IBM X-Force RazorCMS Advisory
To read my Original Advisory:
Ivano Binetti's RazorCMS Original Advisory
In this blog are reported some of my observations about information security. I hope they can be useful for you.
0 commenti Filed Under: IBM X-Force
0 commenti Filed Under: IBM X-Force
0 commenti Filed Under: IBM X-Force
0 commenti Filed Under: IBM X-Force
Yesterday IBM X-Force published my Advisory regarding a new CSRF vulneability that I've found in SyndeoCMS <= 3.0
http://ivanobinetti.blogspot.com/2012/02/syndeocms-30-csrf-vulnerability.html
This vulnerability allows an attacker to change administrator password and gain access to the system.
IBM classified this vulnerability as "Highly Exploitable".
For more details about IBM X-Force publication:
http://xforce.iss.net/xforce/xfdb/73319
0 commenti Filed Under: IBM X-Force
Few days ago I discovered a new CSRF vulnerability (http://ivanobinetti.blogspot.com/2012/02/plumecms-124-csrf-0day-vulnerability.html which affects all versions - included latest (1.2.4) - of Pluse CMS.
Today IBM X-Force published my Advisory and classified the "Exploitability:" of this vulnerability as "High".
Fore more details:
http://xforce.iss.net/xforce/xfdb/73317
0 commenti Filed Under: IBM X-Force
Today IBM X-Force published two of my advisories related to vulnerabilities discoverd into D-Link DSL-2640B ADSL Router / Access Point.
If you would like to read more about them:
http://xforce.iss.net/xforce/xfdb/73316
http://xforce.iss.net/xforce/xfdb/73379
0 commenti Filed Under: 0day Vulnerabilities, hardware, IBM X-Force, Web Vulnerabilities
Today IBM X-Force has published my Advisory related to a security flaw which I've discovered in Cisco Linksys WAG54GS router which allow an attacker to change administrator password.
For more informations:
http://xforce.iss.net/xforce/xfdb/73345
0 commenti Filed Under: 0day Vulnerabilities, hardware, IBM X-Force, Web Vulnerabilities
IBM X-Force (http://xforce.iss.net/) published my new "0day" vulnerability regarding Multiple Vulnerabilities discovered in ForkCMS 3.2.6 and lower:
http://xforce.iss.net/xforce/xfdb/73394
0 commenti Filed Under: 0day Vulnerabilities, IBM X-Force, Web Vulnerabilities