Re: [Full-disclosure] Apple WGT Dictionnaire 1.3 - Script Code Inject Vulnerability

2012-12-03 Thread Vulnerability Lab
Am 01.12.2012 18:33, schrieb Vulnerability Lab: Thanks for the response! We are working on a better automatic scoring bound to the risk system vector calculation of our db. Its all bound and normally a moderator check the content but after a ddos last week we missed to checkthe issue again. We

Re: [Full-disclosure] Apple WGT Dictionnaire 1.3 - Script Code Inject Vulnerability

2012-12-02 Thread Vulnerability Lab
Thanks for the response! We are working on a better automatic scoring bound to the risk system vector calculation of our db. Its all bound and normally a moderator check the content but after a ddos last week we missed to checkthe issue again. We are only human and mistakes happen can ... thanks.

[Full-disclosure] Apple WGT Dictionnaire 1.3 - Script Code Inject Vulnerability

2012-11-28 Thread Vulnerability Lab
Title: == Apple WGT Dictionnaire 1.3 - Script Code Inject Vulnerability Date: = 2012-11-27 References: === http://www.vulnerability-lab.com/get_content.php?id=774 VL-ID: = 774 Common Vulnerability Scoring System: 2.3 Introduction:

Re: [Full-disclosure] Apple WGT Dictionnaire 1.3 - Script Code Inject Vulnerability

2012-11-28 Thread Thor (Hammer of God)
On Nov 27, 2012, at 5:52 PM, Vulnerability Lab resea...@vulnerability-lab.com wrote: Proof of Concept: = The software validation vulnerability can be exploited by local attackers with required user interaction and privileged local system account. For demonstration or