High-Tech Bridge Security Advisories

Vulnerabilities Disclosure Policy

SQL injection vulnerability in e107

Vendor Notification: 03 September 2010
Public Disclosure: 17 September 2010
Vulnerable Version: 0.7.23 and Probably Prior Versions
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Low

SQL injection vulnerability in e107

Vendor Notification: 03 September 2010
Public Disclosure: 17 September 2010
Vulnerable Version: 0.7.23 and Probably Prior Versions
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Low

XSS vulnerability in AContent search

Vendor Notification: 01 September 2010
Public Disclosure: 15 September 2010
Vulnerable Version: 1.0
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium

XSS vulnerability in Atutor edit content folder

Vendor Notification: 01 September 2010
Public Disclosure: 15 September 2010
Vulnerable Version: 1.0
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium

XSS vulnerability in AContent

Vendor Notification: 01 September 2010
Public Disclosure: 15 September 2010
Vulnerable Version: 1.0
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium

XSS vulnerability in AContent

Vendor Notification: 01 September 2010
Public Disclosure: 15 September 2010
Vulnerable Version: 1.0
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium

XSS vulnerability in ATutor

Vendor Notification: 01 September 2010
Public Disclosure: 15 September 2010
Vulnerable Version: 1.0
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Low

XSS vulnerability in AChecker

Vendor Notification: 01 September 2010
Public Disclosure: 15 September 2010
Vulnerable Version: 1.0
Status: Fixed by Vendor
Risk level: Medium

XSS (cross site scripting) vulnerability in Serendipity

Vendor Notification: 26 August 2010
Public Disclosure: 09 September 2010
Vulnerable Version: 1.5.3 and probably prior versions
Status: Fixed by Vendor
Risk level: Medium

XSS vulnerability in SantaFox search module

Vendor Notification: 23 August 2010
Public Disclosure: 06 September 2010
Vulnerable Version: 2.02 and Probably Prior Versions
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Medium

Prev   1   2  3  4  5  6  7  8  9 Next