[FD] [KIS-2014-19] Symantec Web Gateway <= 5.2.1 (restore.php) OS Command Injection Vulnerability

2014-12-31 Thread Egidio Romano
-- Symantec Web Gateway <= 5.2.1 (restore.php) OS Command Injection Vulnerability -- [-] Software Link: http://www.symantec.com/web-gateway/ [

[FD] [KIS-2014-18] Mantis Bug Tracker <= 1.2.17 (ImportXml.php) PHP Code Injection Vulnerability

2014-12-31 Thread Egidio Romano
- Mantis Bug Tracker <= 1.2.17 (ImportXml.php) PHP Code Injection Vulnerability - [-] Software Link: http://www.mantisbt.org/ [-] Affected Ver

[FD] [KIS-2014-17] GetSimple CMS <= 3.3.4 (api.php) XML External Entity Vulnerability

2014-12-31 Thread Egidio Romano
-- GetSimple CMS <= 3.3.4 (api.php) XML External Entity Vulnerability -- [-] Software Link: http://get-simple.info/ [-] Affected Versions: All versions from 3.1.1 to

[FD] [KIS-2014-16] Osclass <= 3.4.2 (contact.php) Unrestricted File Upload Vulnerability

2014-12-31 Thread Egidio Romano
- Osclass <= 3.4.2 (contact.php) Unrestricted File Upload Vulnerability - [-] Software Link: http://osclass.org/ [-] Affected Versions: Version 3.4.2 an

[FD] [KIS-2014-15] Osclass <= 3.4.2 (ajax.php) Local File Inclusion Vulnerability

2014-12-31 Thread Egidio Romano
-- Osclass <= 3.4.2 (ajax.php) Local File Inclusion Vulnerability -- [-] Software Link: http://osclass.org/ [-] Affected Versions: Version 3.4.2 and probably prior vers

[FD] [KIS-2014-14] Osclass <= 3.4.2 (Search::setJsonAlert) SQL Injection Vulnerability

2014-12-31 Thread Egidio Romano
--- Osclass <= 3.4.2 (Search::setJsonAlert) SQL Injection Vulnerability --- [-] Software Link: http://osclass.org/ [-] Affected Versions: Version 3.4.2 and prob