RCE Security
  • Home
  • About
  • Contact Us
  • Services
  • Research
Select Page

HP Intelligent Management Center v5.1: Bypassing javax.faces.ViewState CSRF Protection

by Julien Ahrens | Tuesday, March 5, 2013 | Advisory, Exploit

Have you read my last advisory about the HP Intelligent Management Center v5.1 E0202 topoContent.jsf Non-Persistent Cross-Site Scripting Vulnerability ? You should do! Taken by itself it’s not even an interesting vulnerability. But! You’re able...

Photodex ProShow Producer Vulnerability #5: Insecure Library Loading

by Julien Ahrens | Saturday, February 23, 2013 | Advisory

This is a sweet vulnerability, because all ProShow installations on all Microsoft Windows operating systems up to Windows 8 are exploitable! Let’s have a look at the details and how to exploit it to get a remote shell 🙂 When launching the application, it loads...

Photodex ProShow Producer Vulnerability #4: SEH-Based Buffer Overflow (.PXT)

by Julien Ahrens | Monday, February 18, 2013 | Advisory

And here’s the next one. A SEH-based Buffer Overflow – exploitable on all 32bit windows systems out there :-). The application does not validate (again, but in a different module) the length of the title value while loading the contents of a ProShow...

Photodex ProShow Producer Vulnerability #3: Memory Corruption / Code Execution

by Julien Ahrens | Thursday, February 14, 2013 | Advisory

Hello readers, as predicted 🙂 … here’s the next vulnerability in the ProShow Producer application by Photodex. This time, it’s a dangerous memory corruption which could lead to “remote” code execution using a crafted .pxs file. An...

Marc O’Polo and United Cinemas International Fix XSS Security Flaws

by Julien Ahrens | Wednesday, January 9, 2013 | Advisory

Another day, some new XSS flaws. At first the big fashion label Marc O’Polo fixed a major Cross-Site Scripting issue in their online shop system. Good news, because a malicious attacker was able to use this security hole to hijack (and steal) every account...

Bavarian Social Democratic Party Fixes Several Security Flaws

by Julien Ahrens | Tuesday, November 27, 2012 | Advisory

In early November, I found several Cross-Site Scripting vulnerabilites on the official website of the bavarian social democrats (also called “SPD” – which is the oldest political party in Germany) and immediately notified the official press office...
« Older Entries
Next Entries »
  • X
  • RSS

Designed by Elegant Themes | Powered by WordPress