mySCADA myPRO 7 – Hard-Coded Credentials

#Exploit Title: mySCADA myPRO 7 – Hardcoded FTP Username and Password #Date: 2018-05-19 #Exploit Author: Emre ÖVÜNÇ #Vendor Homepage: https://www.myscada.org/mypro/ #Software Link: https://www.myscada.org/download/ #Version: v7 #Tested on: Linux, Windows # I. Problem Description #In the […]

RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross-Site Flashing / DOM Cross-Site Scriptin

SEC Consult Vulnerability Lab Security Advisory < 20180516-0 > ======================================================================= title: XXE & XSS vulnerabilities product: RSA Authentication Manager vulnerable version: 8.2.1.4.0-build1394922, < 8.3 P1 fixed version: 8.3 P1 and later CVE number: CVE-2018-1247 impact: […]

WordPress Plugin Metronet Tag Manager 1.2.7 – Cross-Site Request Forgery

<!– Details ================ Software: Metronet Tag Manager Version: 1.2.7 Homepage: https://wordpress.org/plugins/metronet-tag-manager/ Advisory report: https://advisories.dxw.com/advisories/csrf-metronet-tag-manager/ CVE: Awaiting assignment CVSS: 5.8 (Medium; AV:N/AC:M/Au:N/C:P/I:P/A:N) Description ================ CSRF in Metronet Tag Manager allows anybody to do almost anything an […]