Cellebrite EPR Decryption Hardcoded AES Key Material

The Cellebrite UFED Physical device relies on key material hardcoded within both the executable code supporting the decryption process and within the encrypted files themselves by using a key enveloping technique. The recovered key material is the same for every device running the same version of the software and does not appear to be changed […]

openSIS 7.4 Incorrect Access Control

openSIS versions 7.4 and below suffer from an access bypass vulnerability.

openSIS 7.4 Local File Inclusion

openSIS versions 7.4 and below suffer from a local file inclusion vulnerability.

openSIS 7.4 SQL Injection

openSIS versions 7.4 and below suffer from multiple remote SQL injection vulnerabilities.

[webapps] Online Shopping Portal 3.1 – Authentication Bypass

Online Shopping Portal 3.1 – Authentication Bypass

[webapps] PHP-Fusion 9.03.60 – PHP Object Injection

PHP-Fusion 9.03.60 – PHP Object Injection

[webapps] e-learning Php Script 0.1.0 – 'search' SQL Injection

e-learning Php Script 0.1.0 – ‘search’ SQL Injection

[local] RM Downloader 2.50.60 2006.06.23 – 'Load' Local Buffer Overflow (EggHunter) (SEH) (PoC)

RM Downloader 2.50.60 2006.06.23 – ‘Load’ Local Buffer Overflow (EggHunter) (SEH) (PoC)