Category Archives: Full Disclosure

Full Disclosure

FortiCloud – (Reports Summary) Multiple Persistent Vulnerabilities

Posted by Vulnerability Lab on Aug 05

Document Title:
===============
FortiCloud – (Reports Summary) Multiple Persistent Vulnerabilities

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1735

Release Date:
=============
2016-08-05

Vulnerability Laboratory ID (VL-ID):
====================================
1735

Common Vulnerability Scoring System:
====================================
3.6

Product & Service Introduction:…

Subrion v4.0.5 CMS – SQL Injection Vulnerability

Posted by Vulnerability Lab on Aug 05

Document Title:
===============
Subrion v4.0.5 CMS – SQL Injection Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1893

Release Date:
=============
2016-08-04

Vulnerability Laboratory ID (VL-ID):
====================================
1893

Common Vulnerability Scoring System:
====================================
7

Product & Service Introduction:
===============================…

Typesettercms v5.0.1 – (Delete Files) CSRF Vulnerability

Posted by Vulnerability Lab on Aug 05

Document Title:
===============
Typesettercms v5.0.1 – (Delete Files) CSRF Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1889

Release Date:
=============
2016-08-03

Vulnerability Laboratory ID (VL-ID):
====================================
1889

Common Vulnerability Scoring System:
====================================
3

Product & Service Introduction:…

Stored Cross-Site Scripting vulnerability in Count per Day WordPress Plugin

Posted by Summer of Pwnage on Aug 04

————————————————————————
Stored Cross-Site Scripting vulnerability in Count per Day WordPress
Plugin
————————————————————————
Julien Rentrop, July 2016

————————————————————————
Abstract
————————————————————————
A Cross-Site Scripting vulnerability was found…

Cross-Site Scripting in Count per Day WordPress Plugin

Posted by Summer of Pwnage on Aug 04

————————————————————————
Cross-Site Scripting in Count per Day WordPress Plugin
————————————————————————
Yorick Koster, July 2016

————————————————————————
Abstract
————————————————————————
A Cross-Site Scripting vulnerability was found in the Count per Day…

Cross-Site Scripting in FormBuilder WordPress Plugin

Posted by Summer of Pwnage on Aug 04

————————————————————————
Cross-Site Scripting in FormBuilder WordPress Plugin
————————————————————————
Peter Ganzevles, July 2016

————————————————————————
Abstract
————————————————————————
A Reflected Cross-Site Scripting (XSS) vulnerability has been found…

Cross-Site Scripting vulnerability in Events Made Easy WordPress plugin

Posted by Summer of Pwnage on Aug 04

————————————————————————
Cross-Site Scripting vulnerability in Events Made Easy WordPress plugin
————————————————————————
Job Diesveld, July 2016

————————————————————————
Abstract
————————————————————————
A Cross-Site Scripting vulnerability has been found…

FortiManager (Series) – (Bookmark) Persistent Vulnerability

Posted by Vulnerability Lab on Aug 04

Document Title:
===============
FortiManager (Series) – (Bookmark) Persistent Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1685

Fortinet PSIRT ID: 1624461

Release Notes 1: http://docs.fortinet.com/uploaded/files/2499/fortios-5.0.12-release-notes.pdf
Release Notes 2: http://docs.fortinet.com/uploaded/files/2861/fortios-v5.2.6-release-notes.pdf
Release Notes 3:…

FortiAnalyzer & FortiManager – Client Side Cross Site Scripting Web Vulnerability

Posted by Vulnerability Lab on Aug 04

Document Title:
===============
FortiAnalyzer & FortiManager – Client Side Cross Site Scripting Web Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1686

Fortinet PSIRT ID: 1624489

Release Notes 1: http://docs.fortinet.com/uploaded/files/2861/fortios-v5.2.6-release-notes.pdf
Release Notes 2: http://docs.fortinet.com/uploaded/files/3075/fortios-v5.4.1-release-notes.pdf
Release Notes…

Cross-Site Scripting in WordPress Landing Pages Plugin

Posted by Summer of Pwnage on Aug 03

————————————————————————
Cross-Site Scripting in WordPress Landing Pages Plugin
————————————————————————
Burak Kelebek, July 2016

————————————————————————
Abstract
————————————————————————
A reflected Cross-Site Scripting (XSS) vulnerability has been found…