Re: [Full-disclosure] IRM Security Advisory : RedDot CMS SQL injection vulnerability

2008-04-21 Thread reepex
so IRMPLC goes from xss in cisco products to sql injection in a small user base webapp? I think you may need to fire your current 'research' team and start over On Mon, Apr 21, 2008 at 11:06 AM, Mark Crowther [EMAIL PROTECTED] wrote: RedDot CMS SQL injection vulnerability (CVE Number:

Re: [Full-disclosure] IRM Security Advisory : RedDot CMS SQL injection vulnerability

2008-04-21 Thread n3td3v
On Mon, Apr 21, 2008 at 5:06 PM, Mark Crowther [EMAIL PROTECTED] wrote: RedDot CMS SQL injection vulnerability (CVE Number: CVE-2008-1613) http://www.irmplc.com/index.php/167-Advisory-026 Vulnerability Type/Importance: SQL injection/Critical Problem Discovered: 12 February

Re: [Full-disclosure] IRM Security Advisory : RedDot CMS SQL injection vulnerability

2008-04-21 Thread Ureleet
seems like no one is buying into your day on may 1. Quit trying to make a name for urself on other ppls research. On 4/21/08, n3td3v [EMAIL PROTECTED] wrote: On Mon, Apr 21, 2008 at 5:06 PM, Mark Crowther [EMAIL PROTECTED] wrote: RedDot CMS SQL injection vulnerability (CVE Number:

Re: [Full-disclosure] IRM Security Advisory : RedDot CMS SQL injection vulnerability

2008-04-21 Thread n3td3v
On Mon, Apr 21, 2008 at 8:36 PM, Ureleet [EMAIL PROTECTED] wrote: seems like no one is buying into your day on may 1. I don't agree with you. Quit trying to make a name for urself on other ppls research. Its about web applicaton security awareness.