BigTree CMS <= 4.2.11 Authenticated SQL Injection Vulnerability

2016-06-27 Thread mehmet
1. ADVISORY INFORMATION Title: BigTree CMS <= 4.2.11 Authenticated SQL Injection Vulnerability Application: BigTree CMS Remotely Exploitable: Yes Versions Affected: < 4.2.11 Vendor URL: https://www.bigtreecms.org Bugs: SQL Injection Author: Mehme

BookingWizz < 5.5 Multiple Vulnerability

2016-06-15 Thread mehmet
9 Bugs: Default credentials, CSRF, XXS, SQLi Injection, LFI Date of Public Advisory: 15 Jun 2016 Author: Mehmet Ince 2. CREDIT Those vulnerabilities was identified during external penetration test by Mehmet INCE from PRODAFT / INVICTUS Original Advisory:

AfterLogic WebMail Pro ASP.NET < 6.2.7 Administrator Account Takover via XXE Injection

2016-05-23 Thread mehmet . ince
ity was identified during penetration test by Mehmet INCE & Halit Alptekin from PRODAFT / INVICTUS 3. VERSIONS AFFECTED AfterLogic WebMail Pro ASP.NET < 6.2.7 4. INTRODUCTION It seems that /webmail/spellcheck.aspx?xml