Services Vulnerabilities Exploits Publications News Blog About DSecRG


RSS RSS

20.01.2012 [DSECRG-12-011] SAP NetWeaver Business Communication Broker - multiple XSS

20.01.2012 [DSECRG-12-010] SAP TesContainerAdmin service - stored XSS

20.01.2012 [DSECRG-12-009] SAP NetWeaver PFL_CHECK_OS_FILE_EXISTENCE - missing authorization check and SMB Relay vulnerability

20.01.2012 [DSECRG-12-008] SAP NetWeaver RWB - unauthorized acñess

20.01.2012 [DSECRG-12-007] Tecomat PLC - Default passwords

20.01.2012 [DSECRG-12-006] OPC Systems.NET FlexGrid 7.1 ActiveX - Buffer Overflow

20.01.2012 [DSECRG-12-005] wellintech KingSCADA 3.0 - Insecure password encryption

20.01.2012 [DSECRG-12-004] WAGO PLC 750 - CSRF password change [0-day]

20.01.2012 [DSECRG-12-003] WAGO PLC 750 - information disclosure [0-day]

20.01.2012 [DSECRG-12-002] WAGO PLC 750 - unauthorized firmware download [0-day]

20.01.2012 [DSECRG-12-001] WAGO PLC - default passwords [0-day]

18.11.2011 [DSECRG-11-042] VMware Update Manager - Directory Traversal

14.11.2011 [DSECRG-11-041] SAP NetWeaver - Authentication bypass (Verb Tampering)

14.11.2011 [DSECRG-11-040] SAP NetWeaver SPML - XML CSRF user creation

14.11.2011 [DSECRG-11-039] SAP NetWeaver TH_GREP module - Code injection vulnerability (NEW)

14.11.2011 [DSECRG-11-037] SAP BW Doc - Multiple XSS

14.11.2011 [DSECRG-11-038] SAP RSTXSCRP report - smb relay vulnerability

14.11.2011 [DSECRG-11-036] SAP NetWaver Virus Scan Interface - multiple XSS

14.11.2011 [DSECRG-11-035] SAP GUI BAPI Explorer- Unauthorized execution of function

14.11.2011 [DSECRG-11-034] SAP NetWeaver J2EE MeSync – information disclose

1 2 3 4 5 6 7 8



Upcoming Advisories
The following is a list most important vulnerabilities discovered by DSecRG researchers that are yet to be published.
The affected vendor has been contacted on the specified date and work on a patch for vulnerability.


[DSECRG-00263] SAP 20.01.2012
[DSECRG-00262] SAP 20.01.2012
[DSECRG-00261] SAP 20.01.2012
[DSECRG-00260] SAP 20.01.2012
[DSECRG-00258] SAP 20.01.2012
[DSECRG-00257] SAP 20.01.2012
[DSECRG-00256] SAP 20.01.2012
[DSECRG-00255] SAP 20.01.2012
[DSECRG-00254] SAP 20.01.2012
[DSECRG-00253] SAP 20.01.2012
[DSECRG-00252] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-00259] SAP 20.01.2012
[DSECRG-00252] SAP 20.01.2012
[DSECRG-00251] SAP 20.01.2012
[DSECRG-00250] SAP 20.01.2012
[DSECRG-00249] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012
[DSECRG-] SAP 20.01.2012


© 2002—2012, ERPScan
For quoting or using materials from this site
link is obligatory

+44 (20) 81334493    e-mail: research@dsecrg.com
Rss: Vulnerabilities, Exploits, News, Publications, Summary
Search