Synology DSM multiple vulnerabilities

2013-09-11 Thread Andrea Fabrizi
** Title: Synology DSM multiple vulnerabilities Version affected: = 4.3-3776 Vendor: Synology Discovered by: Andrea Fabrizi Email: andrea.fabr...@gmail.com Web: http://www.andreafabrizi.it Twitter: @andreaf83 Status: unpatched

Samsung DVR authentication bypass

2013-08-20 Thread Andrea Fabrizi
** Title: Samsung DVR authentication bypass Version affected: firmware version = 1.10 Vendor: Samsung - www.samsung-security.com Discovered by: Andrea Fabrizi Email: andrea.fabr...@gmail.com Web: http://www.andreafabrizi.it Twitter

Buffalo TeraStation TS-Series multiple vulnerabilities

2013-01-31 Thread Andrea Fabrizi
** Title: Buffalo TeraStation TS-Series multiple vulnerabilities Version affected: firmware version = 1.5.7 Vendor: http://www.buffalotech.com/products/network-storage Discovered by: Andrea Fabrizi Email: andrea.fabr...@gmail.com Web

QNAP Turbo NAS Multiple Path Injection

2012-09-05 Thread Andrea Fabrizi
** Vulnerability: Multiple Path Injection Product: QNAP Turbo NAS Vendor: QNAP Version affected: = 3.7.3 build 20120801 Status: Unpatched Website: http://web.qnap.com/pro_detail_feature.asp?p_id=202 Discovered by: Andrea Fabrizi Email

Novell Sentinel Log Manager =1.2.0.1 Path Traversal

2011-12-19 Thread Andrea Fabrizi
** Vuln: Path Traversal Application: Sentinel Log Manager Vendor: Novell Version affected: = 1.2.0.1 Website: http://www.novell.com/products/sentinel-log-manager/ Discovered By: Andrea Fabrizi Email: andrea.fabr...@gmail.com Web: http

VirtueMart eCommerce for Joomla = 1.1.6 Blind SQL Injection

2011-01-31 Thread Andrea Fabrizi
** Application: VirtueMart Version affected: = 1.1.6 Website: http://www.virtuemart.net/ Discovered By: Andrea Fabrizi Email: andrea.fabr...@gmail.com Web: http://www.andreafabrizi.it Vuln: Blind SQL Injection

PhpShop Multiple Vulnerabilities

2009-12-07 Thread Andrea Fabrizi
** Application: PhpShop Version affected:  0.8.1 Website: http://www.phpshop.org/ Discovered By: Andrea Fabrizi Email: andrea.fabr...@gmail.com Web: http://www.andreafabrizi.it Vuln: Multiple Vulnerabilities

Everfocus EDR1600 remote authentication bypass

2009-10-22 Thread Andrea Fabrizi
** Product: Everfocus EDR1600 Version affected: all Website: http://www.everfocus.com/ Discovered By: Andrea Fabrizi Email: andrea.fabr...@gmail.com Web: http://www.andreafabrizi.it Vuln: remote DVR authentication bypass

3Com OfficeConnect Firewall/Router multiple remote Vulnerabilities

2009-10-19 Thread Andrea Fabrizi
** Product: 3Com OfficeConnect Firewall/Router Website: http://www.3com.com/ Discovered By: Andrea Fabrizi Email: andrea.fabr...@gmail.com Web: http://www.andreafabrizi.it Vuln: remote command execution and password disclosure

Snitz Forums 2000 Multiple Cross-Site Scripting Vulnerabilities

2009-10-15 Thread Andrea Fabrizi
** Application: Snitz Forums 2000 Version affected: 3.4.07 Website: http://forum.snitz.com/ Discovered By: Andrea Fabrizi Email: andrea.fabr...@gmail.com Web: http://www.andreafabrizi.it Vuln: Multiple Cross-Site Scripting

Docebo Multiple SQL-Injection Vulnerabilities

2009-10-09 Thread Andrea Fabrizi
** Application: Docebo Version affected: 3.6.0.3 Website: http://www.docebo.com Discovered By: Andrea Fabrizi Email: andrea.fabr...@gmail.com Web: http://www.andreafabrizi.it Vuln: Multiple SQL-Injection Vulnerabilities