[FD] Webmin (Upload Module) Remote Command Injection Vulnerability

2020-05-08 Thread raki ben hamouda
Document Title: === Webmin 1.941 (Install Module) Remote Command Injection Vulnerability Common Vulnerability Scoring System: 8.5 Vulnerability Class: Command Injection Current Estimated Price:

[FD] WSO2 API Manager Stored XSS Vulnerabilty

2020-04-14 Thread raki ben hamouda
Latest Release after Fixing Vuln: === V 3.1.0 (https://wso2.com/library/articles/introducing-wso2-api-manager-3-1/ ) Author : == Raki Ben Hamouda Affected Product(s): WSO2 API Manager Carbon interface V3.0.0 Exploitation

[FD] Comtrend VR-3033 Multiple Command Injection vulnerability

2020-02-28 Thread raki ben hamouda
ploited the same way in traceroute function. ======= Author : Raki Ben Hamouda ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] Disclosing a security vulnerability

2019-06-11 Thread raki ben hamouda
Document Title: === D-Link DWL-2600AP - (Authenticated) OS Command Injection (Restore Configuration) Product & Service Introduction: === The D-Link DWL-2600AP has a web interface for configuration. You can use any web browser you like to login to the