[FD] Responsive Filemanager 9.8.1 Reflected Cross Site Scripting (XSS)

2018-10-09 Thread yavuz atlas
://vulmon.com/vulnerabilitydetails?qid=CVE-2018-18062 V. CREDIT - Yavuz Atlas of Biznet Bilisim http://www.biznet.com.tr/biznet-guvenlik-duyurulari VI. DESCRIPTION - Responsive Filemanager version 9.8.1 is vulnerable to cross-site scripting. A remote

[FD] Responsive Filemanager 9.8.1 Authentication Bypass

2018-10-09 Thread yavuz atlas
/vulnerabilitydetails?qid=CVE-2018-18061 V. CREDIT - Yavuz Atlas of Biznet Bilisim http://www.biznet.com.tr/biznet-guvenlik-duyurulari VI. DESCRIPTION - Responsive Filemanager version 9.8.1 allows remote attackers to bypass authentication. The vulnerability

[FD] Samsung Web Viewer for Samsung DVR Reflected Cross Site Scripting (XSS) CVE-2018-11689

2018-06-14 Thread yavuz atlas
- Yavuz Atlas - Biznet Bilisim http://www.biznet.com.tr/biznet-guvenlik-duyurulari V. DESCRIPTION - Samsung Web Viewer for Samsung DVR devices (Samsung Smart Viewer) is vulnerable to cross-site scripting. The vulnerability allows remote attackers to inject

[FD] Gridbox extension for Joomla! <= 2.4.0 Reflected Cross Site Scripting (XSS)

2018-06-08 Thread yavuz atlas
DIT ----- Yavuz Atlas of Biznet Bilisim http://www.biznet.com.tr/biznet-guvenlik-duyurulari VII. DESCRIPTION - Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting. A remote attacker could exploit t

[FD] Ignite Realtime Openfire Version 3.7.1 Reflected Cross Site Scripting (CVE-2018-11688)

2018-06-05 Thread yavuz atlas
II. CREDIT ----- Yavuz Atlas - @yavuzatlas_ http://www.biznet.com.tr/biznet-guvenlik-duyurulari ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] Ruckus (Brocade) ICX7450-48 Reflected Cross Site Scripting

2018-05-28 Thread Yavuz Atlas
Connection: close Upgrade-Insecure-Requests: 1 Cache-Control: max-age=0 Response: Object Not Found Object Not Found The requested URL '/alert(1)' was not found on the asdf_ICX. Return to last page VI. CREDIT ----- Yavuz Atlas - @yavuzatlas_ http://www.biznet.com.