[FD] [KIS-2024-03] Invision Community <= 4.7.16 (toolbar.php) Remote Code Execution Vulnerability

2024-04-11 Thread Egidio Romano
VE identifier requested [24/03/2024] - CVE identifier assigned [05/04/2024] - Coordinated public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2024-30162 to this vulnerability. [-] Credits: Vulnerability discovered by

[FD] [KIS-2024-02] Invision Community <= 4.7.15 (store.php) SQL Injection Vulnerability

2024-04-11 Thread Egidio Romano
2024] - Vulnerability details sent to SSD Secure Disclosure [12/03/2024] - Version 4.7.16 released [20/03/2024] - CVE identifier requested [24/03/2024] - CVE identifier assigned [05/04/2024] - Coordinated public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (

[FD] [KIS-2024-01] XenForo <= 2.2.13 (ArchiveImport.php) Zip Slip Vulnerability

2024-02-04 Thread Egidio Romano
ssigned a CVE identifier for this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Other References: https://xenforo.com/tickets/BC37EB98/?v=5da7bd5728 [-] Original Advisory: http://karmainsecurity.com/KIS-2024-01 ___ Sent

[FD] [KIS-2023-14] PKP-WAL <= 3.4.0-3 (NativeImportExportPlugin) Remote Code Execution Vulnerability

2023-12-19 Thread Egidio Romano
lic GitHub issue: https://github.com/pkp/pkp-lib/issues/9464 [05/11/2023] - CVE identifier assigned [17/11/2023] - Version 3.4.0-4 released [14/12/2023] - Publication of this advisory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assign

[FD] [KIS-2023-13] ISPConfig <= 3.2.11 (language_edit.php) PHP Code Injection Vulnerability

2023-12-12 Thread Egidio Romano
23] - Version 3.2.11p1 released [27/10/2023] - CVE identifier assigned [07/12/2023] - Publication of this advisory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-46818 to this vulnerability. [-] Credits: Vulnerability discove

[FD] [KIS-2023-12] phpFox <= 4.8.13 (redirect) PHP Object Injection Vulnerability

2023-10-27 Thread Egidio Romano
osure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-46817 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: https://karmainsecurity.com/KIS-2023-12 [-] Other References: h

[FD] [KIS-2023-11] SugarCRM <= 13.0.1 (set_note_attachment) Unrestricted File Upload Vulnerability

2023-10-26 Thread Egidio Romano
uested [26/10/2023] - Publication of this advisory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has not assigned a CVE identifier for this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: https://karmainsecuri

[FD] [KIS-2023-10] SugarCRM <= 13.0.1 (GetControl) Server-Side Template Injection Vulnerability

2023-10-26 Thread Egidio Romano
erabilities and Exposures project (cve.mitre.org) has not assigned a CVE identifier for this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: https://karmainsecurity.com/KIS-2023-10 [-] Other References: https://support.sugarcrm.com/resour

[FD] [KIS-2023-09] CrafterCMS <= 4.0.2 Multiple Reflected Cross-Site Scripting Vulnerabilities

2023-08-23 Thread Egidio Romano
CVE-2023-4136 to these vulnerabilities. [-] Credits: Vulnerabilities discovered by Egidio Romano, working with IMQ Minded Security. [-] Original Advisory: https://karmainsecurity.com/KIS-2023-09 [-] Other References: https://docs.craftercms.org/en/4.1/security/advisory.html#cv-2023080

[FD] [KIS-2023-08] SugarCRM <= 12.2.0 Two SQL Injection Vulnerabilities

2023-08-23 Thread Egidio Romano
CVE-2023-35811 to these vulnerabilities. [-] Credits: Vulnerabilities discovered by Egidio Romano. [-] Original Advisory: https://karmainsecurity.com/KIS-2023-08 [-] Other References: https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2023-

[FD] [KIS-2023-07] SugarCRM <= 12.2.0 (Docusign_GlobalSettings) PHP Object Injection Vulnerability

2023-08-23 Thread Egidio Romano
rability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: https://karmainsecurity.com/KIS-2023-07 [-] Other References: https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2023-009/ ___ Sent through the Full Disclo

[FD] [KIS-2023-06] SugarCRM <= 12.2.0 (updateGeocodeStatus) Bean Manipulation Vulnerability

2023-08-23 Thread Egidio Romano
- Vendor notified [12/04/2023] - Fixed versions released [17/06/2023] - CVE number assigned [23/08/2023] - Publication of this advisory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-35809 to this vulnerability. [-]

[FD] [KIS-2023-05] SugarCRM <= 12.2.0 (Notes) Unrestricted File Upload Vulnerability

2023-08-23 Thread Egidio Romano
number assigned [23/08/2023] - Publication of this advisory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-35808 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://kar

[FD] [KIS-2023-04] Tiki Wiki CMS Groupware <= 24.1 (tikiimporter_blog_wordpress.php) PHP Object Injection Vulnerability

2023-01-09 Thread Egidio Romano
leased [09/01/2023] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-22851 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/K

[FD] [KIS-2023-03] Tiki Wiki CMS Groupware <= 24.0 (grid.php) PHP Object Injection Vulnerability

2023-01-09 Thread Egidio Romano
.items.add(file); fileInput.files = dataTransfer.files; document.forms[0].submit(); [-] Solution: Upgrade to version 24.1 or later. [-] Disclosure Timeline: [07/03/2022] - Vendor notified [23/08/2022] - Version 24.1 released [09/01/2023]

[FD] [KIS-2023-02] Tiki Wiki CMS Groupware <= 24.0 (structlib.php) PHP Code Injection Vulnerability

2023-01-09 Thread Egidio Romano
[08/03/2022] - Vendor notified [23/08/2022] - Version 24.1 released [09/01/2023] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-22853 to this vulnerability. [-] Credits: Vulnerability discovered by Egi

[FD] [KIS-2023-01] Tiki Wiki CMS Groupware <= 25.0 Two Cross-Site Request Forgery Vulnerabilities

2023-01-09 Thread Egidio Romano
ied [09/01/2023] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2023-22852 to this vulnerability. [-] Credits: Vulnerabilities discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2

[FD] Drupal H5P Module <= 2.0.0 (isValidPackage) Zip Slip Vulnerability

2022-12-03 Thread Egidio Romano
roject (cve.mitre.org) has not assigned a CVE identifier for this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Other References: https://security.drupal.org/node/175968 [-] Original Advisory: http://karmainsecurity.com/KIS-2022-06 __

[FD] Exploiting an N-day vBulletin PHP Object Injection Vulnerability

2022-11-29 Thread Egidio Romano
Hello list, Just wanted to share with you my latest blog post: http://karmainsecurity.com/exploiting-an-nday-vbulletin-php-object-injection Best regards, /EgiX ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisc

[FD] [KIS-2022-05] Joomla! <= 4.1.0 (Tar.php) Zip Slip Vulnerability

2022-03-29 Thread Egidio Romano
ged by the vendor [21/02/2021] - Vendor sent details about a proposed patch [21/02/2021] - Sent feedback about the patch correctness [29/03/2022] - Vendor update released [29/03/2022] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has as

Re: [FD] ImpressCMS: from unauthenticated SQL injection to RCE

2022-03-28 Thread Egidio Romano
Hello again, Just wanted to let you know I updated the blog post with some more details: apparently, this technique could be abused to bypass WAFs such as OWASP ModSecurity CRS (Paranoia Level 1) and Cloudflare, check it out! /EgiX On Wed, Mar 23, 2022 at 3:07 PM Egidio Romano wrote: > He

[FD] ImpressCMS: from unauthenticated SQL injection to RCE

2022-03-23 Thread Egidio Romano
Hello list, I'd like to share with you my latest blog post. Hope you may find this SQL injection exploitation technique interesting and potentially useful for your penetration tests. Enjoy it! Link: http://karmainsecurity.com/impresscms-from-unauthenticated-sqli-to-rce Best regards, /EgiX __

[FD] [KIS-2022-04] ImpressCMS <= 1.4.3 (findusers.php) SQL Injection Vulnerability

2022-03-22 Thread Egidio Romano
eased [22/03/2022] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2021-26599 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Other References: https://hackerone.com/reports/1081

[FD] [KIS-2022-03] ImpressCMS <= 1.4.2 (findusers.php) Incorrect Access Control Vulnerability

2022-03-22 Thread Egidio Romano
es and Exposures project (cve.mitre.org) has assigned the name CVE-2021-26598 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Other References: https://hackerone.com/reports/1081137 [-] Original Advisory: http://karmainsecurity.com/KIS-2022-03 ___

[FD] [KIS-2022-02] ImpressCMS <= 1.4.2 (image-edit.php) Path Traversal Vulnerability

2022-03-22 Thread Egidio Romano
d Exposures project (cve.mitre.org) has assigned the name CVE-2021-26601 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Other References: https://hackerone.com/reports/1081878 [-] Original Advisory: http://karmainsecurity.com/KIS-2022-02 __

[FD] [KIS-2022-01] ImpressCMS <= 1.4.2 (autologin.php) Authentication Bypass Vulnerability

2022-03-22 Thread Egidio Romano
resolved and will be in ImpressCMS 1.4.3 [03/02/2021] - CVE number assigned [06/02/2022] - Version 1.4.3 released [22/03/2022] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2021-26600 to this vulnerability

[FD] [KIS-2021-05] Concrete5 <= 8.5.5 (Logging Settings) Phar Deserialization Vulnerability

2021-07-19 Thread Egidio Romano
fixed [02/06/2021] - Asked for an update, no response [06/07/2021] - Asked for an update, no response [16/07/2021] - CVE number assigned [19/07/2021] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2021-36766 to t

[FD] [KIS-2021-01] IPS Community Suite <= 4.5.4 (Downloads REST API) SQL Injection Vulnerability

2021-01-06 Thread Egidio Romano
tified through HackerOne [27/12/2020] - Vendor released a targeted patch [05/01/2021] - Vendor released version 4.5.4.2 [05/01/2021] - CVE number assigned [06/01/2021] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name

[FD] [KIS-2020-11] qdPM <= 9.1 (executeExport) PHP Object Injection Vulnerability

2021-01-03 Thread Egidio Romano
the end of the year [30/12/2020] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2020-26165 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio

[FD] SugarCRM < 10.1.0 (Reports Export) SQL Injection Vulnerability

2020-08-11 Thread Egidio Romano
org) has assigned the name CVE-2020-17373 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-17373> to this vulnerability. *• Credits:* Vulnerability discovered by Egidio Romano. ___ Sent through the Full Disclosure mailing list https://nmap.or

[FD] SugarCRM < 10.1.0 Multiple Reflected Cross-Site Scripting Vulnerabilities

2020-08-11 Thread Egidio Romano
blic disclosure *• CVE Reference:* The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2020-17372 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-17372> to these vulnerabilities. *• Credits:* Vulnerabilities discov

[FD] [KIS-2020-08] openSIS <= 7.4 Multiple SQL Injection Vulnerabilities

2020-06-30 Thread Egidio Romano
numbers assigned [30/06/2020] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2020-13380 to vulnerabilities (1) and (2), and name CVE-2020-13381 for the other vulnerabilities. [-] Credits: Vulnerabilities discovered

[FD] [KIS-2020-07] openSIS <= 7.4 (Bottom.php) Local File Inclusion Vulnerability

2020-06-30 Thread Egidio Romano
xed [22/05/2020] - CVE number assigned [30/06/2020] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2020-13383 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisor

[FD] [KIS-2020-06] openSIS <= 7.4 Incorrect Access Control Vulnerabilities

2020-06-30 Thread Egidio Romano
20] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2020-13382 to these vulnerabilities. [-] Credits: Vulnerabilities discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS

[FD] [KIS-2020-05] SuiteCRM <= 7.11.10 Multiple SQL Injection Vulnerabilities

2020-02-12 Thread Egidio Romano
d [10/02/2020] - Version 7.11.11 released [12/02/2020] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2020-8804 to these vulnerabilities. [-] Credits: Vulnerabilities discovered by Egidio Romano. [-] Origina

[FD] [KIS-2020-04] SuiteCRM <= 7.11.11 (add_to_prospect_list) Broken Access Control Vulnerability

2020-02-12 Thread Egidio Romano
has assigned the name CVE-2020-8803 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2020-04 ___ Sent through the Full Disclosure mailing list https://nmap.or

[FD] [KIS-2020-03] SuiteCRM <= 7.11.11 (action_saveHTMLField) Bean Manipulation Vulnerability

2020-02-12 Thread Egidio Romano
sure intention, no response [07/02/2020] - CVE number assigned [12/02/2020] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2020-8802 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Roma

[FD] [KIS-2020-02] SuiteCRM <= 7.11.11 Multiple Phar Deserialization Vulnerabilities

2020-02-12 Thread Egidio Romano
mitre.org) has assigned the name CVE-2020-8801 to these vulnerabilities. [-] Credits: Vulnerabilities discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2020-02 ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] [KIS-2020-01] SuiteCRM <= 7.11.11 Second-Order PHP Object Injection Vulnerabilities

2020-02-12 Thread Egidio Romano
CVE-2020-8800 to these vulnerabilities. [-] Credits: Vulnerabilities discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2020-01 ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/full

[FD] [KIS-2019-10] YouPHPTube <= 7.7 (getChat.json.php) SQL Injection Vulnerability

2019-12-04 Thread Egidio Romano
it.io/JeD2U [02/11/2019] - CVE number assigned [02/12/2019] - Versions 7.8 released [04/12/2019] - Publication of this advisory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2019-18662 to this vulnerability. [-] Credits: Vulnerabili

[FD] [KIS-2019-09] SugarCRM <= 9.0.1 Multiple Phar Deserialization Vulnerabilities

2019-10-10 Thread Egidio Romano
ary PHP objects into the application scope (PHP Object Injection via phar:// stream wrapper), allowing them to carry out a variety of attacks, such as executing arbitrary PHP code. [-] Solution: Upgrade to version 9.0.2, 8.0.4, or later. [-] Disclosure Timeline: [07/02/2019] - Vendor notified

[FD] [KIS-2019-08] SugarCRM <= 9.0.1 Multiple PHP Object Injection Vulnerabilities

2019-10-10 Thread Egidio Romano
ary PHP code. 15) The vulnerability exists because the "authenticateDownloadKey()" function is using the unserialize() function with the "license_validation_key" setting variable, and such a value can be arbitrarily manipulated in different ways. This can be exploit

[FD] [KIS-2019-07] SugarCRM <= 9.0.1 Multiple PHP Code Injection Vulnerabilities

2019-10-10 Thread Egidio Romano
to .php the file extension for the system log file. Successful exploitation of this vulnerability requires a System Administrator account. [-] Solution: Upgrade to version 9.0.2, 8.0.4, or later. [-] Disclosure Timeline: [07/02/2019] - Vendor notified [01/10/2019] - Versions 9.0.2 and 8

[FD] [KIS-2019-06] SugarCRM <= 9.0.1 Multiple Path Traversal Vulnerabilities

2019-10-10 Thread Egidio Romano
meline: [07/02/2019] - Vendor notified [01/10/2019] - Versions 9.0.2 and 8.0.4 released [10/10/2019] - Publication of this advisory [-] Credits: Vulnerabilities discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2

[FD] [KIS-2019-05] SugarCRM <= 9.0.1 Multiple Broken Access Control Vulnerabilities

2019-10-10 Thread Egidio Romano
parameter to "Administration" and the "parent_type" parameter to "expandDatabase" or any other action which does not implement ACL checks). [-] Solution: Upgrade to version 9.0.2, 8.0.4, or later. [-] Disclosure Timeline: [07/02/2019] - Vendor notified [01/10/

[FD] [KIS-2019-04] SugarCRM <= 9.0.1 Multiple SQL Injection Vulnerabilities

2019-10-10 Thread Egidio Romano
d before being used to construct a SQL query. This can be exploited by malicious users to e.g. read sensitive data from the database through in-band SQL Injection attacks. [-] Solution: Upgrade to version 9.0.2, 8.0.4, or later. [-] Disclosure Timeline: [07/02/2019] - Vendor notified [01

[FD] [KIS-2019-03] SugarCRM <= 9.0.1 Multiple Reflected Cross-Site Scripting Vulnerabilities

2019-10-10 Thread Egidio Romano
[-] Disclosure Timeline: [07/02/2019] - Vendor notified [01/10/2019] - Versions 9.0.2 and 8.0.4 released [10/10/2019] - Publication of this advisory [-] Credits: Vulnerabilities discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2019-03 [-] Other References: htt

[FD] [KIS-2019-02] vBulletin <= 5.5.4 (updateAvatar) Remote Code Execution Vulnerability

2019-10-07 Thread Egidio Romano
posures project (cve.mitre.org) has assigned the name CVE-2019-17132 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2019-02 ___ Sent through the Full Disclosur

[FD] vBulletin <= 5.5.4 Two SQL Injection Vulnerabilities

2019-10-07 Thread Egidio Romano
ties and Exposures project (cve.mitre.org) has assigned the name CVE-2019-17271 to these vulnerabilities. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2019-01 ___ Sent through the Full Dis

[FD] [KIS-2018-08] SugarCRM (Web Logic Hooks module) Path Traversal Vulnerability

2018-12-31 Thread Egidio Romano
published [31/12/2018] - Publication of this advisory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has not assigned a CVE identifier for this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainse

[FD] [KIS-2018-07] SugarCRM (Web Logic Hooks module) PHP Code Injection Vulnerability

2018-12-31 Thread Egidio Romano
ublished [31/12/2018] - Publication of this advisory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has not assigned a CVE identifier for this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecu

[FD] [KIS-2018-06] SugarCRM (addLabels) PHP Code Injection Vulnerability

2018-12-31 Thread Egidio Romano
ublished [31/12/2018] - Publication of this advisory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has not assigned a CVE identifier for this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecu

[FD] [KIS-2018-05] SugarCRM (SaveDropDown) PHP Code Injection Vulnerability

2018-12-31 Thread Egidio Romano
s advisory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has not assigned a CVE identifier for this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2018-05 [-] Other Referenc

[FD] [KIS-2018-04] SugarCRM (ConnectorsController) Server-Side Request Forgery Vulnerability

2018-12-31 Thread Egidio Romano
- Fixed versions released and security advisory published [31/12/2018] - Publication of this advisory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has not assigned a CVE identifier for this vulnerability. [-] Credits: Vulnerability discovered by Egidio R

[FD] [KIS-2018-03] SugarCRM (portal_get_related_notes) SQL Injection Vulnerability

2018-12-31 Thread Egidio Romano
t assigned a CVE identifier for this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2018-03 [-] Other References: https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2018-003/ __

[FD] [KIS-2018-02] SugarCRM (WorkFlow module) PHP Code Injection Vulnerability

2018-12-31 Thread Egidio Romano
12/2018] - Publication of this advisory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has not assigned a CVE identifier for this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-

[FD] [KIS-2018-01] Oracle Application Express (AnyChart) Flash-based Cross-Site Scripting Vulnerability

2018-12-31 Thread Egidio Romano
16/01/2018] - Oracle fixed the issue in the January Critical Patch Update (CPU) [31/12/2018] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2018-2699 to this vulnerability. [-] Credits: Vulnerability discove

[FD] [KIS-2017-02] Tuleap <= 9.6 Second-Order PHP Object Injection Vulnerability

2017-10-23 Thread Egidio Romano
Exposures project (cve.mitre.org) has assigned the name CVE-2017-7411 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2017-02 ___ Sent through the Full Disclosure mai

[FD] Tales of SugarCRM Security Horrors

2017-04-23 Thread Egidio Romano
Hello list, Tonight I'd like to share with you my latest blog post. Enjoy! Link: http://karmainsecurity.com/tales-of-sugarcrm-security-horrors Best regards, /EgiX ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/full

[FD] [KIS-2017-01] PEAR HTML_AJAX <= 0.5.7 (PHP Serializer) PHP Object Injection Vulnerability

2017-02-06 Thread Egidio Romano
/02/security [06/02/2017] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2017-5677 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-

[FD] [KIS-2016-13] Piwik <= 2.16.0 (saveLayout) PHP Object Injection Vulnerability

2016-11-07 Thread Egidio Romano
se [17/02/2016] - Bug bounty received [11/04/2016] - Version 2.16.1 released: http://piwik.org/changelog/piwik-2-16-1/ [16/06/2016] - CVE number requested [07/11/2016] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has not assigned

[FD] [KIS-2016-12] Magento <= 1.9.2.2 (RSS Feed) Information Disclosure Vulnerability

2016-10-06 Thread Egidio Romano
bilities and Exposures project (cve.mitre.org) has assigned the name CVE-2016-5313 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2016-12 ___ Sent through th

[FD] [KIS-2016-11] IPS Community Suite <= 4.1.12.3 Autoloaded PHP Code Injection Vulnerability

2016-07-07 Thread Egidio Romano
er assigned [07/07/2016] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2016-6174 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecuri

[FD] [KIS-2016-10] Concrete5 <= 5.7.3.1 (Application::dispatch) Local File Inclusion Vulnerability

2016-06-28 Thread Egidio Romano
advisory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has not assigned a CVE identifier for this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2016-10 [-] Other References

[FD] [KIS-2016-09] Concrete5 <= 5.7.3.1 Multiple Stored Cross-Site Scripting Vulnerabilities

2016-06-28 Thread Egidio Romano
;post('msgstr')); 116.} User input passed through the "msgstr" POST parameter is not properly sanitized before being stored. This can be exploited by an authenticated attacker to permanently store arbitrary script code within the database, which might be executed by anoth

[FD] [KIS-2016-08] Concrete5 <= 5.7.3.1 Multiple Cross-Site Request Forgeries Vulnerabilities

2016-06-28 Thread Egidio Romano
The Common Vulnerabilities and Exposures project (cve.mitre.org) has not assigned a CVE identifier for these vulnerabilities. [-] Credits: Vulnerabilities discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2016-08 [-] Other References: https://hackerone.

[FD] [KIS-2016-07] SugarCRM <= 6.5.23 (SugarRestSerialize.php) PHP Object Injection Vulnerability

2016-06-23 Thread Egidio Romano
The Common Vulnerabilities and Exposures project (cve.mitre.org) has not assigned a CVE identifier for this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2016-07 ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] [KIS-2016-06] SugarCRM <= 6.5.18 (MySugar::addDashlet) Insecure fopen() Usage Vulnerability

2016-06-23 Thread Egidio Romano
olution is currently available against the SSRF and XSS attack vectors. [-] Disclosure Timeline: [15/10/2014] - Vendor notified [15/12/2014] - Version 6.5.19 CE released: http://bit.do/sugar6519 [29/04/2015] - CVE number requested [23/06/2016] - Public disclosure [-] CVE Reference: T

[FD] [KIS-2016-05] SugarCRM <= 6.5.18 Two PHP Code Injection Vulnerabilities

2016-06-23 Thread Egidio Romano
-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has not assigned a CVE identifier for these vulnerabilities. [-] Credits: Vulnerabilities discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2016-05 _

[FD] [KIS-2016-04] SugarCRM <= 6.5.18 Missing Authorization Check Vulnerabilities

2016-06-23 Thread Egidio Romano
abilities and Exposures project (cve.mitre.org) has not assigned a CVE identifier for these vulnerabilities. [-] Credits: Vulnerabilities discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2016-04 ___ Sent through the Fu

[FD] [KIS-2016-03] SugarCRM <= 6.5.18 (SAML Authentication) XML External Entity Vulnerability

2016-06-23 Thread Egidio Romano
tre.org) has not assigned a CVE identifier for this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2016-03 ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] Hacking Magento eCommerce For Fun And 17.000 USD

2016-03-03 Thread Egidio Romano
Hello list, Tonight I'd like to share with you my latest blog post. Seeing my personal experience with the Magento bug bounty program (and even experiences from other security researchers), it looks like they truly believe in a "security through obscurity" methodology. I'm quite disappointed by

[FD] Hacking Magento eCommerce For Fun And 17.000 USD

2016-03-03 Thread Egidio Romano
Hello list, Tonight I'd like to share with you my latest blog post. Seeing my personal experience with the Magento bug bounty program (and even experiences from other security researchers), it looks like they truly believe in a "security through obscurity" methodology. I'm quite disappointed by

[FD] [KIS-2016-02] Magento <= 1.9.2.2 (RSS Feed) Information Disclosure Vulnerability

2016-02-23 Thread Egidio Romano
re in RSS feed) have been accepted and you will be receiving a bounty of USD $9,000." [02/02/2016] - CVE number assigned [12/02/2016] - Bug bounty received [23/02/2016] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assign

[FD] [KIS-2016-01] CakePHP <= 3.2.0 "_method" CSRF Protection Bypass Vulnerability

2016-01-15 Thread Egidio Romano
n updated [01/12/2015] - CVE number requested [01/12/2015] - CVE number assigned [12/01/2016] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2015-8379 to this vulnerability. [-] Credits: Vulnerability discove

[FD] [KIS-2015-10] Piwik <= 2.14.3 (DisplayTopKeywords) PHP Object Injection Vulnerability

2015-11-04 Thread Egidio Romano
-2015-7816 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2015-10 ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] [KIS-2015-09] Piwik <= 2.14.3 (viewDataTable) Autoloaded File Inclusion Vulnerability

2015-11-04 Thread Egidio Romano
angelog/piwik-2-15-0 [04/11/2015] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2015-7815 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano.

[FD] [KIS-2015-08] ATutor <= 2.2 (edit_marks.php) PHP Code Injection Vulnerability

2015-11-04 Thread Egidio Romano
er requested [05/10/2015] - CVE number assigned [06/10/2015] - After one year still no official solution available [04/11/2015] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2015-7712 to this vulnerability. [-]

[FD] [KIS-2015-07] ATutor <= 2.2 (popuphelp.php) Reflected Cross-Site Scripting Vulnerability

2015-11-04 Thread Egidio Romano
e.mitre.org) has assigned the name CVE-2015-7711 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2015-07 ___ Sent through the Full Disclosure mailing list https://nma

[FD] [KIS-2015-06] ATutor <= 2.2 (confirm.php) Session Variable Overloading Vulnerability

2015-11-04 Thread Egidio Romano
er requested [05/10/2015] - CVE number assigned [04/11/2015] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-9753 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisor

[FD] [KIS-2015-05] ATutor <= 2.2 (Custom Course Icon) Unrestricted File Upload Vulnerability

2015-11-04 Thread Egidio Romano
-9752 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2015-05 ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archive

[FD] [KIS-2015-04] Magento <= 1.9.2 (catalogProductCreate) Autoloaded File Inclusion Vulnerability

2015-09-11 Thread Egidio Romano
E number assigned [11/09/2015] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2015-6497 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano of Minded Security. [-] Original Advisory:

[FD] [KIS-2015-03] Concrete5 <= 5.7.4 (Access.php) SQL Injection Vulnerability

2015-06-11 Thread Egidio Romano
4] - CVE number requested [11/06/2014] - Publication of this advisory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has not assigned a name to this vulnerability yet. [-] Credits: Vulnerability discovered by Egidio Romano of Minded Security. [-] O

[FD] [KIS-2015-02] Concrete5 <= 5.7.3.1 Multiple Reflected Cross-Site Scripting Vulnerabilities

2015-06-11 Thread Egidio Romano
Concrete5 <= 5.7.3.1 Multiple Reflected Cross-Site Scripting Vulnerabilities [-] Software Link: https://www.concrete5.org/ [-] Affected Vers

[FD] [KIS-2015-01] Concrete5 <= 5.7.3.1 (sendmail) Remote Code Execution Vulnerability

2015-06-11 Thread Egidio Romano
isory [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has not assigned a name to this vulnerability yet. [-] Credits: Vulnerability discovered by Egidio Romano of Minded Security. [-] Original Advisory: http://karmainsecurity.com/KIS-2015-01 [-] Other Refer

[FD] [KIS-2014-19] Symantec Web Gateway <= 5.2.1 (restore.php) OS Command Injection Vulnerability

2014-12-31 Thread Egidio Romano
ssigned the name CVE-2014-7285 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano, Secunia Research. [-] Original Advisory: http://karmainsecurity.com/KIS-2014-19 ___ Sent through the Full Disclosure mailing list http

[FD] [KIS-2014-18] Mantis Bug Tracker <= 1.2.17 (ImportXml.php) PHP Code Injection Vulnerability

2014-12-31 Thread Egidio Romano
[-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-7146 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2014-18 __

[FD] [KIS-2014-17] GetSimple CMS <= 3.3.4 (api.php) XML External Entity Vulnerability

2014-12-31 Thread Egidio Romano
(cve.mitre.org) has assigned the name CVE-2014-8790 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2014-17 ___ Sent through the Full Disclosure mailing list http:

[FD] [KIS-2014-16] Osclass <= 3.4.2 (contact.php) Unrestricted File Upload Vulnerability

2014-12-31 Thread Egidio Romano
[31/12/2014] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-8085 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/K

[FD] [KIS-2014-15] Osclass <= 3.4.2 (ajax.php) Local File Inclusion Vulnerability

2014-12-31 Thread Egidio Romano
pdate to version 3.4.3 or later. [-] Disclosure Timeline: [29/09/2014] - Vendor notified [29/09/2014] - Vendor response [09/10/2014] - Version 3.4.3 released: http://blog.osclass.org/2014/10/09/osclass-3-4-3 [09/10/2014] - CVE number requested [11/10/2014] - CVE number assigned [31/12/2014] - Pub

[FD] [KIS-2014-14] Osclass <= 3.4.2 (Search::setJsonAlert) SQL Injection Vulnerability

2014-12-31 Thread Egidio Romano
3 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2014-14 ___ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure W

[FD] [KIS-2014-13] Tuleap <= 7.6-4 (register.php) PHP Object Injection Vulnerability

2014-11-28 Thread Egidio Romano
[11/10/2014] - CVE number requested [13/11/2014] - CVE number assigned [13/11/2014] - Version 7.7 released [27/11/2014] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-8791 to this vulnerability. [-] Credits

[FD] [KIS-2014-12] TestLink <= 1.9.12 (database.class.php) Path Disclosure Weakness

2014-10-23 Thread Egidio Romano
rg) has assigned the name CVE-2014-8082 to this weakness. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2014-12 ___ Sent through the Full Disclosure mailing list http://nmap.org/

[FD] [KIS-2014-11] TestLink <= 1.9.12 (execSetResults.php) PHP Object Injection Vulnerability

2014-10-23 Thread Egidio Romano
/2014] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-8081 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karma

[FD] [KIS-2014-10] X2Engine <= 4.1.7 (FileUploadsFilter.php) Unrestricted File Upload Vulnerability

2014-09-23 Thread Egidio Romano
mon Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-5298 to this vulnerability. [-] Credits: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2014-10 ___ Sent through the F

[FD] [KIS-2014-09] X2Engine <= 4.1.7 (SiteController.php) PHP Object Injection Vulnerability

2014-09-23 Thread Egidio Romano
http://x2community.com/?showtopic=1804 [01/08/2014] - CVE number requested [16/08/2014] - CVE number assigned [05/09/2014] - Version 4.2 released [23/09/2014] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-52

[FD] [KIS-2014-08] OpenCart <= 1.5.6.4 (cart.php) PHP Object Injection Vulnerability

2014-07-14 Thread Egidio Romano
Vendor replied there's no need to alert its users because the vulnerability is very weak [14/07/2014] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-3990 to this vulnerability. [-]

Re: [FD] [KIS-2014-06] Dotclear <= 2.6.2 (Media Manager) Unrestricted File Upload Vulnerability

2014-05-22 Thread Egidio Romano
ty to publish as well the the ability to manage your own > media. > > Feel free to edit as you would like and make a pull request! > > https://gist.github.com/brandonprry/efc0765c342a44a0dedb > > > On Wed, Ma

[FD] [KIS-2014-07] Dotclear <= 2.6.2 (categories.php) SQL Injection Vulnerability

2014-05-21 Thread Egidio Romano
r requested [19/05/2014] - CVE number assigned [21/05/2014] - Public disclosure [-] CVE Reference: The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2014-3783 to this vulnerability. [-] Credits: Vulnerability disc

[FD] [KIS-2014-06] Dotclear <= 2.6.2 (Media Manager) Unrestricted File Upload Vulnerability

2014-05-21 Thread Egidio Romano
its: Vulnerability discovered by Egidio Romano. [-] Original Advisory: http://karmainsecurity.com/KIS-2014-06 ___ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://secli

  1   2   >