[ERPSCAN-16-019] SAP NetWeaver Enqueue Server - DoS vulnerability

2016-07-14 Thread ERPScan inc
Application: SAP NetWeaver Enqueue Server Versions Affected: SAP NetWeaver Enqueue Server 7.4 Vendor URL: http://SAP.com Bug: denial of service Sent: 04.12.2015 Reported: 05.12.2015 Vendor response: 05.12.2015 Date of Public Advisory: 12.04.2016 Reference: SAP Security Note

[ERPSCAN-16-020] SAP NetWeaver AS JAVA UDDI component - XXE vulnerability

2016-07-14 Thread ERPScan inc
Application: SAP NetWeaver AS JAVA Versions Affected: SAP NetWeaver AS JAVA 7.4 Vendor URL: http://SAP.com Bug: XXE Sent: 04.12.2015 Reported: 05.12.2015 Vendor response: 05.12.2015 Date of Public Advisory: 12.04.2016 Reference: SAP Security Note 2254389 Author: Vahagn Vardanyan

[ERPSCAN-16-021] SAP xMII - Reflected XSS vulnerability

2016-07-14 Thread ERPScan inc
Application: SAP xMII Versions Affected: SAP xMII 15 Vendor URL: http://SAP.com Bugs: XSS Sent: 04.12.2015 Reported: 05.12.2015 Vendor response: 05.12.2015 Date of Public Advisory: 12.04.2016 Reference: SAP Security Note 2201295 Author: Nursultan Abubakirov (ERPScan) , Vahagn Vardanyan

Cross-Site Scripting vulnerability in Google Forms WordPress Plugin

2016-07-14 Thread Summer of Pwnage
Cross-Site Scripting vulnerability in Google Forms WordPress Plugin Yorick Koster, July 2016

Cross-Site Scripting vulnerability in WP No External Links WordPress Plugin

2016-07-14 Thread Summer of Pwnage
Cross-Site Scripting vulnerability in WP No External Links WordPress Plugin Yorick Koster, July 2016

Cross-Site Scripting vulnerability in Top 10 - Popular posts plugin for WordPress

2016-07-14 Thread Summer of Pwnage
Cross-Site Scripting vulnerability in Top 10 - Popular posts plugin for WordPress Yorick Koster, July 2016

Cross-Site Scripting vulnerability in Simple Membership WordPress Plugin

2016-07-14 Thread Summer of Pwnage
Cross-Site Scripting vulnerability in Simple Membership WordPress Plugin Yorick Koster, July 2016