Carl's Blog

  • About
  • Archive

February 2017

Advisory

Security Advisory – Open URL Redirect in Koozali SME Server

Product: Koozali SME Server Vendor: Koozali Foundation/Open Source Software Version: 8.x, 9.x, 10.x Category: Open URL Redirect Vendor Notified: 2017-01-11 Patched: 2017-01-23 Disclosed: 2017-02-02 Researcher(s): Carl Pearson CVE: CVE-2017-1000027 Summary An open URL redirect vulnerability exists in the user login function of Koozali SME Server. The server fails to validate Read more

By cpearson, 10 yearsFebruary 2, 2017 ago
Recent Posts
  • CVE-2025-11380 – Everest Backup – Unauthenticated Backup access
  • CVE-2021-3429 cloud-init exposed credentials under certain conditions
  • Google Docs clipboard leak
  • Account Hijacking – Integria IMS
  • Security Advisory – Multiple Cross Site Scripting Vulnerabilities in EspoCRM
Recent Comments
    Hestia | Developed by ThemeIsle