[FD] Cross Site Scripting | WolfCMS v0.8.3.1 and before

2019-05-10 Thread Pramod Rana
Description: WolfCMS v0.8.3.1 and before is vulnerable to cross site scripting in User Add module for parameter Name. Impacted URL is http://[your_webserver_ip]/wolfcms/?/admin/user/add Payload used is "TestXSS> Further details: https://github.com/wolfcms/wolfcms/issues/683 Already requested

[FD] Cross Site Scripting | Alkacon OpenCMS v10.5.4 and before

2019-05-10 Thread Pramod Rana
Description: OpenCMS v10.5.4 and before is vulnerable to cross site scripting in New User module for parameter First Name and Last Name Impacted URL is http://[your_webserver_ip]/opencms/system/workplace/admin/accounts/user_new.jsp Payload used in PoC is

[FD] CSV Injection | Alkacon OpenCMS v10.5.4 and before

2019-05-10 Thread Pramod Rana
Description: OpenCMS v10.5.4 and before is vulnerable to CSV injection in New User module for parameter First Name and Last Name Impacted URL is http://[your_webserver_ip]/opencms/system/workplace/admin/accounts/user_new.jsp Payload used is

[FD] Open source tool | Lets Map Your Network

2019-05-07 Thread Pramod Rana
Let’s Map Your Network (LMYN) aims to provide an easy to use interface to security engineer and network administrator to have their network in graphical form with zero manual error, where a node represents a system and relationship between nodes represent the connection. It is utmost important

[FD] Open Source Tool | vPrioritization | Risk Prioritization Framework

2020-09-04 Thread Pramod Rana
It is no secret that today we have more vulnerabilities than we can assess and remediate, timely and comprehensively. Risk prioritization is a key component for any vulnerability management program. Implementing a good risk prioritization framework is easier said than done because of the variable