Mail Index
- [FD] Netlife Photosuite Pro - Client Side Cross Site Scripting Vulnerability
- [FD] File Hub v3.3 iOS (Wifi) - Multiple Web Vulnerabilities
- [FD] Soso Transfer v1.1 iOS - Denial of Service Vulnerability
- [FD] Soso Transfer v1.1 iOS - Denial of Service Vulnerability
- [FD] File Manager PRO v1.3 iOS - Multiple Web Vulnerabilities
- [FD] SimpleView CRM - Client Side Open Redirect Vulnerability
- [FD] Getdpd Bug Bounty #1 - (asm0option0) Persistent Web Vulnerability
- [FD] Compal ConnectBox Wireless - Passphrase Settings Filter Bypass Vulnerability
- [FD] Security Advisories
- From: Portcullis Advisories
- [FD] AST-2016-001: BEAST vulnerability in HTTP server
- From: Asterisk Security Team
- [FD] AST-2016-002: File descriptor exhaustion in chan_sip
- From: Asterisk Security Team
- [FD] AST-2016-003: Remote crash vulnerability when receiving UDPTL FAX data.
- From: Asterisk Security Team
- [FD] ManageEngine Eventlog Analyzer v4-v10 Privilege Esacalation
- [FD] Symphony CMS 2.6.3 – Multiple SQL Injection Vulnerabilities
- [FD] VMWare Zimbra Mailer | DKIM longterm Mail Replay vulnerability
- [FD] OpenXchange | Information Disclosure
- [FD] Equibase.com HTML Injection/Possible Reflected XSS
- [FD] Atutor 2.2: XSS
- From: Curesec Research Team (CRT)
- [FD] Opendocman 1.3.4: CSRF
- From: Curesec Research Team (CRT)
- [FD] Opendocman 1.3.4: HTML Injection
- From: Curesec Research Team (CRT)
- [FD] Time-based SQL Injection in Admin panel UliCMS <= v9.8.1
- From: Manuel Garcia Cardenas
- [FD] GE Industrial Solutions - UPS SNMP Adapter Command Injection and Clear-text Sensitive Info Vulnerabilities
- [FD] MailPoet Newsletter 2.6.19 - Security Advisory - Reflected XSS
- [FD] ASUS RT-N56U Persistent XSS
- [FD] DLink DVGN5402SP Multiple Vulnerabilities
- [FD] Sauter ModuWEB Vision SCADA vulnerabilities
- [FD] Dell SecureWorks iOS Application - MITM SSL Certificate Vulnerability
- [FD] [CERT 777024 / CVE-2016-1524/5]: RCE and file download in Netgear NMS300
- [FD] CALL FOR PAPERS - FAQin Congress - Madrid
- [FD] Apple Software Update 2.1.3 (Windows) Remote Command Execution.
- [FD] A tale of openssl_seal(), PHP and Apache2handle
- [FD] ArpON (ARP handler inspection) 3.0-ng release
- [FD] Apple iOS v9.1, 9.2 & 9.2.1 - Application Update Loop Pass Code Bypass
- [FD] NDI5aster – Privilege Escalation through NDIS 5.x Filter Intermediate Drivers
- [FD] osTicket multiple vulnerabilities
- [FD] Netgear RP614v3 : Authentication Bypass
- [FD] Executable installers are vulnerable^WEVIL (case 23): WinImage's installer and self-extractors allow arbitrary (remote) code execution and escalation of privilege
- [FD] JavaScript Anywhere v3.0.4 iOS - Persistent Vulnerability
- [FD] Getdpd BB #3 - Persistent Cross Site Scripting Vulnerability
- [FD] Getdpd BB #5 - Persistent Filename Vulnerability
- [FD] Getdpd BB #4 - (name) Persistent Validation Vulnerability
- [FD] Alsovalue CMS 2016Q1 - SQL Injection Web Vulnerability
- [FD] Ebay Inc (Pages) - Client Side Cross Site Scripting Vulnerabilities
- [FD] PressePortal NewsAktuell (DPA) - Multiple Vulnerabilities
- [FD] SEC Consult SA-20160210-0 :: Yeager CMS Multiple Vulnerabilities
- From: SEC Consult Vulnerability Lab
- [FD] File Sharing Manager v1.0 iOS - Multiple Web Vulnerabilities
- [FD] MyScript Memo v3.0 iOS - (Mail) Persistent Vulnerability
- [FD] Getdpd Bug Bounty #6 - (Import - FTP) Persistent Vulnerability
- [FD] Apache Sling Framework v2.3.6 (Adobe AEM) [CVE-2016-0956] - Information Disclosure Vulnerability
- [FD] NPS Datastore server DLL side loading vulnerability
- [FD] BDA MPEG2 Transport Information Filter DLL side loading vulnerability
- [FD] MapsUpdateTask Task DLL side loading vulnerability
- Re: [FD] OLE DB Provider for Oracle multiple DLL side loading vulnerabilities
- [FD] D-Link router DSL-2750B firmware 1.01 to 1.03 - remote command execution no auth required
- [FD] [CVE-2016-0602, CVE-2016-0603] Executable installers are vulnerable^WEVIL (case 24): Oracle Java 6/7/8 SE and VirtualBox
- [FD] Multiple vulnerabilities in Open Real Estate v 1.15.1
- From: Simon Waters (Surevine)
- [FD] SerVision HVG - Hardcoded password
- [FD] Executable installers are vulnerable^WEVIL (case 25): WinRAR's installer and self-extractors allow arbitrary (remote) code execution and escalation of privilege
- [FD] Poor UX in Asus routers can leave the web UI unintentionally exposed to the Internet
- [FD] CVE-2016-2046 Cross Site Scripting in Sophos UTM 9
- [FD] VP2016-001: Remote Command Execution in File Replication Pro
- From: Vantage Point Security
- Re: [FD] Netgear GS105Ev2 - Multiple Vulnerabilities
- [FD] HD Video Player v2.5 iOS - Multiple Web Vulnerabilities
- [FD] KL-001-2016-001 : Arris DG1670A Cable Modem Remote Command Execution
- From: KoreLogic Disclosures
- [FD] Serena Business Manager < 10.01 DOM XSS Vulnerability
- [FD] RVAsec 2016 CFP is now Open!
- [FD] BSides Hannover 2016
- [FD] Point of Sale WinREST machines remote privilege escalation
- [FD] [ERPSCAN-15-031] SAP MII – Encryption Downgrade vulnerability
- [FD] [ERPSCAN-15-032] SAP PCo agent – DoS vulnerability
- [FD] Redaxo CMS contains multiple vulnerabilities
- [FD] Browser Security Tool: HTTPS Only (Why, How, Open Source, Python)
- [FD] Packet Hacking Village Speaker Workshops at DEF CON 24 CFP Now Open (Modified)
- [FD] Tiny Tiny RSS Blind SQL Injection
- Re: [FD] [oss-security] HTTPS Only (Open Source, Python)
- [FD] BFS-SA-2016-001: FireEye Detection Evasion and Whitelisting of Arbitrary Malware
- From: Blue Frost Security Research Lab
- Re: [FD] Point of Sale WinREST machines remote privilege escalation
- Re: [FD] Point of Sale WinREST machines remote privilege escalation
- Re: [FD] Point of Sale WinREST machines remote privilege escalation
- [FD] Vesta Control Panel <= 0.9.8-15 - Persistent XSS Vulnerability
- [FD] CVE-2016-2046 Cross Site Scripting in Sophos UTM 9
- [FD] Umbraco - The open source ASP.NET CMS Multiple Vulnerabilities
- [FD] Cisco ASA VPN - Zero Day Exploit
- [FD] EBAY Bugbounty: Persistent DOM Based XSS on ebay.com
- From: Alexander Korznikov
- [FD] ifixit Bug Bounty #5 - Guide Search Persistent Vulnerability
- [FD] ifixit Bug Bounty #6 -(Profile) Persistent Vulnerability
- [FD] Prezi Bug Bounty #5 - Client Side Cross Site Scripting & Open Redirect Vulnerability
- [FD] Investors Application - Client Side Cross Site Scripting Vulnerability
- [FD] Chamilo LMS IDOR - (messageId) Delete POST Inject Vulnerability
- [FD] Chamilo LMS - Persistent Cross Site Scripting Vulnerability
- [FD] Adobe - Multiple Client Side Cross Site Scripting Web Vulnerabilities
- [FD] InstantCoder v1.0 iOS - Multiple Web Vulnerabilities
- [FD] Ubiquiti Networks Bug Bounty #9 - Invoice Persistent Vulnerabilities
- Re: [FD] Cisco ASA VPN - Zero Day Exploit
- [FD] Avast Virtualization Driver - Elevation Of Privileges
- [FD] BlackBerry Enterprise Service 12 Self-Service - SQLi and Reflected XSS
- [FD] PLANET IP Surveillance camera Multiple Vulnerabilities
- [FD] ferretCMS– Multiple Cross-Site Scripting Vulnerabilities
- Re: [FD] Cisco ASA VPN - Zero Day Exploit
- From: Mark-David McLaughlin (marmclau)
- [FD] Vulnerability in WebSVN 2.3.3
- [FD] CVE Request: Fiyo CMS 2.0.2.1 - Multiple Persistent XSS Vulnerabilities
- Re: [FD] Cisco ASA VPN - Zero Day Exploit
- [FD] Oxwall Forum v1.8.1 - Persistent Cross Site Scripting Vulnerability
- [FD] InstantCoder v1.0 iOS - Multiple Web Vulnerabilities
- [FD] Prezi Bug Bounty #7 - (Charts) Persistent Vulnerability
- [FD] [KIS-2016-02] Magento <= 1.9.2.2 (RSS Feed) Information Disclosure Vulnerability
- [FD] eFront Learning 3.6.15.6 CMS - (Forum) Persistent Title Web Vulnerability
- [FD] eFront 3.6.15.6 CMS – (Message Attachment) Persistent Cross Site Scripting Vulnerability
- [FD] GTA Firewall GB-OS v6.2.02 - Filter Bypass & Persistent Vulnerability
- [FD] CVE-2015-0955 - Stored XSS in Adobe Experience Manager (AEM)
- [FD] CSNC-2016-001 - XSS in OpenAM
- [FD] CSNC-2016-002 - Open Redirect in OpenAM
- [FD] Ubiquiti Networks UniFi v3.2.10 Generic CSRF Protection Bypass
- [FD] CVE ID Request : Centreon remote code execution
- [FD] CVE ID Request : Proxmox VE Insecure hostname checking (remote root exploit)
- [FD] CVE-2015-6541 : Multiple CSRF in Zimbra Mail interface
- [FD] D-Link, Netgear Router Vulnerabiltiies
- [FD] XSSer v1.7b: "ZiKA-47 Swarm!" released....
- Re: [FD] Executable installers are vulnerable^WEVIL (case 26): the installer of GIMP for Windows allows arbitrary (remote) and escalation of privilege
- Re: [FD] Cisco ASA VPN - Zero Day Exploit
- [FD] Hacking Passwords, Lesson 11, Available Now!
- [FD] [CVE-2015-5345] Information disclosure vulnerability in Apache Tomcat
- [FD] Various Linux Kernel USERNS Issues
- [FD] Executable installers are vulnerable^WEVIL (case 26): the installer of GIMP for Windows allows arbitrary (remote) and escalation of privilege
- Re: [FD] Executable installers are vulnerable^WEVIL (case 26): the installer of GIMP for Windows allows arbitrary (remote) and escalation of privilege
- [FD] Executable installers are vulnerable^WEVIL (case 4): InstallShield's wrapper and setup.exe
- [FD] WP Good News Themes - Client Side Cross Site Scripting Web Vulnerability
Mail converted by MHonArc