerability [Video] Date: = 2012-02-10 References: === Download: http://www.vulnerability-lab.com/resources/videos/432.wmv View: http://www.youtube.com/watch?v=cc9qc90Rz64 VL-ID: = 432 Status: Publis

[Full-disclosure] Linux Kloxo LxCenter Server CP v6.1.10 - Multiple Web Vulnerabilities

2012-02-10 Thread resea...@vulnerability-lab.com
Title: == Kloxo LxCenter Server CP v6.1.10 - Multiple Web Vulnerabilities Date: = 2012-02-10 References: === http://www.vulnerability-lab.com/get_content.php?id=429 VL-ID: = 429 Introduction: = Scriptable, distributed and object oriented Hosting Platform. Man

[Full-disclosure] Indianapolis Superbowl 2012 - SQL Injection Vulnerabilities

2012-02-10 Thread resea...@vulnerability-lab.com
Title: == Indianapolis Superbowl 2012 - SQL Injection Vulnerabilities Date: = 2012-02-06 VL-ID: = 418 Abstract: = Alexander Fuchs discovered 2 remote SQL Injection Vulnerabilities on the official website of Indianapolis Superbowl 2012 (US). Status: Verified by

[Full-disclosure] Dolibarr CMS v3.2.0 Alpha - SQL Injection Vulnerabilities

2012-02-10 Thread resea...@vulnerability-lab.com
Title: == Dolibarr CMS v3.2.0 Alpha - SQL Injection Vulnerabilities Date: = 2012-02-09 References: === http://www.vulnerability-lab.com/get_content.php?id=427 VL-ID: = 427 Introduction: = Dolibarr ERP & CRM is a modern software to manage your company or found

[Full-disclosure] Dolibarr CMS v3.2.0 Alpha - SQL Injection Vulnerabilities

2012-02-10 Thread resea...@vulnerability-lab.com
Title: == Dolibarr CMS v3.2.0 Alpha - SQL Injection Vulnerabilities Date: = 2012-02-09 References: === http://www.vulnerability-lab.com/get_content.php?id=427 VL-ID: = 427 Introduction: = Dolibarr ERP & CRM is a modern software to manage your company or found

[Full-disclosure] OnxShop CMS v1.5.0 - Multiple Web Vulnerabilities

2012-02-10 Thread resea...@vulnerability-lab.com
Title: == OnxShop CMS v1.5.0 - Multiple Web Vulnerabilities Date: = 2012-02-08 References: === http://www.vulnerability-lab.com/get_content.php?id=426 VL-ID: = 426 Introduction: = Onxshop is not only great CMS offering integrated in-context editing and full

[Full-disclosure] Dolibarr CMS v3.2.0 Alpha - File Include Vulnerabilities

2012-02-10 Thread resea...@vulnerability-lab.com
Title: == Dolibarr CMS v3.2.0 Alpha - File Include Vulnerabilities Date: = 2012-02-07 References: === http://www.vulnerability-lab.com/get_content.php?id=428 VL-ID: = 428 Introduction: = Dolibarr ERP & CRM is a modern software to manage your company or founda

[Full-disclosure] eFront Community++ v3.6.10 - Multiple Web Vulnerabilities

2012-02-09 Thread resea...@vulnerability-lab.com
Title: == eFront Community++ v3.6.10 - Multiple Web Vulnerabilities Date: = 2012-02-09 References: === http://www.vulnerability-lab.com/get_content.php?id=421 VL-ID: = 421 Introduction: = Tailored with larger organizations in mind, eFront Community ++ offers

[Full-disclosure] HITB2011KUL - Is The Pen Still Mightier Than The Sword

2012-02-07 Thread resea...@vulnerability-lab.com
Title: == HITB2011KUL - Is The Pen Still Mightier Than The Sword Date: = 2012-01-18 References: === Download: http://www.vulnerability-lab.com/resources/videos/385.wmv View: http://www.youtube.com/watch?v=9dsYY_Zl4sk VL-ID: = 385 Status: Publis

[Full-disclosure] HITB2011KUL - Chip & PIN - Protocol Analysis EMV POS

2012-02-07 Thread resea...@vulnerability-lab.com
Title: == HITB2011KUL - Chip & PIN - Protocol Analysis EMV POS Date: = 2012-01-26 References: === Download: http://www.vulnerability-lab.com/resources/videos/399.wmv View: http://www.youtube.com/watch?v=5zFlqMFWYhc VL-ID: = 399 Status: Published

[Full-disclosure] HITB2011KUL - Mobile Malware Analysis

2012-02-07 Thread resea...@vulnerability-lab.com
Title: == HITB2011KUL - Mobile Malware Analysis Date: = 2012-02-06 References: === Download: http://www.vulnerability-lab.com/resources/videos/424.wmv View: http://www.youtube.com/watch?v=nVAuZ7jf7Sk VL-ID: = 424 Status: Published Exploitation

[Full-disclosure] HITB2011KUL - Post Memory Corruption Analysis

2012-02-07 Thread resea...@vulnerability-lab.com
Title: == HITB2011KUL - Post Memory Corruption Analysis Date: = 2012-01-26 References: === Download: http://www.vulnerability-lab.com/resources/videos/398.wmv View: http://www.youtube.com/watch?v=kOgarD9KCbg VL-ID: = 398 Status: Published Expl

[Full-disclosure] Video => Google Service Reward #1 - ClickJacking Vulnerability

2012-02-07 Thread resea...@vulnerability-lab.com
Title: == Google Service Reward #1 - ClickJacking Vulnerability Date: = 2012-02-07 References: === Download: http://www.vulnerability-lab.com/resources/videos/416.wmv View: http://www.youtube.com/watch?v=6N0YS9cTRHw VL-ID: = 416 Status: Publishe

[Full-disclosure] Video => Cyberoam Central Console v2.x - File Include Vulnerability

2012-02-07 Thread resea...@vulnerability-lab.com
Title: == Cyberoam Central Console v2.x - File Include Vulnerability Date: = 2012-02-05 References: === Download: http://www.vulnerability-lab.com/resources/videos/411.wmv View: http://www.youtube.com/watch?v=pGJy2XNugy8 VL-ID: = 411 Status: Pub

[Full-disclosure] Dinama SMS Service - Persistent Web Vulnerability

2012-02-07 Thread resea...@vulnerability-lab.com
Title: == Dinama SMS Service - Persistent Web Vulnerability Date: = 2012-02-05 References: === http://www.vulnerability-lab.com/get_content.php?id=417 VL-ID: = 417 Introduction: = Las soluciones de medios interactivos de DINAMA habilitan la comunicación bidi

[Full-disclosure] Facebook Game Store - SQL Injection Vulnerability

2012-02-07 Thread resea...@vulnerability-lab.com
Title: == Facebook Game Store - SQL Injection Vulnerability Date: = 2012-02-04 References: === http://www.vulnerability-lab.com/get_content.php?id=408 VL-ID: = 408 Introduction: = The application is currently included and viewable by all facebook users. The s

[Full-disclosure] eFronts Community++ v3.6.10 - Cross Site Vulnerability

2012-02-07 Thread resea...@vulnerability-lab.com
Title: == eFronts Community++ v3.6.10 - Cross Site Vulnerability Date: = 2012-02-07 References: === http://www.vulnerability-lab.com/get_content.php?id=423 VL-ID: = 423 Introduction: = Tailored with larger organizations in mind, eFront Community ++ offers so

[Full-disclosure] VolksBank Online Banking - Multiple Web Vulnerabilities

2012-02-07 Thread resea...@vulnerability-lab.com
Title: == VolksBank Online Banking - Multiple Web Vulnerabilities Date: = 2012-02-07 References: === http://www.vulnerability-lab.com/get_content.php?id=172 VL-ID: = 172 Introduction: = Die Volksbank AG trifft eine Reihe von Sicherheitsvorkehrungen, die einen

Re: [Full-disclosure] Vulnerability-lab.com XSS

2012-02-07 Thread resea...@vulnerability-lab.com
i recomment your desinformation with 2 short links ... article: http://www.vulnerability-lab.com/dev/?p=382 news: http://www.vulnerability-lab.com/news/get_news.php?id=74 ... we will not respond to this crap anymore ... false envy. by ;) -- Website: www.vulnerability-lab.com ; vuln-lab.com or

[Full-disclosure] Electronic Arts - Cross Site Scripting Vulnerability

2012-02-07 Thread resea...@vulnerability-lab.com
Title: == Electronic Arts - Cross Site Scripting Vulnerability Date: = 2012-02-06 References: === http://www.vulnerability-lab.com/get_content.php?id=367 VL-ID: = 367 Introduction: = Electronic Arts, Inc. (EA) (NASDAQ: EA) is a major American developer, mar

[Full-disclosure] Sun Microsystems (Print) - Cross Site Scripting Vulnerability

2012-02-07 Thread resea...@vulnerability-lab.com
Title: == Sun Microsystems (Print) - Cross Site Scripting Vulnerability Date: = 2012-02-01 References: === http://www.vulnerability-lab.com/get_content.php?id=404 VL-ID: = 404 Introduction: = Sun Microsystems, Inc. was a company that sold computers, computer

[Full-disclosure] NexorONE Online Banking - Multiple Cross Site Vulnerabilities

2012-02-06 Thread resea...@vulnerability-lab.com
Title: == NexorONE Online Banking - Multiple Cross Site Vulnerabilities Date: = 2012-02-04 References: === http://www.vulnerability-lab.com/get_content.php?id=304 VL-ID: = 304 Introduction: = NexorONE is the leading online banking software provider for Privat

[Full-disclosure] NASA Subdomains FCKEditor - Multiple Vulnerabilities

2012-02-03 Thread resea...@vulnerability-lab.com
Title: == NASA Subdomains FCKEditor - Multiple Vulnerabilities Date: = 2012-01-29 References: === http://vulnerability-lab.com/get_content.php?id=400 VL-ID: = 400 Introduction: = The National Aeronautics and Space Administration (NASA) is the agency of the U

[Full-disclosure] Achievo v1.4.3 - Multiple Web Vulnerabilities

2012-02-03 Thread resea...@vulnerability-lab.com
Title: == Achievo v1.4.3 - Multiple Web Vulnerabilities Date: = 2012-01-30 References: === http://www.vulnerability-lab.com/get_content.php?id=403 VL-ID: = 403 Introduction: = Achievo is a flexible web-based resource management tool for business environments

[Full-disclosure] OSCommerce v3.0.2 - Persistent Cross Site Vulnerability

2012-02-03 Thread resea...@vulnerability-lab.com
Title: == OSCommerce v3.0.2 - Persistent Cross Site Vulnerability Date: = 2012-02-02 VL-ID: = 407 Introduction: = osCommerce is the leading Open Source online shop e-commerce solution that is available for free under the GNU General Public License. It features a ric

[Full-disclosure] FAA US Academy (AFS) - Auth Bypass Vulnerability

2012-01-30 Thread resea...@vulnerability-lab.com
Title: == FAA US Academy (AFS) - Auth Bypass Vulnerability Date: = 2012-01-28 References: === http://vulnerability-lab.com/get_content.php?id=171 VL-ID: = 171 Introduction: = This is a FAA computer system. FAA computer systems are provided for the processing

[Full-disclosure] ME Monitoring Manager v9.x; v10.x - Multiple Vulnerabilities

2012-01-30 Thread resea...@vulnerability-lab.com
Title: == ME Monitoring Manager v9.x; v10.x - Multiple Vulnerabilities Date: = 2012-01-27 References: === http://www.vulnerability-lab.com/get_content.php?id=115 VL-ID: = 115 Introduction: = Mit dem ManageEngine Applications Manager können IT-Administratoren

[Full-disclosure] eBank IT Online Banking - Multiple Web Vulnerabilities

2012-01-30 Thread resea...@vulnerability-lab.com
Title: == eBank IT Online Banking - Multiple Web Vulnerabilities Date: = 2012-01-26 References: === http://www.vulnerability-lab.com/get_content.php?id=313 VL-ID: = 313 Introduction: = As a leading provider of innovative online banking software solutions, eB

[Full-disclosure] Fortigate UTM WAF Appliance - Multiple Web Vulnerabilities

2012-01-27 Thread resea...@vulnerability-lab.com
Title: == Fortigate UTM WAF Appliance - Multiple Web Vulnerabilities Date: = 2012-01-27 References: === http://vulnerability-lab.com/get_content.php?id=144 VL-ID: = 144 Introduction: = The FortiGate series of multi-threat security systems detect and eliminate

[Full-disclosure] Acolyte CMS v1.5 and v6.3 - SQL Injection Vulnerabilities

2012-01-25 Thread resea...@vulnerability-lab.com
Title: == Acolyte CMS v1.5 and v6.3 - SQL Injection Vulnerabilities Date: = 2012-01-25 References: === http://www.vulnerability-lab.com/get_content.php?id=397 VL-ID: = 397 Abstract: = A Vulnerability Laboratory researcher discovered a critical (remote) SQL Injec

[Full-disclosure] Verkehrsbetriebe Berlin - SQL Injection Vulnerability

2012-01-25 Thread resea...@vulnerability-lab.com
Title: == Verkehrsbetriebe Berlin - SQL Injection Vulnerability Date: = 2012-01-25 References: === http://www.vulnerability-lab.com/get_content.php?id=138 VL-ID: = 138 Introduction: = VBB Verkehrsverbund Berlin-Brandenburg GmbH Der VBB koordiniert die Interes

[Full-disclosure] SpamTitan Application v5.08x - SQL Injection Vulnerability

2012-01-24 Thread resea...@vulnerability-lab.com
Title: == SpamTitan Application v5.08x - SQL Injection Vulnerability Date: = 2012-01-23 References: === http://www.vulnerability-lab.com/get_content.php?id=197 VL-ID: = 197 Introduction: = SpamTitan Anti Spam is a complete software solution to email security

[Full-disclosure] Bart`s CMS - SQL Injection Vulnerability

2012-01-23 Thread resea...@vulnerability-lab.com
Title: == Bart`s CMS - SQL Injection Vulnerability Date: = 2012-01-23 References: === http://www.vulnerability-lab.com/get_content.php?id=390 VL-ID: = 390 Introduction: = It is a website Content Management System that is build with Codecharge Studio. There w

[Full-disclosure] Parallels H Sphere v3.3 P1 - Multiple Persistent Vulnerabilities

2012-01-23 Thread resea...@vulnerability-lab.com
Title: == Parallels H Sphere v3.3 P1 - Multiple Persistent Vulnerabilities Date: = 2012-01-22 References: === http://www.vulnerability-lab.com/get_content.php?id=392 VL-ID: = 392 Introduction: = Parallels H-Sphere delivers a multi-server hosting automation so

[Full-disclosure] Joomla com_mobile Component - SQL Injection Vulnerability

2012-01-23 Thread resea...@vulnerability-lab.com
Title: == Joomla com_mobile Component - SQL Injection Vulnerability Date: = 2012-01-21 References: === http://www.vulnerability-lab.com/get_content.php?id=393 VL-ID: = 393 Introduction: = com_mobile Joomla CMS Component Abstract: = A Vulnerability L

[Full-disclosure] Zone Rouge CMS 2012 - SQL Injection Vulnerability

2012-01-23 Thread resea...@vulnerability-lab.com
Title: == Zone Rouge CMS 2012 - SQL Injection Vulnerability Date: = 2012-01-21 References: === http://www.vulnerability-lab.com/get_content.php?id=391 VL-ID: = 391 Introduction: = Professional CMS with many amenities, popular in his country. (Copy of the Ven

[Full-disclosure] Snitz Communications 2010/11 - SQL Injection Vulnerability

2012-01-20 Thread resea...@vulnerability-lab.com
Title: == Snitz Communications 2010/11 - SQL Injection Vulnerability Date: = 2012-01-18 References: === http://www.vulnerability-lab.com/get_content.php?id=384 VL-ID: = 384 Introduction: = Snitz Forums 2000, one of the best ASP based bulletin board systems o

[Full-disclosure] Engine by Avatarus Simple CMS - SQL Injection Vulnerability

2012-01-20 Thread resea...@vulnerability-lab.com
Title: == Engine by Avatarus Simple CMS - SQL Injection Vulnerability Date: = 2012-01-19 References: === http://www.vulnerability-lab.com/get_content.php?id=388 VL-ID: = 388 Introduction: = Engine by Avatarus Powered by Simple CMS is mainly used on the pages

[Full-disclosure] Barracuda Spam/Virus WAF 600 - Multiple Web Vulnerabilities

2012-01-20 Thread resea...@vulnerability-lab.com
Title: == Barracuda Spam/Virus WAF 600 - Multiple Web Vulnerabilities Date: = 2012-01-19 References: === http://www.vulnerability-lab.com/get_content.php?id=28 VL-ID: = 28 Introduction: = Barracuda Networks - Worldwide leader in email and Web security. The Ba

[Full-disclosure] Airport Koeln/Bonn - Blind SQL Injection Vulnerabilities

2012-01-20 Thread resea...@vulnerability-lab.com
Title: == Airport Koeln/Bonn - Blind SQL Injection Vulnerabilities Date: = 2012-01-20 References: === http://www.vulnerability-lab.com/get_content.php?id=174 VL-ID: = 174 Introduction: = Der Köln Bonn Airport ist einer der größten Verkehrsflughäfen Deutschlan

[Full-disclosure] RheinMetall AG - Multiple SQL Injection Vulnerabilities

2012-01-20 Thread resea...@vulnerability-lab.com
Title: == RheinMetall AG - Multiple SQL Injection Vulnerabilities Date: = 2012-01-17 References: === http://www.vulnerability-lab.com/get_content.php?id=170 VL-ID: = 170 Introduction: = -> UK Rheinmetall AG is a German automotive and defence company with fact

[Full-disclosure] Syneto UTM WAF v1.4.2 - Multiple Web Vulnerabilities

2012-01-20 Thread resea...@vulnerability-lab.com
Title: == Syneto UTM WAF v1.4.2 - Multiple Web Vulnerabilities Date: = 2012-01-20 References: === http://www.vulnerability-lab.com/get_content.php?id=373 VL-ID: = 373 Introduction: = The Syneto UTM (Unified Threat Management) is a security appliance that per

[Full-disclosure] VolksBank ZU Application - Auth Bypass Vulnerability

2012-01-20 Thread resea...@vulnerability-lab.com
Title: == VolksBank ZU Application - Auth Bypass Vulnerability Date: = 2012-01-20 References: === http://www.vulnerability-lab.com/get_content.php?id=382 VL-ID: = 382 Introduction: = Die Volksbank AG trifft eine Reihe von Sicherheitsvorkehrungen, die einen w

[Full-disclosure] WebTitan Appliance v3.50.x - Multiple Web Vulnerabilities

2012-01-17 Thread resea...@vulnerability-lab.com
Title: == WebTitan Appliance v3.50.x - Multiple Web Vulnerabilities Date: = 2012-01-13 References: === http://www.vulnerability-lab.com/get_content.php?id=89 VL-ID: = 89 Introduction: = WebTitan is a complete internet monitoring software (web filter) which pr

[Full-disclosure] Barracuda SSL VPN 480 - Multiple Web Vulnerabilities

2012-01-17 Thread resea...@vulnerability-lab.com
Title: == Barracuda SSL VPN 480 - Multiple Web Vulnerabilities Date: = 2012-01-12 References: === http://www.vulnerability-lab.com/get_content.php?id=35 VL-ID: = 35 Introduction: = The Barracuda SSL VPN is an integrated hardware and software solution enabling

[Full-disclosure] DUS INT Airport - Multiple SQL Injection Vulnerabilities

2012-01-17 Thread resea...@vulnerability-lab.com
Title: == DUS INT Airport - Multiple SQL Injection Vulnerabilities Date: = 2012-01-11 References: === http://www.vulnerability-lab.com/get_content.php?id=173 VL-ID: = 173 Introduction: = Duesseldorf International - Large airports are regional poles for growth

[Full-disclosure] Zimbra Desktop v7.1.2 - Persistent Software Vulnerability

2012-01-17 Thread resea...@vulnerability-lab.com
Title: == Zimbra Desktop v7.1.2 - Persistent Software Vulnerability Date: = 2012-01-12 References: === http://www.vulnerability-lab.com/get_content.php?id=378 VL-ID: = 378 Introduction: = The Zimbra offline client (also Zimbra Desktop) for Microsoft Windows,

[Full-disclosure] Canopus Internet Banking FIVE - Auth Bypass Vulnerability

2012-01-17 Thread resea...@vulnerability-lab.com
Title: == Canopus Internet Banking FIVE - Auth Bypass Vulnerability Date: = 2012-01-12 References: === http://www.vulnerability-lab.com/get_content.php?id=305 VL-ID: = 305 Introduction: = Automation of banks, small and medium sized, money transfer systems, co

[Full-disclosure] MegaSWF - Persistant Cross Site Scripting Vulnerability

2012-01-17 Thread resea...@vulnerability-lab.com
Title: == MegaSWF - Persistant Cross Site Scripting Vulnerability Date: = 2012-01-12 References: === http://www.vulnerability-lab.com/get_content.php?id=368 VL-ID: = 368 Introduction: = Do you create Flash games, Flash animations, or any other type of content

[Full-disclosure] Tine v2.0 Maischa - Cross Site Scripting Vulnerability

2012-01-17 Thread resea...@vulnerability-lab.com
Title: == Tine v2.0 Maischa - Cross Site Scripting Vulnerability Date: = 2012-01-13 References: === http://www.vulnerability-lab.com/get_content.php?id=379 VL-ID: = 379 Introduction: = Tine 2.0 is an open source project which combines groupware and CRM in one

[Full-disclosure] SonicWall AntiSpam & EMail Security v7.x - Multiple Web Vulnerabilities

2012-01-08 Thread resea...@vulnerability-lab.com
Title: == SonicWall AntiSpam & EMail Security v7.x - Multiple Web Vulnerabilities Date: = 2012-01-07 References: === http://www.vulnerability-lab.com/get_content.php?id=58 VL-ID: = 58 Introduction: = Spam-, Phishing- und mit Viren infizierte Nachrichten veru

[Full-disclosure] ATMAIL WebMail Admin v6.3.4 - Multiple Vulnerabilities

2012-01-08 Thread resea...@vulnerability-lab.com
Title: == ATMAIL WebMail Admin v6.3.4 - Multiple Vulnerabilities Date: = 2012-01-07 References: === http://www.vulnerability-lab.com/get_content.php?id=376 VL-ID: = 376 Introduction: = Atmail is a commercial Linux messaging platform provider. The company was

[Full-disclosure] Barracuda Control Center 620 - Multiple Web Vulnerabilities

2012-01-06 Thread resea...@vulnerability-lab.com
Title: == Barracuda Control Center 620 - Multiple Web Vulnerabilities Date: = 2011-12-21 References: === http://www.vulnerability-lab.com/get_content.php?id=32 VL-ID: = 32 Introduction: = Barracuda Networks - Worldwide leader in email and Web security. Contro

[Full-disclosure] Astaro Security Gateway v8.1 - Input Validation Vulnerability

2012-01-06 Thread resea...@vulnerability-lab.com
Title: == Astaro Security Gateway v8.1 - Input Validation Vulnerability Date: = 2011-12-27 References: === http://www.vulnerability-lab.com/get_content.php?id=193 VL-ID: = 193 Introduction: = Das Astaro Security Gateway 8.101 wurde speziell für den Schutz gro

[Full-disclosure] Strato FAQ Center 2012 - Cross Site Scripting Vulnerability

2012-01-06 Thread resea...@vulnerability-lab.com
Title: == Strato FAQ Center 2012 - Cross Site Scripting Vulnerability Date: = 2012-01-06 References: === http://www.vulnerability-lab.com/get_content.php?id=372 http://www.vulnerability-lab.com/news/get_news.php?id=68 VL-ID: = 372 Introduction: = FAQ / Login &

[Full-disclosure] eFront Enterprise v3.6.10 - File Include Vulnerability

2012-01-06 Thread resea...@vulnerability-lab.com
Title: == eFront Enterprise v3.6.10 - File Include Vulnerability Date: = 2012-01-06 References: === http://www.vulnerability-lab.com/get_content.php?id=296 VL-ID: = 296 Introduction: = Tailored with larger organizations in mind, eFront Enterprise offers solut

[Full-disclosure] ATMAIL WebMail v6.3.4 - Multiple Web Vulnerabilities

2012-01-06 Thread resea...@vulnerability-lab.com
Title: == ATMAIL WebMail v6.3.4 - Multiple Web Vulnerabilities Date: = 2012-01-06 References: === http://www.vulnerability-lab.com/get_content.php?id=375 VL-ID: = 375 Introduction: = Atmail is a commercial Linux messaging platform provider. The company was f

Re: [Full-disclosure] CertificationMagazine - Blind SQL Injection Vulnerability

2011-12-24 Thread resea...@vulnerability-lab.com
: > http://www.vs-db.info/?p=593 > > MAY 2010 - Nice that you can find 1.5 YEARS old hole LOL! > > Tomy > > Wiadomość napisana przez resea...@vulnerability-lab.com > <mailto:resea...@vulnerability-lab.com> w dniu 20 gru 2011, o godz. 17:08: > >> http://www.cert

[Full-disclosure] Whois Cart Billing - Multiple Web Vulnerabilities

2011-12-22 Thread resea...@vulnerability-lab.com
Title: == Whois Cart Billing - Multiple Web Vulnerabilities Date: = 2011-12-22 References: === http://www.vulnerability-lab.com/get_content.php?id=343 VL-ID: = 343 Introduction: = Whois.Cart() is a client/administrator tool that facilitates the many tasks in

[Full-disclosure] Kaspersky IS&AV 2011/12 - Memory Corruption Vulnerability

2011-12-22 Thread resea...@vulnerability-lab.com
Title: == Kaspersky IS&AV 2011/12 - Memory Corruption Vulnerability Date: = 2011-12-19 References: === http://www.vulnerability-lab.com/get_content.php?id=129 VL-ID: = 129 Introduction: = Kaspersky Internet Security 2011 has everything that you need to stay s

[Full-disclosure] CertificationMagazine - Blind SQL Injection Vulnerability

2011-12-22 Thread resea...@vulnerability-lab.com
Title: == CertificationMagazine - Blind SQL Injection Vulnerability Date: = 2011-12-19 VL-ID: = 269 Reference: == http://www.vulnerability-lab.com/get_content.php?id=269 Introduction: = Certification Magazine is a technical training and certification publicati

[Full-disclosure] SpamTitan v5.08 - Multiple Web Vulnerabilities

2011-12-22 Thread resea...@vulnerability-lab.com
Title: == SpamTitan v5.08 - Multiple Web Vulnerabilities Date: = 2011-12-20 References: === http://www.vulnerability-lab.com/get_content.php?id=91 VL-ID: = 91 Introduction: = SpamTitan Anti Spam is a complete software solution to email security offering prot

[Full-disclosure] Cyberoam UTM Appliance - SQL Injection Vulnerability

2011-12-22 Thread resea...@vulnerability-lab.com
Title: == Cyberoam UTM Appliance - SQL Injection Vulnerability Date: = 2011-12-19 References: === http://www.vulnerability-lab.com/get_content.php?id=60 VL-ID: = 60 Introduction: = Small and medium enterprises are as much at risk as large enterprises from the

[Full-disclosure] Kaspersky IS&AV 2011/12 - Memory Corruption Vulnerability

2011-12-22 Thread resea...@vulnerability-lab.com
Title: Kaspersky IS&AV 2011/12 - Memory Corruption Vulnerability URL: http://www.vulnerability-lab.com/get_content.php?id=129 -- Website: www.vulnerability-lab.com ; vuln-lab.com or vuln-db.com Contact: ad...@vulnerability-lab.com or supp...@vulnerability-lab.com ___

[Full-disclosure] appRain CMF v0.1.5 - Multiple Web Vulnerabilities

2011-12-18 Thread resea...@vulnerability-lab.com
Title: == appRain CMF v0.1.5 - Multiple Web Vulnerabilities Date: = 2011-12-17 References: === http://www.vulnerability-lab.com/get_content.php?id=362 VL-ID: = 362 Introduction: = appRain is one of the first officially released Opensource Content Management

[Full-disclosure] Content Papst CMS v2011.2 - Multiple Web Vulnerabilities

2011-12-18 Thread resea...@vulnerability-lab.com
Title: == Content Papst CMS v2011.2 - Multiple Web Vulnerabilities Date: = 2011-12-18 References: === http://www.vulnerability-lab.com/get_content.php?id=363 VL-ID: = 363 Introduction: = Contentpapst ist ein leistungsstarkes und sehr flexibles Content-Manage

[Full-disclosure] Adapt CMS v2.0.1 - SQL Injection Vulnerability

2011-11-28 Thread resea...@vulnerability-lab.com
Title: == Adapt CMS v2.0.1 - SQL Injection Vulnerability Date: = 2011-11-25 References: === http://www.vulnerability-lab.com/get_content.php?id=341 VL-ID: = 341 Introduction: = AdaptCMS is brought to you by Insane Visions, with the v2.0.1 versions being the

[Full-disclosure] Joomla Component (com_content) - Blind SQL Injection Vulnerability

2011-11-11 Thread resea...@vulnerability-lab.com
Title: == Joomla Component (com_content) - Blind SQL Injection Vulnerability Date: = 2011-11-11 References: === http://www.vulnerability-lab.com/get_content.php?id=323 VL-ID: = 323 Introduction: = Joomla is a free and open source content management system (C

[Full-disclosure] iGuard Biometric Access Control - Multiple Vulnerabilities

2011-11-11 Thread resea...@vulnerability-lab.com
Title: == iGuard Biometric Access Control - Multiple Vulnerabilities Date: = 2011-11-08 References: === 2011/Q3-4 URL: http://vulnerability-lab.com/get_content.php?id=104 VL-ID: = 104 Introduction: = Each iGuard Biometric / Smart Card Security Appliance has a

[Full-disclosure] Skype Vendor Website - Cross Site Scripting Vulnerability

2011-11-11 Thread resea...@vulnerability-lab.com
Title: == Skype Vendor Website - Cross Site Scripting Vulnerability Date: = 2011-11-11 References: === http://www.vulnerability-lab.com/get_content.php?id=309 VL-ID: = 309 Introduction: = Skype is a software application that allows users to make voice and vid

[Full-disclosure] WhiteHouse Gov Service - Persistent Web Vulnerability

2011-11-04 Thread resea...@vulnerability-lab.com
Title: == WhiteHouse Gov Service - Persistent Web Vulnerability Date: = 2011-11-04 References: === http://www.vulnerability-lab.com/get_content.php?id=308 VL-ID: = 308 Introduction: = http://www.whitehouse.gov/ Abstract: = The vulnerability-lab rese

[Full-disclosure] NATO Research & Technology ORG - File Include Vulnerability

2011-11-02 Thread resea...@vulnerability-lab.com
Title: == NATO Research & Technology ORG - File Include Vulnerability Date: = 2011-11-02 References: === http://www.vulnerability-lab.com/get_content.php?id=307 VL-ID: = 307 Introduction: = The NATO Research and Technology Organisation (RTO) (Organisation pou

[Full-disclosure] Prosieben Community Website - Persistent Script Code Inject

2011-11-01 Thread resea...@vulnerability-lab.com
Title: == Prosieben Community Website - Persistent Script Code Inject Date: = 2011-10-31 References: === http://www.vulnerability-lab.com/get_content.php?id=306 VL-ID: = 306 Abstract: = The Vulnerability Lab Research Team discovered a persistent script code inje

[Full-disclosure] Maxdome Website - SQL Injection Vulnerability

2011-10-28 Thread resea...@vulnerability-lab.com
Title: == Maxdome Website - SQL Injection Vulnerability Date: = 2011-10-26 References: === http://www.vulnerability-lab.com/get_content.php?id=300 VL-ID: = 300 Introduction: = maxdome ist das Video-on-Demand-Angebot der ProSiebenSat.1 Media. Das Pay-per-View

[Full-disclosure] eFront Enterprise v3.6.10 - Multiple Remote Vulnerabilities

2011-10-28 Thread resea...@vulnerability-lab.com
Title: == eFront Enterprise v3.6.10 - Multiple Remote Vulnerabilities Date: = 2011-10-27 References: === http://www.vulnerability-lab.com/get_content.php?id=298 VL-ID: = 298 Introduction: = Tailored with larger organizations in mind, eFront Enterprise offers

[Full-disclosure] Opera Browser v11.52 - Stack Buffer Overflow Vulnerability (DoS) Full

2011-10-28 Thread resea...@vulnerability-lab.com
Title: == Opera Browser v11.52 - Stack Buffer Overflow Vulnerability Date: = 2011-10-28 References: === http://www.vulnerability-lab.com/get_content.php?id=275 http://packetstormsecurity.org/files/106020/opera1152-overflow.txt VL-ID: = 299 Introduction: = Ope

[Full-disclosure] HackInTheBox Quartal Magazine - eZine Issue #007

2011-10-18 Thread resea...@vulnerability-lab.com
;) Title: == HITB Quartal Magazine - eZine Issue 007 Date: = 2011-10-18 References: === Original: http://magazine.hackinthebox.org/issues/HITB-Ezine-Issue-007.pdf Article: http://magazine.hitb.org/ Mirror: http://www.vulnerability-lab.com/resources/documents/297.pdf Article:

[Full-disclosure] Sparkasse Bank – Tricky Card Bug on ATM [ATM Adventure]

2011-10-16 Thread resea...@vulnerability-lab.com
Title: == Sparkasse Bank – Tricky Card Bug on ATM [ATM Adventure] Date: = 2011-10-17 References: === Document: http://www.vulnerability-lab.com/resources/documents/295.pdf Article: http://www.vulnerability-lab.com/dev/?p=247 VL-ID: = 295 Status: Published Exp

[Full-disclosure] Skype Software Vulnerabilities - 0 Day Exploitation 2011

2011-10-16 Thread resea...@vulnerability-lab.com
Title: == Skype Software Vulnerabilities - 0 Day Exploitation 2011 [HACK IN THE BOX MALAYSIA #2011 KUL CONFERENCE] (13th) Date: = 2011-10-16 References: === Article: http://www.vulnerability-lab.com/get_content.php?id=293 Document: http://www.vulnerability-lab.com/resources/do

[Full-disclosure] eFront Enterprise v3.6.9 - Arbitrary Download Vulnerability

2011-10-07 Thread resea...@vulnerability-lab.com
Title: == eFront Enterprise v3.6.9 - Arbitrary Download Vulnerability Date: = 2011-10-08 References: === http://www.vulnerability-lab.com/get_content.php?id=290 http://www.vulnerability-lab.com/get_content.php?id=230 VL-ID: = 290 Introduction: = Tailored with

[Full-disclosure] Apple Website - Non Persistent Cross Site Scripting Vulnerability

2011-10-07 Thread resea...@vulnerability-lab.com
Title: == Apple Website - Non Persistent Cross Site Vulnerability Date: = 2011-10-07 References: === http://www.vulnerability-lab.com/get_content.php?id=289 VL-ID: = 289 Introduction: = Our communities are filled with thousands of Mac, iPod, iPhone and iPad u

[Full-disclosure] eFront Enterprise Edition v3.6.9 - SQL Injection Vulnerability

2011-10-07 Thread resea...@vulnerability-lab.com
Title: == eFront Enterprise Edition v3.6.9 - SQL Injection Vulnerability Date: = 2011-10-07 References: === http://www.vulnerability-lab.com/get_content.php?id=230 VL-ID: = 230 Introduction: = Tailored with larger organizations in mind, eFront Enterprise offe

Re: [Full-disclosure] 0day Full disclosure: American Express

2011-10-06 Thread resea...@vulnerability-lab.com
ack Am 06.10.2011 14:38, schrieb resea...@vulnerability-lab.com: > Hey Andreas, > read the following article its fresh and new ... > http://www.vulnerability-lab.com/dev/ > This is 4 real ^^ > > > Am 06.10.2011 12:18, schrieb Andreas: >> Zitat von Carlos Alberto Lo

Re: [Full-disclosure] 0day Full disclosure: American Express

2011-10-06 Thread resea...@vulnerability-lab.com
Hey Andreas, read the following article its fresh and new ... http://www.vulnerability-lab.com/dev/ This is 4 real ^^ Am 06.10.2011 12:18, schrieb Andreas: > Zitat von Carlos Alberto Lopez Perez : > >> American Express admins looks really worried by security >> >> At least they thought about

  1   2   >