Full Disclosure: by date

41 messages starting Apr 04 19 and ending Apr 30 19
Date index | Thread index | Author index


Thursday, 04 April

Various vulnerabilities in Lupusec XT2 Plus home alarm system Dan Fabian
Uniqkey Password Manager 1.14 - Remote Credential Disclosure gionreale
Open-Xchange Security Advisory 2019-04-01 Open-Xchange GmbH via Fulldisclosure
c0c0n XII | The cy0ps c0n - Call For Papers & Call For Workshops Prajwal Panchmahalkar
CVE-2019-7727 - JMX/RMI Nice ENGAGE <= 6.5 Remote Command Execution Red Timmy Sec -
DSA-2019-031: Dell EMC IsilonSD Management Server Cross-Site Scripting (XSS) Vulnerabilities secure
SphereFTP 2.0 Denial Of Service Sachin Wagh
hardwear.io 2019 Call For Papers is Open - USA & Netherlands Yuliya Pliavaka

Friday, 05 April

Uniqkey Password Manager 1.14 - Remote Denial Of Service [CVE-2019-10845] gionreale
Arris Touchstone TG1672 Administrative Login Vulnerabilities Harley A.W. Lorenzo via Fulldisclosure
WordPress Plugin Form Maker by WD [CSRF → LFI] Panagiotis Vagenas
WordPress plugin Contact Form by WD [CSRF → LFI] Panagiotis Vagenas

Tuesday, 09 April

Loytec LGATE-902: Multiple Vulnerabilities (XSS, Path traversal and File Deletion) Daniel dos Santos
EasyIO 30P: CVE-2018-15820 (Stored XSS) and CVE-2018-15819 (Authentication bypass) Daniel dos Santos
GAT-Ship Web Module [All versions before 1.40] - Unrestricted File Upload gionreale
CALL FOR PAPERS - Hackers 2 Hackers Conference 16th edition Rodrigo Rubira Branco (BSDaemon)
DSA-2019-031: Dell EMC IsilonSD Management Server Cross-Site Scripting (XSS) Vulnerabilities secure
HD Pan/Tilt Wi-Fi Camera NC450 Hard-Coded Credential Vulnerability Sachin Wagh

Saturday, 13 April

Security Analysis of the TP-Link Archer C50 Router Harley A.W. Lorenzo via Fulldisclosure
Nagios XI 5.5.10: XSS to root RCE (CVE-2019-9164, 9165, 9166, 9167, 9202, 9203, 9204) Abdel Adim `smaury` Oisfi
Microsoft Internet Explorer v11 / XML External Entity Injection 0day hyp3rlinx

Sunday, 14 April

[SE-2019-01] Gemalto SIM card applet loading vulnerability Security Explorations

Tuesday, 16 April

CVE-2019-9955 Refelected XSS on Zyxel Login page aaron bishop
Re: Microsoft Internet Explorer v11 / XML External Entity Injection 0day bo0od
Redhat/CentOS root through network-scripts Victor Angelier CCX

Thursday, 18 April

Re: Microsoft Internet Explorer v11 / XML External Entity Injection 0day hyp3rlinx
Obtaining location using Google maps & JavaScript Bhavesh Naik via Fulldisclosure
Re: Redhat/CentOS root through network-scripts Kurt H Maier
CVE-2018-2879 - anniversary Red Timmy Sec -
Re: Redhat/CentOS root through network-scripts Victor Angelier CCX

Tuesday, 23 April

WordPress Plugin Contact Form Builder [CSRF → LFI] Panagiotis Vagenas
Re: Obtaining location using Google maps & JavaScript Reed Black
Multiple vulnerabilities in Sony Smart TVs xen1thLabs

Friday, 26 April

Re: GAT-Ship Web Module [All versions before 1.40] - Unrestricted File Upload gionreale

Tuesday, 30 April

Multiple vulnerabilities in Dovecot 2.3 Aki Tuomi via Fulldisclosure
Re: WordPress Plugin Contact Form Builder [CSRF → LFI] Henri Salo
Re: WordPress Plugin Form Maker by WD [CSRF → LFI] Henri Salo
Re: WordPress plugin Contact Form by WD [CSRF → LFI] Henri Salo
OpenPGP and S/MIME signature forgery attacks in multiple email clients Jens Müller via Fulldisclosure
[REVIVE-SA-2019-001] Revive Adserver - Multiple vulnerabilities Matteo Beccati via Fulldisclosure
[CVE-2019-9826] phpBB Native Fulltext Search denial of service Colin Snover