[FD] Vaadin Javascript Injection

2017-06-22 Thread Caleb Cushing
first time poster, so I'm not sure if this is the best venue, format, etc. https://github.com/vaadin/framework/issues/8731 using vaadin 7.7.6 using example https://vaadin.com/docs/-/part/framework/components/components-combobox.html but with malicious text that assumes humans are adding the

[FD] OffensiveCon Berlin 2018 Call for Papers

2017-06-22 Thread Moritz Jodeit
OffensiveCon Berlin 2018 Call for Papers [OVERVIEW] We are pleased to announce the CFP for the first edition of OffensiveCon Berlin which is a highly technical international security conference focused on offensive

[FD] PayPal Inc BB #149 - (Gift) Insufficient Authentication Vulnerability

2017-06-22 Thread Vulnerability Lab
Document Title: === PayPal Inc BB #149 - (Gift) Insufficient Authentication Vulnerability References (Source): https://www.vulnerability-lab.com/get_content.php?id=1973 ID EIBBP-34368 Release Date: = 2017-06-21 Vulnerability Laboratory ID

[FD] SEC Consult SA-20170622-0 :: XXE, SQLi, XSS & local file disclosure in Cisco Prime Infrastructure

2017-06-22 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20170622-0 > === title: XML External Entity Injection (XXE), SQL Injection, Cross Site Scripting, Local File Disc