[Full-disclosure] Hacktics Advisory Feb10: XSS in IBM WebSphere Portal & Lotus WCM

2010-02-25 Thread Ofer Maor
8.0, 8.0.0.2, 8.1, 8.1.1, 8.1.1.1 === VII. Credit === The vulnerability was discovered by Oren Hafif of Hacktics Ltd. --- Ofer Maor CTO, Hacktics Chairman, OWASP Israel Web: www.hacktics.com ___ Full-Disclosure - We believe in it. Charter: http

[Full-disclosure] Hacktics Advisory Feb10: XSS in IBM WebSphere Portal & Lotus WCM

2010-02-25 Thread Ofer Maor
8.0, 8.0.0.2, 8.1, 8.1.1, 8.1.1.1 === VII. Credit === The vulnerability was discovered by Oren Hafif of Hacktics Ltd. --- Ofer Maor CTO, Hacktics Chairman, OWASP Israel Web: www.hacktics.com ___ Full-Disclosure - We believe in it. Charter: http

[Full-disclosure] Hacktics Advisory Feb10: Persistent XSS in Microsoft SharePoint Portal

2010-02-22 Thread Ofer Maor
= VII. Affected Systems = Microsoft Office SharePoint Server 2007. VIII. Credit The vulnerability was discovered by Irene Abezgauz, Hacktics Ltd. --- Ofer Maor CTO, Hacktics Chairman, OWASP Isra

[Full-disclosure] Hacktics Advisory Feb09: XSS in Oracle E-Business Suite

2010-02-09 Thread Ofer Maor
le in production. === VII. Credit === The vulnerability was discovered by Gil Cohen from Hacktics Ltd. --- Ofer Maor CTO, Hacktics Chairman, OWASP Israel Web: www.hacktics.com ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.

Re: [Full-disclosure] Hacktics Advisory Dec09: Oracle eBusinessSuite - Multiple Vulnerabilities Allow Remote Takeover

2009-12-14 Thread Ofer Maor
to try and see if it's hidden behind one of the CVEs. Ofer. From: mikeyc...@gmail.com [mailto:mikeyc...@gmail.com] On Behalf Of Michael Coyne Sent: Monday, December 14, 2009 4:52 PM To: Ofer Maor Cc: full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] Hacktics Advisor

Re: [Full-disclosure] Hacktics Advisory Dec09: Oracle eBusinessSuite - Multiple Vulnerabilities Allow Remote Takeover

2009-12-14 Thread Ofer Maor
I do not believe there are CVEs for these issues. According to the correspondence with Oracle, this was never published (otherwise we would not publish it.) Oracle's main claim is that this interface was removed in Oracle 12, however, we still encounter this vulnerability with many of our custome

[Full-disclosure] Hacktics Advisory Dec09: Oracle eBusiness Suite - Multiple Vulnerabilities Allow Remote Takeover

2009-12-14 Thread Ofer Maor
Hacktics Research Group Security Advisory http://www.hacktics.com/#details=;view=Resources%7CAdvisory By Shay Chen, Hacktics. 14-Dec-2009 === I. Overview === During a penetration test performed by Hacktics' experts, certain vulnerabilities were identified in the Oracle eBusiness