[FD] CSNC-2016-002 - Open Redirect in OpenAM

2016-02-25 Thread Alexandre Herzog
# # # COMPASS SECURITY ADVISORY http://www.csnc.ch/en/downloads/advisories.html # # # CSNC ID: CSNC-2016-002 # Product: OpenAM [1] # Vendor: For

[FD] CSNC-2016-001 - XSS in OpenAM

2016-02-25 Thread Alexandre Herzog
# # # COMPASS SECURITY ADVISORY http://www.csnc.ch/en/downloads/advisories.html # # # CSNC ID: CSNC-2016-001 # Product: OpenAM [1] # Vendor: For

[FD] CVE-2015-0955 - Stored XSS in Adobe Experience Manager (AEM)

2016-02-25 Thread Alexandre Herzog
# # # COMPASS SECURITY ADVISORY http://www.csnc.ch/ # # # CSNC ID: CSNC-2015-011 # CVE ID :CVE-2015-0955 # Product: Adobe Experience Manager

Re: [FD] Authentication Bypass in Netgear Router Firmware N300_1.1.0.31_1.0.1.img and N300-1.1.0.28_1.0.1.img

2015-10-08 Thread Alexandre Herzog
September (!) but did not yet publish… Thanks, Alexandre From: Joe G [mailto:joseph.giro...@gmail.com] Sent: Dienstag, 6. Oktober 2015 19:02 To: Alexandre Herzog Cc: bugt...@securityfocus.com; fulldisclosure@seclists.org Subject: Re: Authentication Bypass in Netgear Router Firmware

[FD] Authentication Bypass in Netgear Router Firmware N300_1.1.0.31_1.0.1.img and N300-1.1.0.28_1.0.1.img

2015-10-08 Thread Alexandre Herzog
# # # COMPASS SECURITY ADVISORY # http://www.csnc.ch/en/downloads/advisories.html # # # # Product: Netgear Router Firmware N300_1.1.0.31_1.0.1.img # and N300-1.

[FD] SAP Security Note 1908531 - XXE in BusinessObjects Explorer

2014-10-09 Thread Alexandre Herzog
### # # COMPASS SECURITY ADVISORY # http://www.csnc.ch/en/downloads/advisories.html # ### # # Product: BusinessObjects Explorer # Vendor:SAP

[FD] SAP Security Note 1908647 - Cross Site Flashing in BusinessObjects Explorer

2014-10-09 Thread Alexandre Herzog
### # # COMPASS SECURITY ADVISORY # http://www.csnc.ch/en/downloads/advisories.html # ### # # Product: BusinessObjects Explorer # Vendor:SAP

[FD] SAP Security Note 1908562 - Port scanning in BusinessObjects Explorer

2014-10-09 Thread Alexandre Herzog
### # # COMPASS SECURITY ADVISORY # http://www.csnc.ch/en/downloads/advisories.html # ### # # Product: BusinessObjects Explorer # Vendor:SAP

[FD] CSNC-2014-004 neuroML - Multiple Vulnerabilities

2014-10-09 Thread Alexandre Herzog
# # # COMPASS SECURITY ADVISORY # http://www.csnc.ch/en/downloads/advisories.html # # # # Product: neuroML # Version: <=v1.8.1 (Confirmed: v1.8.1) # Vendor: neuroML.org # CSNC

[FD] JavaMail SMTP Header Injection via method setSubject [CSNC-2014-001]

2014-05-19 Thread Alexandre Herzog
: # Subject: SMTP Header Injection via method setSubject # Risk: Medium # Effect: Remotely exploitable # Author: Alexandre Herzog # Date: 19.05.2014 # # Introduction: - The JavaMail API