[FD] CVE-2014-2081 - VTLS Virtua InfoStation.cgi SQLi.

2014-08-25 Thread J. Tozo
=[Alligator Security Team - Security Advisory] - VTLS Virtua InfoStation.cgi SQLi - CVE-2014-2081 - Author: José Tozo < juniorbsd () gmail com > =[Table of Contents]== 1. Background 2. Detailed descr

[FD] Graylog2-Web LDAP Injection - CVE-2014-9217

2014-12-22 Thread J. Tozo
=[Alligator Security Team - Security Advisory] - Graylog2-Web LDAP Injection - CVE-2014-9217 - Author: José Tozo < juniorbsd () gmail com > =[Table of Contents]== 1. Background 2. Detailed description 3. Other contexts & solutions 4. Timeline 5. Refer

[FD] CVE-2015-1169 - CAS Server 3.5.2 allows remote attackers to bypass LDAP authentication via crafted wildcards.

2015-01-21 Thread J. Tozo
=[Alligator Security Team - Security Advisory] CVE-2015-1169 - CAS Server 3.5.2 allows remote attackers to bypass LDAP authentication via crafted wildcards. Reporter: José Tozo < juniorbsd () gmail com > =[Table of Contents]== 1. Background 2