2-Factor Authentication Bypass Flaw Reported in cPanel and WHM Software

Connect
Hello! I'm Steve, an independent security researcher, and analyst from Scotland, UK.

I've had an avid interest in Computers, Technology and Security since my early teens. 20 years on, and, it's a whole lot more complicated...

I've assisted Governments, Individuals and Organizations throughout the world. Including; US DOJ, NHS UK, GOV UK.

I'll often reblog infosec-related articles that I find interesting. On the RiSec website, You'll also find a variety of write-ups, tutorials and much more!
Connect

cPanel, a provider of popular administrative tools to manage web hosting, has patched a security vulnerability that could have allowed

Read more

SyncBreeze 10.0.28 – (password) Remote Buffer Overflow Exploit

CVE: N/A Platform: Multiple / Win / WebAPPS Date: 25-11-2020

Read more

osCommerce 2.3.4.1 – ‘title’ Persistent Cross-Site Scripting

CVE: N/A Platform: PHP Date: 2020-11-25

Read more

nopCommerce Store 4.30 – ‘name’ Stored Cross-Site Scripting

Connect
Hello! I'm Steve, an independent security researcher, and analyst from Scotland, UK.

I've had an avid interest in Computers, Technology and Security since my early teens. 20 years on, and, it's a whole lot more complicated...

I've assisted Governments, Individuals and Organizations throughout the world. Including; US DOJ, NHS UK, GOV UK.

I'll often reblog infosec-related articles that I find interesting. On the RiSec website, You'll also find a variety of write-ups, tutorials and much more!
Connect

CVE: N/A Platform: Multiple Date: 2020-11-24

Read more

Apache OpenMeetings 5.0.0 – ‘hostname’ Denial of Service

Connect
Hello! I'm Steve, an independent security researcher, and analyst from Scotland, UK.

I've had an avid interest in Computers, Technology and Security since my early teens. 20 years on, and, it's a whole lot more complicated...

I've assisted Governments, Individuals and Organizations throughout the world. Including; US DOJ, NHS UK, GOV UK.

I'll often reblog infosec-related articles that I find interesting. On the RiSec website, You'll also find a variety of write-ups, tutorials and much more!
Connect

CVE: 2020-13951 Platform: Multiple Date: 2020-11-24

Read more

ZeroShell 3.9.0 – ‘cgi-bin/kerbynet’ Remote Root Command Injection

Connect
Hello! I'm Steve, an independent security researcher, and analyst from Scotland, UK.

I've had an avid interest in Computers, Technology and Security since my early teens. 20 years on, and, it's a whole lot more complicated...

I've assisted Governments, Individuals and Organizations throughout the world. Including; US DOJ, NHS UK, GOV UK.

I'll often reblog infosec-related articles that I find interesting. On the RiSec website, You'll also find a variety of write-ups, tutorials and much more!
Connect

CVE: 2019-12725 Platform: LINUX Date: 2020-11-24

Read more

Netsuveillancewebcookie Web interface password change

Connect
Hello! I'm Steve, an independent security researcher, and analyst from Scotland, UK.

I've had an avid interest in Computers, Technology and Security since my early teens. 20 years on, and, it's a whole lot more complicated...

I've assisted Governments, Individuals and Organizations throughout the world. Including; US DOJ, NHS UK, GOV UK.

I'll often reblog infosec-related articles that I find interesting. On the RiSec website, You'll also find a variety of write-ups, tutorials and much more!
Connect
Read more

WonderCMS 3.1.3 – ‘content’ Persistent Cross-Site Scripting

Connect
Hello! I'm Steve, an independent security researcher, and analyst from Scotland, UK.

I've had an avid interest in Computers, Technology and Security since my early teens. 20 years on, and, it's a whole lot more complicated...

I've assisted Governments, Individuals and Organizations throughout the world. Including; US DOJ, NHS UK, GOV UK.

I'll often reblog infosec-related articles that I find interesting. On the RiSec website, You'll also find a variety of write-ups, tutorials and much more!
Connect
Read more

Boxoft Convert Master 1.3.0 – ‘wav’ SEH Local Exploit

Read more

Free MP3 CD Ripper 2.8 – Multiple File Buffer Overflow (Metasploit)

Read more