[FD] SiteVision Insufficient Module Access Control

2019-12-06 Thread Oscar Hjelm
cript was executed. ## Vulnerability Disclosure Timeline 2019-06-03 - Disclosed to vendor 2019-06-04 - Vendor confirms vulnerability 2019-09-26 - Vendor issues patches 2019-12-04 - Public disclosure Oscar Hjelm Cybercom Sweden signature.asc Description: Message signed with OpenPGP ___

[FD] SiteVision Remote Code Execution

2019-12-06 Thread Oscar Hjelm
ot;. 12. Press "OK". 13. Note the script output, and how it contains the result of the system command. In the command example above, the result of whoami should be "root" if SiteVision 5 was installed using the vendor-provided RPM package. ## Vulnerability Disclosure Timeline 20

[FD] F-Secure Radar Login Page Unvalidated Redirect Vulnerability

2018-02-16 Thread Oscar Hjelm
5 - Vendor contact & response 2018-02-09 - Vendor confirms fix 2018-02-15 - Public disclosure This post is also available at http://oscarhjelm.com/blag/2018/02/f-secure-radar-login-page-unvalidated-redirect-vulnerability/ Best regards, Oscar Hjelm signature.asc Description: Message signe

[FD] F-Secure Radar Persistent Cross-Site Scripting Vulnerability

2018-02-16 Thread Oscar Hjelm
01 - Vendor confirms fix 2018-02-15 - Public disclosure This post is also available at http://oscarhjelm.com/blag/2018/02/f-secure-radar-persistent-cross-site-scripting-vulnerability/ Best regards, Oscar Hjelm signature.asc Description: Message signed with OpenPGP