Siemens Spectrum Power Command Injection

During my time at Applied Risk I discovered a Command Injection vulnerability in Siemens Spectrum with the help of Rutger Hendriks. Siemens Spectrum is a control system for power grids.

- Siemens Spectrum, Power, Command Injection, advisory


Broken TLS certificate pinning in VTech DigiGo Kid Connect app

Advisory for broken TLS certificate pinning in VTech DigiGo Kid Connect app that allows for a Man-in-the-Middle attack on the chat functionality.

- advisory, VTech DigiGo, TLS, pinning


Multiple vulnerabilities in VTech DigiGo allow browser overlay attack

Advisory for vulnerability that allows attackers to perform a persistent overlay attack on the browser app.

- advisory, VTech DigiGo, browser, XSS


Broken TLS certificate validation in VTech DigiGo browser

Advisory for broken TLS certificate validation in the VTech DigiGo browser.

- advisory, VTech DigiGo, TLS


Reflected Cross-Site Scripting in CM4ALL

Advisory for Reflected Cross-Site Scripting in CM4ALL.

- advisory, XSS, CM4ALL


Buffer over-read vulnerability in Virtuozzo Power Panel (VZPP) and Automator

Advisory for buffer over-read vulnerability in Virtuozzo Power Panel (VZPP) and Automator.

- advisory, buffer over-read, VZPP


Stored Cross-Site Scripting in Gallery - Image Gallery WordPress Plugin

Advisory for Stored Cross-Site Scripting in Gallery - Image Gallery (Wordpress plugin).

- advisory, summer of pwnage, wordpress, php


Persistent Cross-Site Scripting in Instagram Feed plugin via CSRF

Advisory for Persistent Cross-Site Scripting in Instagram Feed plugin via CSRF (Wordpress plugin).

- advisory, summer of pwnage, wordpress, php


Weak validation of Amazon SNS push messages in W3 Total Cache WordPress Plugin

Advisory for Weak validation of Amazon SNS push messages in W3 Total Cache (Wordpress plugin).

- advisory, summer of pwnage, wordpress, php


Persistent Cross-Site Scripting in WP Google Maps Plugin via CSRF

Advisory for Persistent Cross-Site Scripting in WP Google Maps Plugin via CSRF (Wordpress plugin).

- advisory, summer of pwnage, wordpress, php


Information disclosure race condition in W3 Total Cache WordPress Plugin

Advisory for Information disclosure race condition in W3 Total Cache (Wordpress plugin).

- advisory, summer of pwnage, wordpress, php


Reflected Cross-Site Scripting vulnerability in MailPoet Newsletters plugin

Advisory for Reflected Cross-Site Scripting vulnerability in MailPoet Newsletters plugin (Wordpress plugin).

- advisory, summer of pwnage, wordpress, php


Multiple vulnerabilities in All In One WP Security & Firewall plugin login CAPTCHA

Advisory for Multiple vulnerabilities in All In One WP Security & Firewall plugin login CAPTCHA (Wordpress plugin).

- advisory, summer of pwnage, wordpress, php


Reflected Cross-Site Scripting vulnerability in W3 Total Cache plugin

Advisory for Reflected Cross-Site Scripting vulnerability in W3 Total Cache plugin (Wordpress plugin).

- advisory, summer of pwnage, wordpress, php


Cross-Site Request Forgery in WordPress Press This function allows DoS

Advisory for DoS via Cross-Site Request Forgery in WordPress Press This function.

- advisory, summer of pwnage, wordpress, php


Persistent Cross-Site Scripting in Woocommerce WordPress plugin

Advisory for Persistent Cross-Site Scripting in Woocommerce WordPress plugin (Wordpress plugin).

- advisory, summer of pwnage, wordpress, php


Authorization bypass in InfiniteWP Admin Panel

Advisory for authorization bypass in InfiniteWP Admin Panel (Wordpress plugin).

- advisory, summer of pwnage, wordpress, php


Command injection in InfiniteWP Admin Panel

Advisory for Command injection in InfiniteWP Admin Panel (Wordpress plugin).

- advisory, summer of pwnage, wordpress, php


Hackerone DoS by PNG compression

Advisory for Denial of Service vulnerability in HackerOne via PNG image upload.

- advisory, DoS, upload, parsing


Glype proxy local address filter bypass

Advisory for bypassing local address filters in the Glype web-based proxy that allows attacking the internal network of the proxy host.

- advisory, ip filter, php


Glype proxy cookie jar path traversal allows code execution

Advisory for path traversal vulnerability in the Glype web-based proxy that allows an attacker to run arbitrary PHP code on the server or remove critical files from the filesystem.

- advisory, proxy, php, path traversal, code execution, web security


Hackerone DoS by GIF resize flooding

Advisory for Denial of Service vulnerability in HackerOne via GIF image upload.

- advisory, DoS, upload, parsing


Hackerone DoS by JPG pixel flood

Advisory for Denial of Service vulnerability in HackerOne via JPG image upload.

- advisory, DoS, upload, parsing