Real Name | Nate Power |
---|---|
Email address | private |
Website | www.securitypentest.com |
First Active | 2011-01-01 |
Last Active | 2014-08-03 |
The Microsoft Exchange Client Access Server (CAS) that services Autodiscover has been found vulnerable to an information disclosure. It has been discovered that a standard domain user without Exchange permissions can enumerate Autodiscover configuration files of Exchange users by an XML SOAP parameter injection.
54c985d67107ade894f094c2b0fe43f071b3e549fb3bf44c8d221541460ae91e
The Client Access Server (CAS) that services Autodiscover and Outlook Web App (OWA) has been found to be vulnerable to time-based authentication attacks. It has been discovered that when sending authentication requests to the CAS, behavior in the timing of the responses can be used to verify Active Directory (AD) realms and usernames within those realms. Authentication timing issues have been found in specific IIS file paths and OWA form-based authentication. This issue can allow an attacker to confirm the existence of a specific username in the directory, and will make other attacks such as password guessing or social engineering attacks more successful.
061b94a5edc404d05361b21ffb528c06f80aa1cef15fbbc558442730005bf285
Multiple issues have been discovered that makes it possible to disclose internal IP addresses of remote Microsoft Exchange environments.
1583d0211f9142e47c610ac0fa845c95f421e39d1782f40c8b7bdb1923355789
Facebook.com suffers from a bypass vulnerability where an executable can be attached to a message if a spaced is added to the name.
d50f0c387bdb7f361f67403ec07249d408f5a19eed5358e240b208741277268f
Multi-Tech Systems MultiModem iSMS suffers from multiple cross site scripting vulnerabilities. MultiModem iSMS Web Management Interface versions 1.47 and below are affected.
857d2a189b2061187d191edcd0432fd735cd894adbea85bee5dfbb848ba0063c
Trustwave WebDefend suffers from a static database password vulnerability. It was discovered in various DLLs and EXEs and affects WebDefend Enterprise Manager Appliance / Console software versions 5.0 and 4.0.
af8e8db72fb21529ddd405451250cf64c1245de881c6b67c33191743d4d5a7f7
The Unidesk Management Console versions 1.3 and below suffer from a direct access vulnerability that allows an attacker direct access to administrative resources.
0d22cc882b3d6c110e94623b1274d806e3e68239274da8ea4c92fd017f31ea87
PayPal's send money feature suffered from a cross site scripting vulnerability.
3de760a1d3613532edb3bcb89657f899c49fc5641c61f9d37414668b5825366f