[FD] Raritan CommandCenter Secure Gateway XSS Vulnerability on < 8.0

2019-11-15 Thread okan coskun
I. VULNERABILITY - XSS Vulnerability on Raritan CommandCenter Secure Gateway II. CVE REFERENCE - - III. VENDOR - https://www.raritan.com/support/product/commandcenter-secure-gateway IV. TIMELINE -

[FD] Raritan CommandCenter Secure Gateway XML External Entity < 8.0

2019-11-15 Thread okan coskun
I. VULNERABILITY - Raritan CommandCenter Secure Gateway XML External Entity II. CVE REFERENCE - CVE-2018-20687 III. VENDOR - https://www.raritan.com/support/product/commandcenter-secure-gateway IV. TIMELINE

[FD] Stored XSS Vulnerability on TP-Link Archer VR300 v1

2019-11-15 Thread okan coskun
I. VULNERABILITY - Stored XSS Vulnerability on TP-Link Archer VR300 v1 - firmware version: 1.3.0 0.8.0 v007b.1 build 180905 Rel.55344n II. CVE REFERENCE - - III. VENDOR - https://www.tp-link.com/ IV. TIMELINE

Re: [FD] Microsoft Forefront Unified Access Gateway 2010 External DNS Interaction

2018-07-02 Thread okan coskun
# Exploit Title: Microsoft Forefront Unified Access Gateway 2010 External DNS Interaction # Vendor Homepage: https://www.microsoft.com/ # Version: 2010 # CVE : CVE-2018-12571 # MSRC: Case 39000 # Proof of Concept #1 Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to

[FD] ManageEngine Service Desk Plus < 9403 Cross-Site Scripting

2018-03-27 Thread okan coskun
# Exploit Title: ManageEngine Service Desk Plus < 9403 Cross-Site Scripting # Vendor Homepage: https://www.manageengine.com/ # Version: < 9403 # CVE : CVE-2018-5799 # Proof of Concept #1 Visiting the following page: /api/request/?OPERATION_NAME=GET_REQUESTS">*"%3ca