[FD] Google AOSP Email App HTML Injection

2015-11-17 Thread Cláudio André
:* 16 November 2015 *Advisory URL:* https://labs.integrity.pt/advisories/google-aosp-email-app-html-injection/ *Credits: *Discovery by Cláudio André 2. Vulnerability Summary A remote attacker is able to send a crafted email with a payload that redirects the user to a target url as soon as he opens

[FD] Good for Enterprise Android HTML Injection (CVE-2014-4925)

2015-01-08 Thread Cláudio André
/) Products: Good for Enterprise Android (possibly others) Advisory Release Date: 8 January 2015 Advisory URL: http://labs.integrity.pt/advisories/cve-2014-4925/ Credits: Discovery and PoC by Cláudio André 2. Vulnerability Summary A remote attacker is able to send a crafted email with a payload that