Barracuda Appliances - Validation Filter Bypass Vulnerability

2012-08-01 Thread Vulnerability Lab
is estimated as high(-). Credits: Vulnerability Laboratory [Research Team] -Benjamin Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties

Barracuda SSL VPN 680 - Cross Site Scripting Vulnerabilities

2012-08-01 Thread Vulnerability Lab
] -Benjamin Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability

ME Application Manager 10 - Multiple Web Vulnerabilities

2012-08-01 Thread Vulnerability Lab
] - Ibrahim El-Sayed [storm] (st...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability

Distimo Monitor 6.0 - Multiple Cross Site Vulnerabilities

2012-08-01 Thread Vulnerability Lab
(b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose

ME Mobile Application Manager v10 - SQL Vulnerabilities

2012-08-01 Thread Vulnerability Lab
are estimated as high. Credits: Vulnerability Laboratory [Research Team] - Ibrahim El-Sayed [storm] (st...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties

Kaspersky PM 5.0.0.164 - Software Filter Vulnerability

2012-08-01 Thread Vulnerability Lab
: Vulnerability Laboratory [Research Team] -Benjamin Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including

Kaspersky Password Manager 5.0.0.164 - Software Filter Vulnerability

2012-08-02 Thread Vulnerability Lab
: Vulnerability Laboratory [Research Team] -Benjamin Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including

Joomla com_package - SQL Injection Vulnerability

2012-08-06 Thread Vulnerability Lab
) Abstract: = A Vulnerability-Lab researcher discovered a SQL injection vulnerability in the com_package module of the joomla CMS. Report-Timeline: 2012-07-08: Public or Non-Public Disclosure Status: Published Exploitation-Technique

iAuto Mobile Application 2012 - Multiple Web Vulnerabilities

2012-08-06 Thread Vulnerability Lab
...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability

Inout Mobile Webmail APP - Multiple Web Vulnerabilities

2012-08-06 Thread Vulnerability Lab
any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental

BeneficialBank Business v4.13.1 - Auth Bypass Vulnerability

2012-08-06 Thread Vulnerability Lab
: = A Vulnerability-Lab researcher discovered an SQL injection vulnerability in the Beneficial Bank Business Banking v4.13.1 CMS. Report-Timeline: 2012-07-09: Public or Non-Public Disclosure Status: Published Exploitation-Technique: === Remote

Flogr v2.5.6 v2.3 - Cross Site Script Vulnerabilities

2012-08-09 Thread Vulnerability Lab
Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its

Joomla com_fireboard - SQL Injection Vulnerability

2012-08-09 Thread Vulnerability Lab
provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case

Arasism (IR) CMS - File Upload Vulnerability

2012-08-09 Thread Vulnerability Lab
Shahmohamadi - (resea...@sec-lab.ir) [www.sec-lab.ir] - TEAM K0242 Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability

Flynax General Classifieds v4.0 CMS - Multiple Vulnerabilities

2012-08-14 Thread Vulnerability Lab
-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab

7sepehr CMS 2012 - Multiple SQL Injection Vulnerabilities

2012-08-14 Thread Vulnerability Lab
: Nafsh - Ehram Shahmohamadi - (resea...@sec-lab.ir) [www.sec-lab.ir] - TEAM K0242 Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties

Social Engine v4.2.5 - Multiple Web Vulnerabilities

2012-08-17 Thread Vulnerability Lab
risk of the client side cross site scripting vulnerability is estimated as low(+). Credits: X-Cisadane Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied

ShopperPress v2.7 Wordpress - SQL Injection Vulnerability

2012-08-17 Thread Vulnerability Lab
is estimated as high(-). Credits: Vulnerability Laboratory [Research Team] -Benjamin Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either

ShopperPress v2.7 Wordpress - Cross Site Vulnerabilities

2012-08-17 Thread Vulnerability Lab
any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental

Nike+ Panel Mobile App - Multiple Web Vulnerabilities

2012-08-17 Thread Vulnerability Lab
of the Homepage: http://itunes.apple.com/de/app/nike+-fuelband/id493325070?mt=8# ) Abstract: = Vulnerability-Lab Team discovered multiple Web Vulnerabilities in the Nike+ Control Panel fuelband mobile web application. Report-Timeline: 2012-04-06: Researcher Notification

ManageEngine OpStor v7.4 - Multiple Web Vulnerabilities

2012-08-17 Thread Vulnerability Lab
] - Ibrahim El-Sayed (the_storm) [st...@vulnerability-lab.com] [iel-sayed.blogspot.com] Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties

eFront Educational v3.6.11 - Multiple Web Vulnerabilities

2012-09-05 Thread Vulnerability Lab
: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case

eFront Enterprise v3.6.11 - Multiple Web Vulnerabilities

2012-09-05 Thread Vulnerability Lab
Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability

Barracuda Web Filter 910 5.0.015 - Multiple Vulnerabilities

2012-09-05 Thread Vulnerability Lab
and groups, or network IP address ranges. (Copy of the Vendor Homepage: http://www.barracudanetworks.com/ns/products/web-filter-overview.php ) Abstract: = The Vulnerability Lab Research Team discovered multiple Web Vulnerabilities in Barracudas Web Filter Application v5.0.0.015

Knowledge Base EE v4.62.0 - SQL Injection Vulnerability

2012-09-13 Thread Vulnerability Lab
: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable

Fortigate UTM WAF Appliance - Multiple Web Vulnerabilities

2012-09-13 Thread Vulnerability Lab
: = Vulnerability-Lab Research Team discovered multiple persistent Web Vulnerabilities in the FortiGate UTM Appliance Application. Report-Timeline: 2012-05-06: Researcher Notification Coordination 2012-05-10: Vendor Notification 2012-06-11: Vendor Response

ASTPP VoIP Billing (4cf207a) - Multiple Web Vulnerabilities

2012-09-17 Thread Vulnerability Lab
of the persistent web vulnerabilities are estimated as high(-). Credits: Vulnerability Laboratory [Research Team] -Benjamin Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab

NeoBill CMS v0.8 Alpha - Multiple Web Vulnerabilities

2012-09-17 Thread Vulnerability Lab
as low(+)|(-)medium. Credits: Vulnerability Laboratory [Research Team] -Benjamin Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either

Axis VoIP Manager v2.1.5.7 - Multiple Web Vulnerabilities

2012-09-18 Thread Vulnerability Lab
-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business profits

SonicWALL EMail Security 7.3.5 - Multiple Vulnerabilities

2012-09-18 Thread Vulnerability Lab
) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its

Fortigate UTM WAF Appliance - Multiple Web Vulnerabilities

2012-09-18 Thread Vulnerability Lab
: = Vulnerability-Lab Research Team discovered multiple persistent Web Vulnerabilities in the FortiGate UTM Appliance Application. Report-Timeline: 2012-05-06: Researcher Notification Coordination 2012-05-10: Vendor Notification 2012-06-11: Vendor Response

Fortigate UTM WAF Appliance - Cross Site Vulnerabilities

2012-09-18 Thread Vulnerability Lab
. The military provides high security standards save outdoor camps, air base, offices with fortigate hardware. (Copy from the Vendor Homepage: http://www.fortinet.com/products/fortigate ) Abstract: = Vulnerability-Lab Research Team discovered multiple non-persistent Web Vulnerabilities

GTA UTM Firewall GB 6.0.3 - Multiple Web Vulnerabilities

2012-10-02 Thread Vulnerability Lab
Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular

Switchvox Asterisk v5.1.2 - Multiple Web Vulnerabilities

2012-10-02 Thread Vulnerability Lab
as medium(+). Credits: Vulnerability Laboratory [Research Team] -Ibrahim M. El-Sayed [the StOrM) (st...@vulnerability-lab.com) [http://iel-sayed.blogspot.com] Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab

Better WP Security v3.4.3 Wordpress - Web Vulnerabilities

2012-10-02 Thread Vulnerability Lab
as medium. Credits: Vulnerability Laboratory [Research Team] -Benjamin Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed

Switchvox Asterisk v5.1.2 - Multiple Web Vulnerabilities

2012-10-02 Thread Vulnerability Lab
as medium(+). Credits: Vulnerability Laboratory [Research Team] -Ibrahim M. El-Sayed [the StOrM) (st...@vulnerability-lab.com) [http://iel-sayed.blogspot.com] Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab

Omnistar Mailer v7.2 - Multiple Web Vulnerabilities

2012-10-03 Thread Vulnerability Lab
in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including

Interspire Email Marketer v6.0.1 - Multiple Vulnerabilites

2012-10-09 Thread Vulnerability Lab
) [st...@vulnerability-lab.com] [iel-sayed.blogspot.com] Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability

GTA UTM Firewall GB 6.0.3 - Multiple Web Vulnerabilities

2012-10-09 Thread Vulnerability Lab
: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers

Endpoint Protector v4.0.4.0 - Multiple Web Vulnerabilities

2012-10-09 Thread Vulnerability Lab
: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers

vOlk Botnet Framework v4.0 - Multiple Web Vulnerabilities

2012-10-10 Thread Vulnerability Lab
. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss

CMSQLITE v1.3.2 - Multiple Web Vulnerabiltiies

2012-10-19 Thread Vulnerability Lab
The security risk of the client site cross site request forgery vulnerabilties are estimated as low(+). Credits: Katharina S.L. (ka...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab

NetCat CMS v5.0.1 - Multiple Web Vulnerabilities

2012-11-01 Thread Vulnerability Lab
(-). Credits: SECURITY EFFECT [Research Team] - (http://seceffect.tumblr.com/) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties

VaM Shop v1.69 - Multiple Web Vulnerabilities

2012-11-01 Thread Vulnerability Lab
vulnerability is estimated as low(+). Credits: SECURITY EFFECT [Research Team] - (http://seceffect.tumblr.com/) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied

BananaDance Wiki b2.2 - Multiple Web Vulnerabilities

2012-11-12 Thread Vulnerability Lab
in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including

Eventy CMS v1.8 Plus - Multiple Web Vulnerablities

2012-11-13 Thread Vulnerability Lab
: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case

Zoner Photo Studio v15 b3 - Buffer Overflow Vulnerabilities

2012-11-13 Thread Vulnerability Lab
in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct

iDev Rentals v1.0 - Multiple Web Vulnerabilities

2012-11-14 Thread Vulnerability Lab
(the_storm) [st...@vulnerability-lab.com] [iel-sayed.blogspot.com] Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability

Akeni LAN v1.2.118 - Filter Bypass Vulnerability (Local)

2012-11-19 Thread Vulnerability Lab
any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental

Manage Engine Exchange Reporter v4.1 - Multiple Web Vulnerabilites

2012-11-19 Thread Vulnerability Lab
: Vulnerability Laboratory [Research Team] - Ibrahim El-Sayed (the_storm) [st...@vulnerability-lab.com] [iel-sayed.blogspot.com] Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either

SonicWALL CDP 5040 v6.x - Multiple Web Vulnerabilities

2012-11-20 Thread Vulnerability Lab
: = Vulnerability Lab Research Team discovered multiple Vulnerabilities in SonicWalls Continuous Data Protection v6.x 5040 appliance application. Report-Timeline: 2012-05-04: Researcher Notification Coordination 2012-05-08: Vendor Notification 1 2012-08-10: Vendor

ManageEngine ServiceDesk 8.0 - Multiple Vulnerabilities

2012-11-21 Thread Vulnerability Lab
as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental

FortiGate FortiDB 2kB 1kC 400B - Cross Site Vulnerability

2012-12-03 Thread Vulnerability Lab
provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage

FortiWeb 4kC,3kC,1kC VA - Cross Site Vulnerabilities

2012-12-03 Thread Vulnerability Lab
warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss

Enterpriser16 LoadBalancer v7.1 - Multiple Web Vulnerabilities

2012-12-19 Thread Vulnerability Lab
El-Sayed (the_storm) [st...@vulnerability-lab.com] [iel-sayed.blogspot.com] Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties

Log Analyzer 3.6.0 - Cross Site Scripting Vulnerability

2012-12-28 Thread Vulnerability Lab
- [http://johncrackernet.blogspot.com] Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular

SonicWall Email Security 7.4.1.x - Persistent Web Vulnerability

2012-12-28 Thread Vulnerability Lab
(+). Credits: Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied

Wordpress Valums Uploader - File Upload Vulnerability

2013-01-22 Thread Vulnerability Lab
: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any

nCircle PureCloud Vulnerability Scanner - Multiple Web Vulnerabilities

2013-01-29 Thread Vulnerability Lab
(+). Credits: Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied

Fortinet FortiMail 400 IBE - Multiple Web Vulnerabilities

2013-01-29 Thread Vulnerability Lab
[Research Team] - Benjamin Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability

Kohana Framework v2.3.3 - Directory Traversal Vulnerability

2013-01-29 Thread Vulnerability Lab
: Vulnerability Laboratory [Research Team] - Karim B. (k...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties

0day full - Free Monthly Websites v2.0 - Multiple Web Vulnerabilities

2013-02-04 Thread Vulnerability Lab
) Greetz 2: X-Code, Borneo Crew, Depok Cyber, Explore Crew, CodeNesia, Bogor-H, Jakarta Anonymous Club and Ngobas Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied

Sonicwall Scrutinizer v9.5.2 - SQL Injection Vulnerability

2013-02-14 Thread Vulnerability Lab
Title: == Sonicwall Scrutinizer v9.5.2 - SQL Injection Vulnerability Date: = 2013-02-13 References: === http://www.vulnerability-lab.com/get_content.php?id=789 #9984: Investigate Vulnerability Lab issues (this ticket included tracking the creation of our DBI shim to error

Sonicwall Scrutinizer v9.5.2 - SQL Injection Vulnerability

2013-02-21 Thread Vulnerability Lab
Title: == Sonicwall Scrutinizer v9.5.2 - SQL Injection Vulnerability Date: = 2013-02-13 References: === http://www.vulnerability-lab.com/get_content.php?id=789 #9984: Investigate Vulnerability Lab issues (this ticket included tracking the creation of our DBI shim to error

MyFi Wireless Disk 1.2 iPad iPhone - Multiple Vulnerabilities

2013-02-21 Thread Vulnerability Lab
is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct

Kayako Fusion v4.51.1891 - Multiple Web Vulnerabilities

2013-02-25 Thread Vulnerability Lab
] - Benjamin Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability

TagScanner v5.1 - Stack Buffer Overflow Vulnerability

2013-03-13 Thread Vulnerability Lab
) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers

MailOrderWorks v5.907 - Multiple Web Vulnerabilities

2013-04-01 Thread Vulnerability Lab
: Vulnerability Laboratory [Research Team] - Ibrahim El-Sayed (the_storm) [st...@vulnerability-lab.com] [iel-sayed.blogspot.com] Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed

Wireless Disk PRO v2.3 iOS - Multiple Web Vulnerabilities

2013-05-13 Thread Vulnerability Lab
(+). Credits: Vulnerability Laboratory [Research Team] -Benjamin Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied

File Lite 3.3 3.5 PRO iOS - Multiple Web Vulnerabilities

2013-05-13 Thread Vulnerability Lab
in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct

Sony PS3 Firmware v4.31 - Code Execution Vulnerability

2013-05-21 Thread Vulnerability Lab
[Research Team] - Benjamin Kunz Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability

Trend Micro DirectPass 1.5.0.1060 - Multiple Vulnerabilities

2013-05-22 Thread Vulnerability Lab
as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental

Barracuda SSL VPN 680 2.2.2.203 - Redirect Web Vulnerability

2013-05-27 Thread Vulnerability Lab
warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss

Bluetooth Chat Connect v1.0 iOS - Multiple Vulnerabilities

2013-06-11 Thread Vulnerability Lab
: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case

eFile Wifi Transfer Manager 1.0 iOS - Multiple Vulnerabilities

2013-06-28 Thread Vulnerability Lab
in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct

Mobile USB Drive HD 1.2 - Arbitrary File Upload Vulnerability

2013-06-28 Thread Vulnerability Lab
: Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties

Barracuda CudaTel 2.6.02.04 - Multiple Web Vulnerabilities

2013-06-28 Thread Vulnerability Lab
Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular

Barracuda CudaTel 2.6.02.04 - Persistent Web Vulnerability

2013-06-28 Thread Vulnerability Lab
as medium. Credits: Vulnerability Laboratory [Research Team] - Chokri Ben Achour (meis...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed

AVAST Universal Core Installer - Multiple Vulnerabilities

2013-07-04 Thread Vulnerability Lab
as medium(+). Credits: Vulnerability Laboratory [Research Team] - Ateeq Khan [at...@evolution-sec.com] Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied

Paypal Bug Bounty #102 QR Dev Labs - Auth Bypass Vulnerability

2013-07-05 Thread Vulnerability Lab
: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers

AVAST Antivirus v8.0.1489 - Multiple Core Vulnerabilities

2013-07-05 Thread Vulnerability Lab
[at...@vulnerability-lab.com] Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability

Avira Analysis Web Service - SQL Injection Vulnerability

2013-07-08 Thread Vulnerability Lab
. Credits: Vulnerability Laboratory [Research Team] - Ebrahim Hegazy [Zigoo] (ebra...@evolution-sec.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied

Air Drive Plus v2.4 iOS - Arbitrary File Upload Vulnerability

2013-07-10 Thread Vulnerability Lab
: Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties

Nikon CoolPix L Series Fw1.0 - Information Disclosure Issue

2013-07-16 Thread Vulnerability Lab
: Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties

FTP Sprite v1.2.1 iOS - Persistent Web Vulnerability

2013-07-16 Thread Vulnerability Lab
as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental

Barracuda CudaTel 2.6.02.040 - Client Side Cross Site Scripting Vulnerability

2013-07-16 Thread Vulnerability Lab
Mejri (b...@vulnerability-lab.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular

Dell Kace 1000 SMA v5.4.70402 - Persistent Vulnerabilities

2013-07-16 Thread Vulnerability Lab
are estimated as medium(+). Credits: Vulnerability Laboratory [Research Team] - Ibrahim Mosaad El-Sayed [ibra...@evolution-sec.com] Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties

Olive File Manager v1.0.1 iOS - Multiple Vulnerabilities

2013-07-16 Thread Vulnerability Lab
: === The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers

WiFly 1.0 Pro iOS - Multiple Web Vulnerabilities

2013-07-18 Thread Vulnerability Lab
...@evolution-sec.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose

Flux Player v3.1.0 iOS - File Include Arbitrary File Upload Vulnerability

2013-07-18 Thread Vulnerability Lab
) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers

Barracuda CudaTel 2.6.02.04 - Multiple Client Side Cross Site Vulnerabilities (Bug Bounty #17)

2013-07-18 Thread Vulnerability Lab
as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental

Download Lite v4.3 iOS - Persistent File Web Vulnerability

2013-07-19 Thread Vulnerability Lab
...@evolution-sec.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose

Barracuda LB, SVF, WAF WEF - Multiple Vulnerabilities

2013-07-22 Thread Vulnerability Lab
provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage

Barracuda CudaTel 2.6.02.040 - Remote SQL Injection Vulnerability

2013-07-22 Thread Vulnerability Lab
in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct

Barracuda CudaTel 2.6.02.040 - SQL Injection Vulnerability

2013-07-22 Thread Vulnerability Lab
is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including direct

Dell Kace 1000 SMA 5.4.742 - SQL Injection Vulnerabilities

2013-07-22 Thread Vulnerability Lab
(the_storm) ibra...@evolution-sec.com] Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular

Photo Server 2.0 iOS - Multiple Critical Vulnerabilities

2013-07-23 Thread Vulnerability Lab
: === The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers

iPic Sharp v1.2.1 Wifi iOS - Persistent Foldername Web Vulnerability

2013-07-24 Thread Vulnerability Lab
: Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties

WebDisk 3.0.2 PhotoViewer iOS - Command Execution Vulnerability

2013-07-29 Thread Vulnerability Lab
vulnerability is estimated as critical. Credits: Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) Disclaimer: === The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties

Microsoft Yammer Social Network - oAuth Bypass (Session Token) Vulnerability

2013-08-07 Thread Vulnerability Lab
in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability- Lab or its suppliers are not liable in any case of damage, including

  1   2   3   4   5   6   7   8   9   >