Carl's Blog

  • About
  • Archive

February 2017

Advisory

Security Advisory – Open URL Redirect in Koozali SME Server

Product: Koozali SME Server Vendor: Koozali Foundation/Open Source Software Version: 8.x, 9.x, 10.x Category: Open URL Redirect Vendor Notified: 2017-01-11 Patched: 2017-01-23 Disclosed: 2017-02-02 Researcher(s): Carl Pearson CVE: CVE-2017-1000027 Summary An open URL redirect vulnerability exists in the user login function of Koozali SME Server. The server fails to validate Read more

By cpearson, 9 yearsFebruary 2, 2017 ago
Recent Posts
  • CVE-2021-3429 cloud-init exposed credentials under certain conditions
  • Google Docs clipboard leak
  • Account Hijacking – Integria IMS
  • Security Advisory – Multiple Cross Site Scripting Vulnerabilities in EspoCRM
  • Security Advisory – Cross Site Request Forgery in Chyrp Lite
Recent Comments
    Hestia | Developed by ThemeIsle