Advisory:
|
SimpleGroupware 0.742 Cross-Site-Scripting vulnerability
|
Advisory ID:
|
INFOSERVE-ADV2012-01
|
Author:
|
Stefan Schurtz
|
Contact:
|
|
Affected Software:
|
Successfully tested on SimpleGroupware 0.742
|
Vendor URL:
|
|
Vendor Status:
|
fixed (see Changelog)
|
|
|
======================
Vulnerability Description
======================
SimpleGroupware 0.742 ‘export’ parameter XSS vulnerability
Continue reading "INFOSERVE-ADV2012-01 - SimpleGroupware 0.742 Cross-Site-Scripting vulnerability"
Advisory:
|
Tiki Wiki CMS Groupware Stored Cross-Site-Scripting
|
Advisory ID:
|
INFOSERVE-ADV2011-07
|
Author:
|
Stefan Schurtz
|
Contact:
|
|
Affected Software:
|
Successfully tested on Tiki 8.1 & 6.4 LTS (affects all current releases)
|
Vendor URL:
|
|
Vendor Status:
|
fixed
|
CVE-ID:
|
CVE-2011-4551
|
======================
Vulnerability Description
======================
All current releases of Tiki Wiki are prone to a stored XSS vulnerability
Continue reading "INFOSERVE-ADV2011-07 - Tiki Wiki CMS Groupware stored Cross-Site-Scripting"
Advisory:
|
Seotoaster SQL-Injection Admin Login Bypass
|
Advisory ID:
|
INFOSERVE-ADV2011-06
|
Author:
|
Stefan Schurtz
|
Contact:
|
|
Affected Software:
|
Successfully tested on Seotoaster v.1.9
|
Vendor URL:
|
|
Vendor Status:
|
fixed
|
======================
Vulnerability Description
======================
Seotoaster v.1.9 is prone to an SQL-Injection which bypass the admin login
Continue reading "INFOSERVE-ADV2011-06 - Seotoaster SQL-Injection Admin Login Bypass"
Advisory:
|
zFTPServer Suite 6.0.0.52 'rmdir' Directory Traversal
|
Advisory ID:
|
INFOSERVE-ADV2011-09
|
Author:
|
Stefan Schurtz
|
Contact:
|
|
Affected Software:
|
Successfully tested on zFTPServer Suite 6.0.0.52
|
Vendor URL:
|
|
Vendor Status:
|
fixed
|
CVE-ID:
|
CVE-2011-4717
|
==========================
Vulnerability Description
==========================
zFTPServer 'rmdir' is prone to a Directory Traversal, which makes it possible to delete directories in the system
Continue reading "INFOSERVE-ADV2011-09 - zFTPServer Suite 6.0.0.52 'rmdir' Directory Traversal"
Advisory:
|
PHP Inventory 1.3.1 Remote (Auth Bypass) SQL Injection Vulnerability
|
Advisory ID:
|
INFOSERVE-ADV2011-08
|
Author:
|
Stefan Schurtz
|
Contact:
|
|
Affected Software:
|
Successfully tested on PHP Inventory 1.3.1
|
Vendor URL:
|
|
Vendor Status:
|
fixed
|
CVE-ID:
|
CVE-2009-4595,CVE-2009-4596,CVE-2009-4597
|
======================
Vulnerability Description
======================
PHP Inventory is (still) prone to a SQL-Injection (Auth Bypass) vulnerability
Continue reading "INFOSERVE-ADV2011-08 - PHP Inventory 1.3.1 Remote (Auth Bypass) SQL Injection Vulnerability"
Advisory:
|
Multiple security vulnerabilities in AShop
|
Advisory ID:
|
INFOSERVE-ADV2011-02
|
Author:
|
Stefan Schurtz
|
Contact:
|
|
Affected Software:
|
Successfully tested on AShop513
|
|
|
Vendor Status:
|
fixed in Version 5.1.4
|
======================
Vulnerability Description:
======================
AShop is prone to multiple security vulnerabilities
Continue reading "INFOSERVE-ADV2011-02 - Multiple security vulnerabilities in AShop"