Dr. Web Control Center Admin UI Remote Script Code Injection

2012-07-30 Thread Oliver Karow
Dr. Web Control Center Admin UI Remote Script Code Injection = Affected Products/Versions -- Product Name: Dr. Web Enterprise Server Version Number: 6.00.3.20300 Product/Company Information

GFI WebMonitor Admin UI Remote Script Code Injection

2010-08-25 Thread Oliver Karow
GFI WebMonitor Admin UI Remote Script Code Injection Affected Products/Versions -- Product Name: GFI Webmonitor Version Number: 2009 Build Number: 20100324 Platform: Microsoft Windows Product/Company Information

Re: MicroWorld MailScan - Multiple Vulnerabilities within Admin-Webinterface

2008-08-15 Thread oliver karow
Please find attached the advisory regarding MicroWorld's MailScan for Mailservers. Cheers, Oliver MicroWorld MailScan - Multiple Vulnerabilities within Admin-Webinterface Affected Products - MailScan for Mail

BitDefender Update Server - Unauthorized Remote File Access Vulnerability

2008-01-19 Thread oliver karow
product * Discovered by: Oliver Karow http://oliver.greyhat.de/2008/01/19/bitdefender-unauthorized-remote-file-access-vulnerability/ * Vulnerable platform: Windows * Vulnerable Version: N/A Product/Company-Information: = - From Bitdefender's web site: BitDefenderT

Re: n.runs, Sophos, German laws, and customer safety

2007-08-30 Thread Oliver Karow
Hi Steven, even if i do not support the new anti hacker law in germany, i don't see any important issue in the inconsistence between the n.runs advisory and the vendors statement in respect of the new law. The most important message for the average customer, who is not able to understand the

Secure Computing - Security Reporter Auth Bypass and Directory Traversal Vulnerability

2007-07-23 Thread Oliver Karow
an email by the venodr, describing the vulnerability with a link to a patch. Discovered -- By Oliver Karow ([EMAIL PROTECTED]) on Tuesday, 05. June 2007 http://www.oliverkarow.de/research/securityreporter.txt

Apache Geronimo 1.0 - CSS and persistent HTML-Injection vulnerabilities

2006-01-16 Thread oliver karow
/browse/GERONIMO-1474 Fix: Upgrade to version 1.0.1 or 1.1 Discovered == Oliver Karow www.oliverkarow.de/research/geronimo_css.txt 13.01.2005