[FD] Exponent CMS 2.3.9 - Useraccounts Persistent Vulnerability

2016-07-28 Thread Vulnerability Lab
atory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, eith

[FD] Zortam Media Studio 20.60 - Buffer Overflow Vulnerability

2016-07-28 Thread Vulnerability Lab
amp; Authors: == ZwX - [http://www.vulnerability-lab.com/show.php?user=ZwX] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or

[FD] VUPlayer 2.49 - (.wax) Buffer Overflow Vulnerability

2016-07-27 Thread Vulnerability Lab
w.php?user=ZwX] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particula

[FD] VUPlayer 2.49 - (.pls) Buffer Overflow Vulnerability

2016-07-27 Thread Vulnerability Lab
= The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its s

[FD] DornCMS v1.4 - (FileManager) Persistent Cross Site Scripting Vulnerability

2016-07-27 Thread Vulnerability Lab
tory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, eithe

[FD] Nusiorung CMS 2016 - (Login) Auth Bypass Vulnerability

2016-07-27 Thread Vulnerability Lab
== The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable

[FD] SEC Consult SA-20160725-0 :: Multiple vulnerabilities in Micro Focus (Novell) Filr

2016-07-25 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20160725-0 > === title: Multiple vulnerabilities product: Micro Focus (former Novell) Filr Appliance vulnerable version: Filr 2 <=2.0.0.421,

[FD] Django CMS v3.3.0 - (Editor Snippet) Persistent Web Vulnerability (CVE-2016-6186)

2016-07-19 Thread Vulnerability Lab
oratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either

[FD] BMW ConnectedDrive - (Update) VIN Session Vulnerability

2016-07-08 Thread Vulnerability Lab
Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (resea...@vulnerability-lab.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any

[FD] BMW - (Token) Client Side Cross Site Scripting Vulnerability

2016-07-08 Thread Vulnerability Lab
his advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, in

[FD] Zero-day flaw lets hackers tamper with your car through BMW portal

2016-07-07 Thread Vulnerability Lab
Title: Zero-day flaw lets hackers tamper with your car through BMW portal URL: http://www.zdnet.com/article/hackers-can-tamper-with-car-registration-through-bmw-connected-car-portal/ -- VULNERABILITY LABORATORY - RESEARCH TEAM SERVICE: www.vulnerability-lab.com CONTACT:

[FD] Micron CMS v5.3 - (cat_id) SQL Injection Vulnerability

2016-07-06 Thread Vulnerability Lab
sclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerab

[FD] KWSPHP CMS v1.6.995 - Persistent Cross Site Scripting Web Vulnerability

2016-07-04 Thread Vulnerability Lab
om/show.php?user=ZwX ] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability f

[FD] Iranian Weblog Services v3.3 CMS - Multiple Web Vulnerabilities

2016-06-28 Thread Vulnerability Lab
.Net] [http://www.vulnerability-lab.com/show.php?user=Iran%20Cyber%20Security] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, includin

[FD] Ladesk Agent #1 (Bug Bounty) - Session Reset Password Vulnerability

2016-06-28 Thread Vulnerability Lab
ulnerability-lab.com) [www.vulnerability-lab.com] [http://www.vulnerability-lab.com/show.php?user=Benjamin%20K.M.] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warr

[FD] SEC Consult SA-20160624-0 :: ASUS DSL-N55U router XSS and information disclosure

2016-06-24 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20160624-0 > === title: XSS and information disclosure vulnerability product: ASUS DSL-N55U router vulnerable version: 3.0.0.4.376_2736

[FD] Wordpress Levo-Slideshow 2.3 - Arbitrary File Upload Vulnerability

2016-06-07 Thread Vulnerability Lab
& Authors: == Aaditya Purani - (https://aadityapurani.com) [http://www.vulnerability-lab.com/show.php?user=Aaditya%20Purani] Disclaimer & Information: ========= The information provided in this advisory is provided as it is without any warranty. Vulnerab

[FD] Mapbox (API) - Filter Bypass & Persistent Vulnerability

2016-06-07 Thread Vulnerability Lab
Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of

[FD] SEC Consult SA-20160602-0 :: Multiple critical vulnerabilities in Ubee EVW3226 Advanced wireless voice gateway

2016-06-02 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20160602-0 > === title: Multiple critical vulnerabilities product: Ubee EVW3226 Advanced wireless voice gateway vulnerable version: Fi

[FD] Bashi v1.6 iOS - Persistent Mail Encoding Vulnerability

2016-05-25 Thread Vulnerability Lab
= The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its

[FD] Bugcrowd Bug Bounty #7 - Persistent Web Vulnerability

2016-05-25 Thread Vulnerability Lab
[http://www.vulnerability-lab.com/show.php?user=Benjamin%20K.M.] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties

[FD] Teampass v2.1.26 - Stored Cross Site Scripting Vulnerability

2016-05-25 Thread Vulnerability Lab
l name field to a script code payload Note: Vulnerability Lab">http://www.vulnerability-lab.com/; onload=alert(document.cookie)<> or 3. The execute occurs in the main label field output context value 4. Successful reproduce of the application-side vulnerability! --- PoC Session L

[FD] Teampass v2.1.25 - Arbitrary File Download Vulnerability

2016-05-25 Thread Vulnerability Lab
amp; Information: ===== The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vuln

[FD] Notes v4.5 iOS - Arbitrary File Upload Vulnerability

2016-05-10 Thread Vulnerability Lab
K.M.] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its

[FD] Skype Manager - (Email Change) Filter Bypass Vulnerability

2016-05-10 Thread Vulnerability Lab
do match with the case scenario. Credits & Authors: == Karim Rahal [ka...@karimrahal.com / karim...@elitesec.org] - @KarimMTV Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerabilit

[FD] Wordpress Truemag Theme - Client Side Cross Site Scripting Web Vulnerability

2016-04-29 Thread Vulnerability Lab
%20Security] Special Thanks: root3r Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability

[FD] Oracle Discoverer Viewer BI - Open Redirect Vulnerability

2016-04-27 Thread Vulnerability Lab
The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liabl

[FD] Sophos XG Firewall (SF01V) - Persistent Web Vulnerability

2016-04-26 Thread Vulnerability Lab
w.php?user=Lawrence%20Amer ) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantabi

[FD] VoipNow v4.0.1 - (xajax_handler) Persistent Vulnerability

2016-04-26 Thread Vulnerability Lab
mation: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its s

[FD] Negin Group CMS - (v) Multiple Web Vulnerabilities

2016-04-25 Thread Vulnerability Lab
is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirec

[FD] Django CMS v3.2.3 - Filter Bypass & Persistent Vulnerability

2016-04-25 Thread Vulnerability Lab
llow usage of special chars and escapte the entries to prevent further application-side script code injection attacks. Security Risk: == The security risk of the application-side input validation vulnerability and filter bypass issue is estimated as medium. (CVSS 3.6) Credit

[FD] Cyberoam Central Console v02.03.1 - Multiple Persistent Vulnerabilities

2016-04-25 Thread Vulnerability Lab
- ( http://www.vulnerability-lab.com/show.php?user=Lawrence%20Amer ) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, in

[FD] UBNT Bug Bounty #2 - XML External Entity Vulnerability

2016-04-25 Thread Vulnerability Lab
this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, includ

[FD] Totemomail v4.x & v5.x - Filter Bypass & Persistent Vulnerability

2016-04-25 Thread Vulnerability Lab
n appliance web-application. Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (resea...@vulnerability-lab.com) [www.vulnerability-lab.com] Disclaimer & Information: ===== The information provided in this advisory is

[FD] SEC Consult SA-20160422-0 :: Insecure credential storage in my devolo Android app

2016-04-22 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20160422-0 > === title: Insecure data storage product: my devolo - android application - air.de.devolo.my.devolo vulnerable version: 1.2.8

[FD] Django CMS v3.2.3 - Filter Bypass & Persistent Vulnerability

2016-04-14 Thread Vulnerability Lab
sk of the application-side input validation web vulnerability in the django cms is estimated as medium. (CVSS 3.6) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: =

[FD] Webline CMS (2016Q2) - SQL Injection Vulnerability

2016-04-13 Thread Vulnerability Lab
, nazanin_wild and 0xdevil Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a par

[FD] WP Multiple Meta Box v1.0 - SQL Injection Vulnerability

2016-04-08 Thread Vulnerability Lab
ded in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, includ

[FD] Eight Webcom CMS (2016 Q2) - SQL Injection Vulnerability

2016-04-07 Thread Vulnerability Lab
lack , whitewolf , mr.s4jj4d , mr.turk , 0day , pi.hack , l3gi0n , nazanin_wild and 0xdevil Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed o

[FD] Techsoft WS CMS (2016 Q2) - SQL Injection Web Vulnerability

2016-04-07 Thread Vulnerability Lab
ck , l3gi0n , nazanin_wild and 0xdevil Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capab

[FD] Apple iOS 9.3.1 (iPhone 6S & iPhone Plus) - (3D Touch) Passcode Bypass Vulnerability

2016-04-05 Thread Vulnerability Lab
The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable

[FD] Techsoft Web Solutions CMS 2016 Q2 - SQL Injection Web Vulnerability

2016-04-04 Thread Vulnerability Lab
ck , l3gi0n , nazanin_wild and 0xdevil Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability a

[FD] Wordpress Scoreme Theme - Client Side Cross Site Scripting Web Vulnerability

2016-04-04 Thread Vulnerability Lab
3gi0n, mr.turk , 0xdevil , king_k4li Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capabil

[FD] Python v2.7 v1.5.4 iOS - Filter Bypass & Persistent Vulnerability

2016-03-31 Thread Vulnerability Lab
= The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its supplie

[FD] Trend Micro (SSO) - (Backend) SSO Redirect & Session Vulnerability

2016-03-31 Thread Vulnerability Lab
T3qwAAbpfxk8XLzrgFKnerkc.NAAUqd6uR22UgXJ6WAA--] Content-Length[382] X-Firefox-Spdy[h2] Security Risk: == The security risk of the session web and redirect vulnerability in the trend micro sso online service web-application is estimated as high. (C

[FD] Cades (2016Q1) - (id) Multiple SQL Injection Vulnerabilities

2016-03-31 Thread Vulnerability Lab
ities in the web-application are estimated as high. (CVSS 7.5) Credits & Authors: == Dr.Malware Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all war

[FD] Docker UI v0.10.0 - Multiple Persistent Vulnerabilities

2016-03-31 Thread Vulnerability Lab
er=Manideep%20K.] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a par

[FD] WP External Links v1.80 - Cross Site Scripting Web Vulnerabilities

2016-03-31 Thread Vulnerability Lab
The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers ar

[FD] Hi Technology & Services CMS - SQL Injection Vulnerabilities

2016-03-31 Thread Vulnerability Lab
i Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab

[FD] ChitaSoft (Web-Application) - SQL Injection Vulnerability

2016-03-14 Thread Vulnerability Lab
it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, in

[FD] Chamlio LMS v1.10.2 - (Profile) Persistent Web Vulnerability

2016-03-14 Thread Vulnerability Lab
ecurity risk of the application-side validation web vulnerability in the profile module is estimated as medium. (CVSS 3.4) Credits & Authors: == Vulnerability Laboratory [Research Team] - Lawrence Amer - http://www.vulnerability-lab.com/show.php?user=Lawrence%20Amer Discl

[FD] Apple iOS v9.2.1 - Multiple PassCode Bypass Vulnerabilities (App Store Link, Buy Tones Link & Weather Channel Link)

2016-03-07 Thread Vulnerability Lab
=== Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (resea...@vulnerability-lab.com) [http://www.vulnerability-lab.com/show.php?user=Benjamin%20K.M.] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability La

[FD] WP Good News Themes - Client Side Cross Site Scripting Web Vulnerability

2016-02-29 Thread Vulnerability Lab
== The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its

[FD] GTA Firewall GB-OS v6.2.02 - Filter Bypass & Persistent Vulnerability

2016-02-24 Thread Vulnerability Lab
Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: ===== The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed

[FD] eFront Learning 3.6.15.6 CMS - (Forum) Persistent Title Web Vulnerability

2016-02-24 Thread Vulnerability Lab
ttp://www.vulnerability-lab.com/show.php?user=Lawrence%20Amer Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties

[FD] Prezi Bug Bounty #7 - (Charts) Persistent Vulnerability

2016-02-23 Thread Vulnerability Lab
rability-lab.com/show.php?user=Milan%20A%20Solanki] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warrantie

[FD] InstantCoder v1.0 iOS - Multiple Web Vulnerabilities

2016-02-23 Thread Vulnerability Lab
this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, inc

[FD] Oxwall Forum v1.8.1 - Persistent Cross Site Scripting Vulnerability

2016-02-22 Thread Vulnerability Lab
er & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vuln

[FD] Adobe - Multiple Client Side Cross Site Scripting Web Vulnerabilities

2016-02-19 Thread Vulnerability Lab
p; Authors: ====== Daniel Díez Tainta - (@DaniLabs) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warrantie

[FD] Chamilo LMS - Persistent Cross Site Scripting Vulnerability

2016-02-19 Thread Vulnerability Lab
ty in the web-application is estimated as medium. (CVSS 3.3) Credits & Authors: == Lawrence Amer - ( http://www.vulnerability-lab.com/show.php?user=Lawrence%20Amer ) Disclaimer & Information: = The information provided in this advisory is provi

[FD] Chamilo LMS IDOR - (messageId) Delete POST Inject Vulnerability

2016-02-19 Thread Vulnerability Lab
amp; Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its supplier

[FD] Prezi Bug Bounty #5 - Client Side Cross Site Scripting & Open Redirect Vulnerability

2016-02-19 Thread Vulnerability Lab
- (milans...@gmail.com) [http://www.safehacking4mas.blogspot.in] [https://www.facebook.com/Mas.Hackers] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warrantie

[FD] ifixit Bug Bounty #6 -(Profile) Persistent Vulnerability

2016-02-19 Thread Vulnerability Lab
mation provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any

[FD] ifixit Bug Bounty #5 - Guide Search Persistent Vulnerability

2016-02-19 Thread Vulnerability Lab
tent input validation web vulnerability in the ifixit.com online service web-application is estimated as medium. (CVSS 3.8) Credits & Authors: == Vulnerability Laboratory [Research Team] - Hadji Samir (sa...@evolution-sec.com) [http://www.vulnerability-lab.com/show.php?us

[FD] HD Video Player v2.5 iOS - Multiple Web Vulnerabilities

2016-02-12 Thread Vulnerability Lab
= Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (resea...@vulnerability-lab.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab dis

[FD] File Sharing Manager v1.0 iOS - Multiple Web Vulnerabilities

2016-02-10 Thread Vulnerability Lab
@vulnerability-lab.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchan

[FD] Apache Sling Framework v2.3.6 (Adobe AEM) [CVE-2016-0956] - Information Disclosure Vulnerability

2016-02-10 Thread Vulnerability Lab
.@evolution-sec.com) [www.vulnerability-lab.com] (https://twitter.com/cybercrimenews) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied

[FD] SEC Consult SA-20160210-0 :: Yeager CMS Multiple Vulnerabilities

2016-02-10 Thread SEC Consult Vulnerability Lab
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 SEC Consult Vulnerability Lab Security Advisory < 20160210-0 > === title: Multiple Vulnerabilities product: Yeager CMS vulnerable version:

[FD] JavaScript Anywhere v3.0.4 iOS - Persistent Vulnerability

2016-02-08 Thread Vulnerability Lab
vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a

[FD] PressePortal NewsAktuell (DPA) - Multiple Vulnerabilities

2016-02-08 Thread Vulnerability Lab
[Research Team] - Marco Onorati [http://www.vulnerability-lab.com/show.php?user=Marco%20Onorati] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expr

[FD] Getdpd BB #3 - Persistent Cross Site Scripting Vulnerability

2016-02-08 Thread Vulnerability Lab
ww.vulnerability-lab.com/show.php?user=Hadji%20Samir] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of

[FD] Getdpd BB #4 - (name) Persistent Validation Vulnerability

2016-02-08 Thread Vulnerability Lab
alidation web vulnerability in the frontend of the getdpd web-application is estimated as medium. (CVSS 3.8) Credits & Authors: ====== Vulnerability Laboratory [Research Team] - Hadji Samir [sa...@evolution-sec.com] Disclaimer & Information: = The informat

[FD] Getdpd BB #5 - Persistent Filename Vulnerability

2016-02-08 Thread Vulnerability Lab
he frontend of the getdpd web-application is estimated as medium. (CVSS 4.2) Credits & Authors: == Vulnerability Laboratory [Research Team] - Hadji Samir [sa...@evolution-sec.com] [www.vulnerability-lab.com] (http://www.vulnerability-lab.com/show.php?user=Hadji%20Samir)

[FD] Ebay Inc (Pages) - Client Side Cross Site Scripting Vulnerabilities

2016-02-08 Thread Vulnerability Lab
s Credits & Authors: == Daniel Díez Tainta - (@DaniLabs) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, inc

[FD] Alsovalue CMS 2016Q1 - SQL Injection Web Vulnerability

2016-02-08 Thread Vulnerability Lab
imer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its su

[FD] Apple iOS v9.1, 9.2 & 9.2.1 - Application Update Loop Pass Code Bypass

2016-02-04 Thread Vulnerability Lab
sea...@vulnerability-lab.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties

[FD] Soso Transfer v1.1 iOS - Denial of Service Vulnerability

2016-02-03 Thread Vulnerability Lab
as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental,

[FD] Getdpd Bug Bounty #1 - (asm0option0) Persistent Web Vulnerability

2016-02-03 Thread Vulnerability Lab
= Vulnerability Laboratory [Research Team] - Hadji Samir [sa...@evolution-sec.com] [www.vulnerability-lab.com] (http://www.vulnerability-lab.com/show.php?user=Hadji%20Samir) Disclaimer & Information: = The information provided in this advisory is provided as it

[FD] File Manager PRO v1.3 iOS - Multiple Web Vulnerabilities

2016-02-03 Thread Vulnerability Lab
application is estimated as high. (CVSS 7.3) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (resea...@vulnerability-lab.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as

[FD] Compal ConnectBox Wireless - Passphrase Settings Filter Bypass Vulnerability

2016-02-03 Thread Vulnerability Lab
[Research Team] - Marco Onorati Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and

[FD] Soso Transfer v1.1 iOS - Denial of Service Vulnerability

2016-02-03 Thread Vulnerability Lab
as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental,

[FD] Netlife Photosuite Pro - Client Side Cross Site Scripting Vulnerability

2016-02-01 Thread Vulnerability Lab
ts & Authors: == Iran Cyber Security Group - 0x3a (ICG SEC) [Iran-Cyber.Net] [http://www.vulnerability-lab.com/show.php?user=Iran%20Cyber%20Security] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warrant

[FD] File Hub v3.3 iOS (Wifi) - Multiple Web Vulnerabilities

2016-02-01 Thread Vulnerability Lab
Benjamin Kunz Mejri (resea...@vulnerability-lab.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including t

[FD] New Era Company CMS - (id) SQL Injection Vulnerability

2016-01-28 Thread Vulnerability Lab
rity Group - 0x3a (ICG SEC) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capabi

[FD] Kleefa v1.7 (IR) - Multiple Web Vulnerabilities

2016-01-27 Thread Vulnerability Lab
ing web vulnerabilities in the web-application are estimated as medium. (CVSS 3.3) Credits & Authors: == Iran Cyber Security Group - (ICG SEC) Disclaimer & Information: = The information provided in this advisory is provided as it is without any war

[FD] los818 CMS 2016 Q1 - SQL Injection Web Vulnerability

2016-01-27 Thread Vulnerability Lab
ded as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, i

[FD] Secure Item Hub v1.0 iOS - Multiple Web Vulnerabilities

2016-01-27 Thread Vulnerability Lab
y [Research Team] - Benjamin Kunz mejri (resea...@vulnerability-lab.com) [www.vulnerability-lab.com] Disclaimer & Information: ===== The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either exp

[FD] Apple WatchOS v2.1 - Denial of Service Vulnerability

2016-01-27 Thread Vulnerability Lab
za.es] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpos

[FD] Telegram (API) - Cross Site Request Forgery Vulnerabilities

2016-01-27 Thread Vulnerability Lab
estimated as medium. (CVSS 3.2) Credits & Authors: == Lawrence Amer - ( http://www.vulnerability-lab.com/show.php?user=Lawrence%20Amer ) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty.

[FD] Ebay Magento Bug Bounty #2 - Persistent Web Vulnerability

2016-01-27 Thread Vulnerability Lab
rity Risk: == The security risk of the persistent mail encoding web vulnerability and the web-server validation misconfiguration are estimated as medium. (CVSS 3.7) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com

[FD] SEC Consult SA-20160121-0 :: Deliberately hidden backdoor account in AMX (Harman Professional) devices

2016-01-21 Thread SEC Consult Vulnerability Lab
for more information. SEC Consult Vulnerability Lab Security Advisory < 20160121-0 > === title: Deliberately hidden backdoor account product: Several AMX (HARMAN Professional) device

[FD] Switch v4.68 - Code Execution Vulnerability

2015-12-22 Thread Vulnerability Lab
d as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidenta

[FD] POP Peeper 4.0.1 - Persistent Code Execution Vulnerability

2015-12-22 Thread Vulnerability Lab
out any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequ

[FD] Lithium Forum - (previewImages) Persistent Vulnerability

2015-12-22 Thread Vulnerability Lab
ility Laboratory [Research Team] – Hadji Samir (sa...@evolution-sec.com) [http://www.vulnerability-lab.com/show.php?user=Hadji%20Samir] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warrantie

[FD] Aeris Calandar v2.1 - Buffer Overflow Vulnerability

2015-12-22 Thread Vulnerability Lab
tion: ===== The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerabil

[FD] DELL Scrutinizer v12.0.3 - Persistent Software Vulnerability

2015-12-22 Thread Vulnerability Lab
== The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not

[FD] Murgent CMS - SQL Injection Vulnerability

2015-11-17 Thread Vulnerability Lab
a Turk and All Of My Friends Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability fo

[FD] Free WMA MP3 Converter - Buffer Overflow Exploit (SEH)

2015-11-17 Thread Vulnerability Lab
print " Email: m...@live.fr" Security Risk: ====== The security risk of the local buffer overflow (SEH) Vulnerability in the converter software is estimated as high. (CVSS 7.5) Credits & Authors: == ZwX - (http://zwx.fr) [ http://www.vulnerability-lab

[FD] Port Scan v2.0 iOS - Command Inject Vulnerability

2015-11-17 Thread Vulnerability Lab
- Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the

[FD] SEC Consult SA-20151105-0 :: Insecure default configuration in Ubiquiti Networks products

2015-11-05 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20151105-0 > === title: Insecure default configuration product: various Ubiquiti Networks products vulnerable version: see Vulnerable / tested ve

<    1   2   3   4   5   6   7   >