XSS vulnerability in guestbook-php-script

2006-02-13 Thread Micha Borrmann
2006 Vendor contacted: February7th 2006 Advisory published: February13th 2006 AUTHOR: Micha Borrmann ([EMAIL PROTECTED]) SySS GmbH D-72070 Tuebingen / Germany APPLICATION:gastbuch AFFECTED VERSION: all 1.3.3 (1.3.2

MitM-vulnerability in Palo Alto Networks GlobalProtect

2012-10-17 Thread Micha Borrmann
: July13th 2012 Advisory published: October 12th 2012 AUTHOR: Micha Borrmann (micha.borrm...@syss.de) SySS GmbH D-72070 Tuebingen / Germany APPLICATION:Windows Client AFFECTED VERSION: 1.1.5-5 (32 Bit Version) Remotely exploitable

CVE-2014-2735 - WinSCP: missing X.509 validation

2014-04-16 Thread Micha Borrmann
Notification: 2014-04-07 Solution Date: 2014-04-09 Public Disclosure: 2014-04-16 CVE Reference: CVE-2014-2735 Author of Advisory: Micha Borrmann (SySS GmbH) - Overview: WinSCP is not checking the Common Name of a X.509

CVE-2014-2845 - Cyberduck (Windows): Failure validating some certificates (using FTP-SSL) with untrusted root certificate authority

2014-05-06 Thread Micha Borrmann
) Vulnerability Type: X.509 validation Risk Level: Medium Solution Status: Fixed Vendor Notification: 2014-04-08 Solution Date: 2014-04-10 Public Disclosure: 2014-05-06 CVE Reference: CVE-2014-2845 Author of Advisory: Micha Borrmann (SySS GmbH) Overview: Cyberduck (Windows versions only) accepts X.509 server

FTP Rush: missing X.509 validation (FTP with TLS)

2014-05-20 Thread Micha Borrmann
Level: Medium Solution Status: Vendor Notification: 2014-04-04 Solution Date: Public Disclosure: 2014-05-19 CVE Reference: Not assigned, (but similiar to CVE-2012-6606) Author of Advisory: Micha Borrmann (SySS GmbH) Overview: FTP Rush does not validating X.509 certificates, if FTP

Re: SSH host key fingerprint - through HTTPS

2014-09-01 Thread Micha Borrmann
Nice tool, but it is also possible, to use DNSSEC to validate SSH fingerprints, which is much more comfortable and more secure. Am 01.09.2014 um 06:41 schrieb John Leo: This tool displays SSH host key fingerprint - through HTTPS. SSH is about security; host key matters a lot here; and you can

[SYSS-2016-067] NetIQ Access Manager (iManager) - Temporary Second Order Cross-Site Scripting (CWE-79)

2016-08-17 Thread Micha Borrmann
: 2016-08-17 CVE Reference: Not yet assigned Author of Advisory: Micha Borrmann, SySS GmbH Overview: NetIQ Access Manager is a web access management software that provides secure access to enterprise and cloud applications

[SYSS-2016-115] Cisco Expressway: Security Bypass Vulnerability (CWE-20)

2016-12-19 Thread Micha Borrmann
: 2016-11-10 Solution Date: 2016-12-05 Public Disclosure: 2016-12-14 CVE Reference: CVE-2016-9207 Author of Advisory: Micha Borrmann, SySS GmbH Overview: Jabber Guest [1] can be used to connect people from the Internet

[SYSS-2017-011] Office 365: Insufficient Session Expiration (CWE-613)

2017-07-07 Thread Micha Borrmann
Level: Low Solution Status: Open Manufacturer Notification: 2017-03-01 Solution Date: Public Disclosure: 2017-07-04 CVE Reference: Not yet assigned Authors of Advisory: Micha Borrmann (SySS GmbH) Overview: Microsoft Office 365

[SYSS-2017-010] HP Wireless Mouse: Spoofing Attack (CWE-345)

2017-05-16 Thread Micha Borrmann
Verification of Data Authenticity (CWE-345) Mouse Spoofing Attack Risk Level: Medium Solution Status: Open Manufacturer Notification: 2017-03-02 Solution Date: - Public Disclosure: 2017-05-08 CVE Reference: Not yet assigned Authors of Advisory: Micha Borrmann and Matthias Deeg

[SYSS-2018-027] missing X.509 validation with Polycom VVX Phones (Skype for Business, on-premise) - CVE-2018-18568

2018-10-23 Thread Micha Borrmann
ble-disclosure-policy/ Credits: This security vulnerability was found by Micha Borrmann of SySS GmbH. E-Mail: micha.borrmann (at) syss.de Public Key: https://www.syss.de/fileadmin/dokumente/PGPKeys/Micha_Borrmann.asc

[SYSS-2018-028] information leakage with Polycom VVX Phones (Skype for Business, on-premise) - CVE-2018-18566

2018-10-23 Thread Micha Borrmann
ype:Information Exposure (CWE-200) Risk Level:Low Solution Status: Open Manufacturer Notification: 2018-08-29 Solution Date: 20??-??-?? Public Disclosure: 2018-10-23 CVE Reference: CVE-2018-18566 Authors of Advisory: Micha Borrmann (SySS G

[SYSS-2018-026] missing X.509 validation with AudioCodes IP Phones (Skype for Business, on-premise) - CVE-2018-18567

2018-10-23 Thread Micha Borrmann
ory: Micha Borrmann (SySS GmbH) Overview: If a AudioCodes 440HD/450HD IP Phone [1] is used with an on-premise installation with Skype for Business, the phone has stored credentials of an account in the active directory. Perform

[SYSS-2018-024] Privilege Escalation in Verint Verba Collaboration Compliance and Quality Management Platform (CVE-2018-17872)

2018-10-02 Thread Micha Borrmann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Advisory ID: SYSS-2018-024 Product: Collaboration Compliance and Quality Management Platform Manufacturer: Verint Verba Affected Version(s): <= 9.1.1.5482 Tested Version(s): 9.1.1.5482

[SYSS-2018-023] Password leakage in Verint Verba Collaboration Compliance and Quality Management Platform (CVE-2018-17871)

2018-10-02 Thread Micha Borrmann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Advisory ID: SYSS-2018-023 Product: Collaboration Compliance and Quality Management Platform Manufacturer: Verint Verba Affected Version(s): <= 9.1.1.5482 Tested Version(s): 9.1.1.5482

[SYSS-2018-043] Authentication Bypass in Kentix MultiSensor LAN - CVE-2018-19783

2019-01-18 Thread Micha Borrmann
CVE number assigned 2018-12-03: Vulnerability reported to manufacturer 2019-01-17: Public release of the security advisory References: [1] Support web site http

[SYSS-2018-042] XSS in HMS Netbiter WS100 - CVE-2018-19694

2019-01-13 Thread Micha Borrmann
ite Scripting (CWE-79) Risk Level:Low Solution Status: Fixed Manufacturer Notification: 2018-11-29 Solution Date: 2018-12-20 Public Disclosure: 2019-01-11 CVE Reference: CVE-2018-19694 Authors of Advisory: Micha Borrmann (SySS G