[FD] CatBot v0.4.2 (PHP) - SQL Injection Vulnerability

2015-01-16 Thread Vulnerability Lab
belo (paulosyibelo.com) Disclaimer & Information: ========= The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capabi

[FD] VeryPhoto v3.0 iOS - Command Injection Vulnerability

2015-01-16 Thread Vulnerability Lab
SS 5.6) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability L

[FD] WiFi File Browser Pro v2.0.8 - Code Execution Vulnerability

2015-01-16 Thread Vulnerability Lab
Hadji Samir s...@hotmail.fr Disclaimer & Information: ===== The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and

[FD] File Pro Mini v5.2 iOS - Multiple Web Vulnerabilities

2015-01-16 Thread Vulnerability Lab
y Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either

[FD] Facebook Bug Bounty #19 - Filter Bypass Web Vulnerability

2015-01-16 Thread Vulnerability Lab
ion provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any

[FD] SPSControl v1.2 iOS - (.spc) Persistent Vulnerability

2015-01-19 Thread Vulnerability Lab
rity Risk: == The security risk of the persistent input validation vulnerability in the name value of the .spc files is estimated as medium. (CVSS 3.7) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.co

[FD] Banana Dance Wiki CMS b2.x - Multiple Web Vulnerabilities

2015-01-19 Thread Vulnerability Lab
includes PoC: /../../../file/we/want/to/include.php%00setup/mysql/tables.php Security Risk: == 1.1 The security risk of the sql injection web vulnerability in the `db_prefix` is estimated as critical. 1.2 The security risk of the local file include web vulnerability in the path v

[FD] Program-O v2.4.6 - Multiple Web Vulnerabilities

2015-01-22 Thread Vulnerability Lab
ocal file manipulation issue and code execution vulnerability is estimated as high. (CVSS 6.4). Credits & Authors: == Paulos Yibelo (paulosyibelo.com) Disclaimer & Information: = The information provided in this advisory is provided as

[FD] PhotoSync 1.1.3 Android - Command Inject Vulnerability

2015-01-22 Thread Vulnerability Lab
as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, incid

[FD] SWFupload 2.5.0 - Cross Frame Scripting (XFS) Vulnerability

2015-01-25 Thread Vulnerability Lab
mer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. V

[FD] Mangallam CMS - SQL Injection Web Vulnerability

2015-01-26 Thread Vulnerability Lab
=== IranGuard Security Team - P0!s0nC0d3 Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantabi

[FD] Barracuda Cloud Series - Filter Bypass Vulnerability (ID 731)

2015-02-11 Thread Vulnerability Lab
d as medium. (CVSS 4.1) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is

[FD] Facebook Bug Bounty #23 - Session ID & CSRF Vulnerability

2015-02-11 Thread Vulnerability Lab
Joe Balhis (https://www.facebook.com/joe.balhis) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, inc

[FD] BlinkSale Bug Bounty #1 - Encode & Validation Vulnerability

2015-02-11 Thread Vulnerability Lab
== Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all wa

[FD] Pandora FMS v5.1 SP1 - SQL Injection Web Vulnerability

2015-02-11 Thread Vulnerability Lab
Document Title: === Pandora FMS v5.1 SP1 - SQL Injection Web Vulnerability References (Source): http://vulnerability-lab.com/get_content.php?id=1355 Release Date: = 2015-02-09 Vulnerability Laboratory ID (VL-ID): ===

[FD] T-Mobile Internet Manager - DLL Hijacking (mfc71enu.dll)

2015-02-11 Thread Vulnerability Lab
g vulnerability in the mfc71enu.dll is estimated as medium. (CVSS 5.6) Credits & Authors: == metacom Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab discla

[FD] Ebay Inc Magento Bug Bounty #5 - Persistent Validation & Mail Encoding Web Vulnerability

2015-02-17 Thread Vulnerability Lab
The security risk of the persistent input validation and mail encoding web vulnerability is estimated as medium. (CVSS 3.8) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer &

[FD] DSS TFTP 1.0 Server - Path Traversal Vulnerability

2015-02-26 Thread Vulnerability Lab
amp; Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its s

[FD] Data Source: Scopus CMS - SQL Injection Web Vulnerability

2015-02-26 Thread Vulnerability Lab
=== [GuardIran Security Team] P0!s0nC0d3 - (http://www.guardiran.org) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, includi

[FD] Wireless File Transfer Pro Android - Multiple CSRF Vulnerabilities

2015-02-26 Thread Vulnerability Lab
quest forgery web vulnerability in the create and delete function is estimated as medium. (CVSS 2.3) Credits & Authors: == Hadji Samir [s...@hotmail.fr] Disclaimer & Information: = The information provided in this advisory is provided as it is without any wa

[FD] Swiss File Knife v1.7.4 HTTP - Buffer Overflow Vulnerability

2015-02-28 Thread Vulnerability Lab
vided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, i

[FD] Photo Manager Pro 4.4.0 iOS - Code Execution Vulnerability

2015-04-21 Thread Vulnerability Lab
ode execution vulnerability in the photo manager wifi service is estimated as high. (CVSS 8.6) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: ========

[FD] Mobile Drive HD v1.8 - File Include Web Vulnerability

2015-04-21 Thread Vulnerability Lab
lity-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose

[FD] Photo Manager Pro v4.4.0 iOS - File Include Vulnerability

2015-04-21 Thread Vulnerability Lab
sclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose.

[FD] Wifi Drive Pro v1.2 iOS - File Include Web Vulnerability

2015-04-21 Thread Vulnerability Lab
on provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any ca

[FD] Ebay Inc Xcom #4 - (Item Preview) Persistent Vulnerability

2015-04-21 Thread Vulnerability Lab
vulnerability and filter bypass issue is estimated as medium. (CVSS 4.1) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information:

[FD] Ebay Inc Xcom #6 - Persistent POST Inject Vulnerability

2015-04-21 Thread Vulnerability Lab
s: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: ===== The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclai

[FD] Ebay Inc Xcom #7 - (Policy) Persistent Vulnerability

2015-04-21 Thread Vulnerability Lab
thors: ====== Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: ===== The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab di

[FD] PayPal Inc Bug Bounty #113 - Client Side Cross Site Scripting Vulnerability

2015-04-21 Thread Vulnerability Lab
= Milan A Solanki - (milans...@gmail.com) [www.safehacking4mas.blogspot.in] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, includin

[FD] SevenIT SevDesk 3.10 - Multiple Web Vulnerabilities

2015-04-21 Thread Vulnerability Lab
Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vu

[FD] Apple iOS 8.0 - 8.0.2 - Controls Re Auth Bypass Vulnerability

2015-04-22 Thread Vulnerability Lab
in Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the

[FD] iPassword Manager v2.6 iOS - Persistent Vulnerabilities

2015-04-22 Thread Vulnerability Lab
Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, includ

[FD] HomeAdvisor Bug Bounty #1 - Filter Bypass & Client Side Exception Handling Vulnerability

2015-04-22 Thread Vulnerability Lab
=== Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all

[FD] Socrata Bug Bounty #1 - Persistent Encoding Vulnerability

2015-04-23 Thread Vulnerability Lab
isk: == The security risk of the application-side mail encodeing web vulnerability is estimated as medium. (CVSS 3.3) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclai

[FD] SonicWall SonicOS 7.5.0.12 & 6.x - Client Side Cross Site Scripting Vulnerability

2015-04-28 Thread Vulnerability Lab
ml to prevent client-side or application-side script code injection attacks. Security Risk: == The security risk of the cross site scripting web vulnerability in the macipspoofview.html file is estimated as medium. (CVSS 3.0) Credits & Authors: == Vulnerability Lab

[FD] PayPal Inc Bug Bounty #114 - JDWP Remote Code Execution Vulnerability

2015-04-28 Thread Vulnerability Lab
=== The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers a

[FD] SevDesk v1.1 iOS - Persistent Dashboard Vulnerability

2015-04-30 Thread Vulnerability Lab
Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability

[FD] HUAWEI MobiConnect 23.9.17.216 - Privilege Escalation Vulnerability

2015-05-04 Thread Vulnerability Lab
mation: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab

[FD] Cisco (Newsroom) - Client Side Cross Site Scripting Vulnerability

2015-05-04 Thread Vulnerability Lab
ewsroom service is estimated as medium. (CVSS 2.5) Credits & Authors: == Vulnerability Laboratory [Research Team] - Hadji Samir [s...@hotmail.fr] Disclaimer & Information: = The information provided in this advisory is provided as it is with

[FD] Grindr v2.1.1 iOS Bounty #1 - (Session) Auth Bypass Vulnerabilities

2015-05-04 Thread Vulnerability Lab
= Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab di

[FD] Grindr v2.1.1 iOS - (eMail) Session Vulnerability

2015-05-04 Thread Vulnerability Lab
Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either

[FD] Grindr 2.1.1 iOS Bug Bounty #2 - Denial of Service Software Vulnerability

2015-05-04 Thread Vulnerability Lab
this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, incl

[FD] PhotoWebsite v3.1 iOS - File Include Web Vulnerability

2015-05-04 Thread Vulnerability Lab
Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, eit

[FD] vPhoto-Album v4.2 iOS - File Include Web Vulnerability

2015-05-05 Thread Vulnerability Lab
document.write("<td height=\"20\" > <p align=\"center\">"); if (i+3 < numberOfAlbums) { document.write("<font face=\"Courier New\"

[FD] Fortinet FortiAnalyzer & FortiManager - Client Side Cross Site Scripting Vulnerability

2015-05-05 Thread Vulnerability Lab
ility in the dataset view module is estimated as medium. (CVSS 3.5) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information pr

[FD] Oracle Business Intelligence Mobile HD v11.x iOS - Persistent UI Vulnerability

2015-05-06 Thread Vulnerability Lab
ratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, eith

[FD] PDF Converter & Editor 2.1 iOS - File Include Vulnerability

2015-05-06 Thread Vulnerability Lab
Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, includi

[FD] TORNADO Computer Trading CMS - SQL Injection Vulnerability

2015-05-06 Thread Vulnerability Lab
ld friends +ALL Muslims Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capabili

[FD] Album Streamer v2.0 iOS - Directory Traversal Vulnerability

2015-05-07 Thread Vulnerability Lab
(b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of

[FD] Yahoo eMarketing Bug Bounty #31 - Cross Site Scripting Vulnerability

2015-05-07 Thread Vulnerability Lab
== The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in

[FD] Grindr v2.1.1 iOS & Account System - Breach Attack Vulnerability

2015-05-07 Thread Vulnerability Lab
oratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or

[FD] Pimcore v3.0.5 CMS - Multiple Web Vulnerabilities

2015-05-08 Thread Vulnerability Lab
y in the pimcore cms is estimated as high. (CVSS 6.1) 1.3 The security risk of the reflected cross site scripting web vulnerabilities in the pimcore cms are estimated as medium. (CVSS 3.2) Credits & Authors: == Alain Homewood - PwC New Zealand (http://www.pwc.co.nz/services/a

[FD] Web India Solutions CMS 2015 - SQL Injection Vulnerability

2015-05-13 Thread Vulnerability Lab
danger_3 and to all my old friends +ALL Muslims Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merc

[FD] Facebook #26 - Filter Bypass & Exception Handling Redirect Web Vulnerability

2015-05-18 Thread Vulnerability Lab
ity-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a

[FD] CRUCMS Crucial Networking - SQL Injection Vulnerability

2015-05-18 Thread Vulnerability Lab
ded in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of

[FD] Wireless Photo Transfer v3.0 iOS - File Include Vulnerability

2015-05-18 Thread Vulnerability Lab
information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any ca

[FD] iClassSchedule 1.6 iOS & Android - Persistent UI Vulnerability

2015-05-18 Thread Vulnerability Lab
Vulnerability Laboratory [Research Team] - Katharin S. L. (CH) (resea...@vulnerability-lab.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims

[FD] OYO File Manager 1.1 iOS&Android - Multiple Vulnerabilities

2015-05-18 Thread Vulnerability Lab
Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed

[FD] HiDisk 2.4 iOS - (currentFolderPath) Persistent Vulnerability

2015-05-20 Thread Vulnerability Lab
Document Title: === HiDisk 2.4 iOS - (currentFolderPath) Persistent Vulnerability References (Source): http://www.vulnerability-lab.com/get_content.php?id=1496 Release Date: = 2015-05-19 Vulnerability Laboratory ID (VL-ID):

[FD] WISE-FTP Software v8.0.2 - DLL Hijacking Vulnerability

2015-05-20 Thread Vulnerability Lab
e ftp software is estimated as high. (CVSS 6.0) Credits & Authors: == metacom Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, ei

[FD] Staff FTP v3.04 Software - DLL Hijacking Vulnerability

2015-05-20 Thread Vulnerability Lab
this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage,

[FD] Eisbär SCADA (All Versions - iOS, Android & W8) - Persistent UI Vulnerability

2015-05-20 Thread Vulnerability Lab
s estimated as medium. (CVSS 5.2) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provide

[FD] WebDrive 12.2 (B4172) - Buffer Overflow Vulnerability

2015-06-02 Thread Vulnerability Lab
The security risk of the buffer overflow vulnerability in the URL/Address parameter is estimated as high. (CVSS 6.8) Credits & Authors: == metacom Disclaimer & Information: = The information provided in this advisory is provi

[FD] 1 Click Audio Converter v2.3.6 - Activex Buffer Overflow

2015-06-05 Thread Vulnerability Lab
aultV"; arg4="defaultV"; arg5="defaultV"; target.InitLicenKeys(arg1 ,arg2 ,arg3 ,arg4 ,arg5 ); Security Risk: == The security risk of the activex buffer overflow vulnerability is estimated as high. (CVSS 6.1) Credits & Authors: =

[FD] 1 Click Audio Converter v2.3.6 - Activex Buffer Overflow

2015-06-05 Thread Vulnerability Lab
"; arg5="defaultV"; target.InitLicenKeys(arg1 ,arg2 ,arg3 ,arg4 ,arg5 ); Security Risk: == The security risk of the activex buffer overflow vulnerability is estimated as high. (CVSS 6.1) Credits & Authors: == metacom (PwC New Zealand) - [http://www.vuln

[FD] 1 Click Extract Audio v2.3.6 - Activex Buffer Overflow

2015-06-05 Thread Vulnerability Lab
uot;defaultV"; target.InitLicenKeys(arg1 ,arg2 ,arg3 ,arg4 ,arg5 ); Security Risk: == The security risk of the activex buffer overflow vulnerability is estimated as high. (CVSS 6.1) Credits & Authors: == metacom (PwC New Zealand) - [http://www.vulnerability-lab.com/show

[FD] Heroku Bug Bounty #2 - (API) Re Auth Session Bypass Vulnerability

2015-06-10 Thread Vulnerability Lab
=== The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its supplie

[FD] ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities

2015-06-19 Thread Vulnerability Lab
nerability is estimated as high. (CVSS 5.9) 1.3 The security risk of the cross site scripting web vulnerabilities are estimated as medium. (CVSS 3.3) Credits & Authors: == Alain Homewood (PwC New Zealand) - [http://vulnerability-lab.com/show.php?user=Alain%20Homewood]

[FD] ZTE ZXV10 W300 v3.1.0c_DR0 - UI Session Delete Vulnerability

2015-06-19 Thread Vulnerability Lab
dji Samir [s...@hotmail.fr] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and

[FD] Ebay Magento Bug Bounty #17 - Client Side Cross Site Scripting Web Vulnerability

2015-06-19 Thread Vulnerability Lab
input of the general_font value by disallowing the usage of special chars. Encode and parse the vulnerable file parameters to prevent client-side script code injection attacks. Security Risk: == The security risk of the client-side cross site scripting web vulnerability in th

[FD] Ebay Magento Bug Bounty #12 - Cross Site Request Forgery Web Vulnerability

2015-06-19 Thread Vulnerability Lab
https://www.magentocommerce.com/magento-connect/ https://www.magentocommerce.com/magento-connect/message/ https://www.magentocommerce.com/magento-connect/message/message/create/ Solution - Fix & Patch: === Setup a cross site request forgery token to protect the create/delet

[FD] ManageEngine Asset Explorer v6.1 - Persistent Vulnerability

2015-06-22 Thread Vulnerability Lab
5) Credits & Authors: == Alain Homewood - PwC New Zealand (http://www.pwc.co.nz/services/assurance-services/pwc-security/) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaim

[FD] Pinterest Bug Bounty #1 - Persistent contact_name Vulnerability

2015-07-01 Thread Vulnerability Lab
= Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all war

[FD] FCS Scanner v1.0 & v1.4 iOS - Command Inject Vulnerability

2015-07-01 Thread Vulnerability Lab
erability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a parti

[FD] Blueberry Express v5.9.x - SEH Buffer Overflow Vulnerability

2015-07-01 Thread Vulnerability Lab
push+nseh+seh+nopsled+shellcode) f.close() print "File created" except: print "File cannot be created" Reference(s): http://www.bbsoftware.co.uk/ http://www.bbsoftware.co.uk/bbflashback/download.aspx Security Risk: == The security risk of the local seh bu

[FD] WK UDID v1.0.1 iOS - Command Inject Vulnerability

2015-07-04 Thread Vulnerability Lab
as medium. (CVSS 5.6) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (b...@evolution-sec.com) [www.vulnerability-lab.com] Disclaimer & Information: = The information provided in this advisory is provided as it is w

[FD] Ebay Inc Magento Bug Bounty #16 - CSRF Web Vulnerability

2015-07-04 Thread Vulnerability Lab
- Hadji Samir [s...@hotmail.fr] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular

[FD] Google HTTP Live Headers v1.0.6 - Client Side Cross Site Scripting Web Vulnerability

2015-07-04 Thread Vulnerability Lab
: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppl

[FD] Apple iOS 10.2 & 10.3 - Control Panel Denial of Service Vulnerability

2017-04-28 Thread Vulnerability Lab
Authors: == Vulnerability Laboratory [Research Team] - (https://www.vulnerability-lab.com/show.php?user=Vulnerability-Lab) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab d

[FD] Super File Explorer 1.0.1 - Arbitrary File Upload Vulnerability

2017-05-03 Thread Vulnerability Lab
njamin%20K.M.) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a partic

[FD] Icecream v4.53 & Pro - File Permission Privilege Escalation

2017-05-03 Thread Vulnerability Lab
ow.php?user=SaifAllahbenMassaoud) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability an

[FD] Hola VPN v1.34 - Privilege Escalation Vulnerability

2017-05-03 Thread Vulnerability Lab
Research Team] - SaifAllah benMassaoud (http://www.vulnerability-lab.com/show.php?user=SaifAllahbenMassaoud) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either e

[FD] Joomla com_tag v1.7.6 - (tag) SQL Injection Vulnerability

2017-05-03 Thread Vulnerability Lab
i_feizezade,Amin_Zohrabi,Shellshock3 and all my friends + all members of the Iedb.Ir Team. Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied,

[FD] Arachni v1.5-0.5.11 - Persistent Cross Site Vulnerability

2017-05-03 Thread Vulnerability Lab
cripting vulnerability in the application is estimated as low. (CVSS 3.7) Credits & Authors: == Peter Kok - [http://www.vulnerability-lab.com/show.php?user=Peter%20Kok] Disclaimer & Information: ===== The information provided in this advisory is pr

[FD] Zenario v7.6 - Persistent Cross Site Scripting Vulnerability

2017-05-03 Thread Vulnerability Lab
as medium. (CVSS 3.4) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (http://www.vulnerability-lab.com/show.php?user=Benjamin%20K.M.) Disclaimer & Information: = The information provided in this advisory is provided as it is withou

[FD] Zenario v7.6 - (Delete) Persistent Cross Site Vulnerability

2017-05-03 Thread Vulnerability Lab
eb-application is estimated as medium. (CVSS 3.6) Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (http://www.vulnerability-lab.com/show.php?user=Benjamin%20K.M.) Disclaimer & Information: = The information provided in this advisor

[FD] PayPal Inc announces 2 new Bug Bounty Program Domains

2017-05-16 Thread Vulnerability Lab
Topic: PayPal Inc announces 2 new Bug Bounty Program Domains Subtitle: PayPal Inc - New Scope & Program Guidelines URL: https://www.vulnerability-db.com/?q=articles/2017/05/16/paypal-inc-announces-2-new-bug-bounty-program-domains# New Domains in Scope: 2 - Braintree (https://www.braintreepayments

[FD] Mozilla Firefox v52.02 - (Stack Overflow) DoS Vulnerability

2017-05-16 Thread Vulnerability Lab
provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-Lab or its suppliers are not liable in any case of damage, including direct, indirect, inci

[FD] MikroTik RouterBoard v6.38.5 - Denial of Service Vulnerability

2017-05-16 Thread Vulnerability Lab
= Hosein Askari (FarazPajohan) - hosein.ask...@aol.com [https://www.vulnerability-lab.com/show.php?user=Hosein%20Askari] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaim

[FD] Wordpress EELV Newsletter v4.5 - Multiple Vulnerabilities

2017-05-16 Thread Vulnerability Lab
m/show.php?user=King%20Coder] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a pa

[FD] Wordpress Newsletter Supsystic 1.1.7 - Cross Site Scripting Vulnerability

2017-05-23 Thread Vulnerability Lab
Credits & Authors: == King Coder - [https://www.vulnerability-lab.com/show.php?user=King%20Coder] Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties,

[FD] Simple ASC CMS v1.2 - (Guestbook) Persistent Vulnerability

2017-05-23 Thread Vulnerability Lab
sclaimer & Information: ===== The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the warranties of merchantability and capability for a particular p

[FD] HTTrack v3.x - Stack Buffer Overflow Vulnerability

2017-05-23 Thread Vulnerability Lab
bility in the software core is estimated as high (CVSS 6.1) Credits & Authors: == Hosein Askari (FarazPajohan) - hosein.ask...@aol.com [https://www.vulnerability-lab.com/show.php?user=Hosein%20Askari] Disclaimer & Information: = The information provided in t

[FD] Perch v3.0.3 CMS - Multiple Web Vulnerabilities

2017-06-07 Thread Vulnerability Lab
curity risk of the persistent cross site and unrestricted file upload web vulnerabilities in the Perch CMS is estimated as medium (CVSS 3.8). Credits & Authors: ====== Vulnerability Laboratory [Research Team] - SaifAllah benMassaoud (https://twitter.com/benmassaou) - (http://www

[FD] Xavier v2.4 PHP MP - SQL Injection Web Vulnerabilities

2017-06-07 Thread Vulnerability Lab
he security risk of the sql-injection vulnerability in the web panel of the xavier application is estimated as medium (CVSS 5.3). Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (http://www.vulnerability-lab.com/show.php?user=Benjamin%20K.M.) Disclaimer

[FD] Evolution Script CMS v5.3 - Cross Site Scripting Vulnerability

2017-06-12 Thread Vulnerability Lab
sk: == The security risk of the cross site scripting web vulnerability in the web-application is estimated as medium (CVSS 3.3). Credits & Authors: == Vulnerability Laboratory [Research Team] - (https://www.vulnerability-lab.com/show.php?user=Vulnerability-Lab)

[FD] Composr CMS v10.0.0 - Cross Site Scripting Vulnerability

2017-06-12 Thread Vulnerability Lab
delete functions. Security Risk: == The security risk of the client-side cross site scripting vulnerability in the web-application is estimated as medium (CVSS 3.3). Credits & Authors: == Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (http://www.vulnerability-lab.c

[FD] Zenbership 1.0.8 CMS - Multiple SQL Injection Vulnerabilities

2017-06-12 Thread Vulnerability Lab
-injection vulnerabilities in the web-application is estimated as medium (CVSS 5.3). Credits & Authors: == N/A - Anonymous Disclaimer & Information: ===== The information provided in this advisory is provided as it is without any warranty. Vulnerabi

[FD] PayPal Inc BB #149 - (Gift) Insufficient Authentication Vulnerability

2017-06-22 Thread Vulnerability Lab
s medium. (CVSS 4.2) Credits & Authors: == Chamli [mohamed.cha...@esprit.tn] - https://www.vulnerability-lab.com/show.php?user=Chamli Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnera

[FD] Microsoft Skype v7.2, v7.35 & v7.36 - Stack Buffer Overflow Vulnerability

2017-06-26 Thread Vulnerability Lab
jri (http://www.vulnerability-lab.com/show.php?user=Benjamin%20K.M.) Disclaimer & Information: = The information provided in this advisory is provided as it is without any warranty. Vulnerability Lab disclaims all warranties, either expressed or implied, including the

<    1   2   3   4   5   6   7   8   9   >