Francesco Ongaro
  • About
  • Research
  • Advisories
  • Conferences
  • Contact

Advisories

May 28, 1985

  • Veeam Backup & Replication Local Privilege Escalation Vulnerability
  • Nginx, Varnish, Cherokee, thttpd, mini-httpd, WEBrick, Orion, AOLserver, Yaws and Boa log escape sequence injection
  • Jetty 6.x and 7.x Multiple Vulnerabilities
  • Vtiger CRM 5.0.4 Multiple Vulnerabilities
  • SugarCRM 5.2.0e Remote Code Execution
  • FormMail 1.92 Multiple Vulnerabilities
  • Zabbix 1.6.2 Frontend Multiple Vulnerabilities
  • Remote Command Execution in Moodle
  • Collabtive 0.4.8 Multiple Vulnerabilities
  • Mantis Bug Tracker 1.1.1 Multiple Vulnerabilities
  • WiKID wClient-PHP <= 3.0-2 Multiple XSS Vulnerabilities
  • Cacti 0.8.7a Multiple Vulnerabilities
  • GreenSQL, a MySQL firewall, bypassed
  • Original Photo Gallery Remote Command Execution
  • Firefox <= 2.0.0.3 DOM Keylogger (bypass same-origin policy)
  • Shadowpage vulnerability: the page that doesn’t exists (Multiple browsers affected)
  • PHP import_request_variables() arbitrary variable overwrite
  • Php Nuke wild POST XSS
  • Milkeyway Captive Portal Multiple Vulnerabilities
  • PmWiki remote file inclusion exploit
  • PHP5 Globals Vulnerability
  • PmWiki Multiple Vulnerabilities
  • PHP iCalendar Remote File Inclusion
  • PHP Web Statistik Multiple Vulnerabilities
  • FreeWebStat Multiple XSS Vulnerabilities
  • Multiple Vulnerabilities in WebCalendar

Copyright © Francesco Ongaro 2025 - Press Review - Privacy Policy - ToS