Category Archives: Full Disclosure

Full Disclosure

Cross-Site Scripting in Activity Log WordPress Plugin

Posted by Summer of Pwnage on Aug 03

————————————————————————
Cross-Site Scripting in Activity Log WordPress Plugin
————————————————————————
Yorick Koster, July 2016

————————————————————————
Abstract
————————————————————————
A Cross-Site Scripting vulnerability was found in the Activity Log…

Cross-Site Scripting vulnerability in search function Activity Log WordPress Plugin

Posted by Summer of Pwnage on Aug 03

————————————————————————
Cross-Site Scripting vulnerability in search function Activity Log
WordPress Plugin
————————————————————————
Edwin Molenaar, July 2016

————————————————————————
Abstract
————————————————————————
A Cross-Site Scripting vulnerability…

Cross-Site Scripting in WangGuard WordPress Plugin

Posted by Summer of Pwnage on Aug 02

————————————————————————
Cross-Site Scripting in WangGuard WordPress Plugin
————————————————————————
Yorick Koster, July 2016

————————————————————————
Abstract
————————————————————————
A Cross-Site Scripting vulnerability was found in the WangGuard…

Cross-Site Scripting in Uji Countdown WordPress Plugin

Posted by Summer of Pwnage on Aug 02

————————————————————————
Cross-Site Scripting in Uji Countdown WordPress Plugin
————————————————————————
Yorick Koster, July 2016

————————————————————————
Abstract
————————————————————————
A Cross-Site Scripting vulnerability was found in the Uji Countdown…

WinSaber – Unquoted Service Path Privilege Escalation

Posted by Vulnerability Lab on Aug 02

Document Title:
===============
WinSaber – Unquoted Service Path Privilege Escalation

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1879

Release Date:
=============
2016-07-29

Vulnerability Laboratory ID (VL-ID):
====================================
1879

Common Vulnerability Scoring System:
====================================
4.2

Product & Service Introduction:…

Zoll ePCR v2.6.4 iOS – Multiple Persistent Vulnerabilities

Posted by Vulnerability Lab on Aug 02

Document Title:
===============
Zoll ePCR v2.6.4 iOS – Multiple Persistent Vulnerabilities

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1882

Release Date:
=============
2016-08-01

Vulnerability Laboratory ID (VL-ID):
====================================
1882

Common Vulnerability Scoring System:
====================================
3.5

Product & Service Introduction:…

Docebo LMS 6.9 – (Moxie) API Calls RST Remote Code Execution Vulnerability

Posted by Vulnerability Lab on Aug 02

Document Title:
===============
Docebo LMS 6.9 – (Moxie) API Calls RST Remote Code Execution Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1888

Video: http://www.vulnerability-lab.com/get_content.php?id=1892

Release Date:
=============
2016-08-02

Vulnerability Laboratory ID (VL-ID):
====================================
1888

Common Vulnerability Scoring System:…

Car CMS v3.00.30 – Search Cross Site Scripting Vulnerability

Posted by Vulnerability Lab on Aug 02

Document Title:
===============
Car CMS v3.00.30 – Search Cross Site Scripting Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1891

Release Date:
=============
2016-08-01

Vulnerability Laboratory ID (VL-ID):
====================================
1891

Common Vulnerability Scoring System:
====================================
3.2

Product & Service Introduction:…

Guppy CMS v5.01.03 – Client Side Cross Site Scripting Web Vulnerability

Posted by Vulnerability Lab on Aug 02

Document Title:
===============
Guppy CMS v5.01.03 – Client Side Cross Site Scripting Web Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1887

Release Date:
=============
2016-07-29

Vulnerability Laboratory ID (VL-ID):
====================================
1887

Common Vulnerability Scoring System:
====================================
3.3

Product & Service Introduction:…

FortiManager (Series) – Multiple Web Vulnerabilities

Posted by Vulnerability Lab on Aug 02

Document Title:
===============
FortiManager (Series) – Multiple Web Vulnerabilities

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1684

Fortinet PSIRT ID: 1624459

Release Notes 1: http://docs.fortinet.com/uploaded/files/2910/fortimanager-v5.4.0-release-notes.pdf
Release Notes 2: http://docs.fortinet.com/uploaded/files/2963/fortimanager-v5.2.6-release-notes.pdf
Release Notes 3:…