A collection of issues I identified and the associated CVE. Vendors have been notified and given ample time to develop/release patches.
- Title: Reflected Cross Site Scripting on Login Page of Zyxel devices
- Disclosure Date: 15 Apr 2019
- Title: BlogEngine.NET Directory Traversal / Content Listing
- Disclosure Date: 24 Jun 2019
- Title: BlogEngine.NET pingback.axd XXE
- Disclosure Date: 19 Jun 2019
- Title: BlogEngine.NET Directory Traversal in File Upload / Remote Code Execution
- Disclosure Date: 17 Jun 2019
- Title: BlogEngine.NET Directory Traversal in theme cookie / Remote Code Execution
- Disclosure Date: 17 Jun 2019
- Title: BlogEngine.NET Unvalidated redirect login page
- Disclosure Date: 24 Jun 2019
- Title: BlogEngine.NET syndication.axd XXE
- Disclosure Date: 19 Jun 2019
- Title: WiKID Systems 2FA Enterprise Server searchDevices.jsp SQL Injection
- Disclosure Date: 16 Oct 2019
- Title: WiKID Systems 2FA Enterprise Server userPreregistration.jsp Cross-site Scripting
- Disclosure Date: 16 Oct 2019
- Title: WiKID Systems 2FA Enterprise Server Logs.jsp Unauthenticated Cross-site Scripting
- Disclosure Date: 16 Oct 2019
- Title: WiKID Systems 2FA Enterprise Server groups.jsp Cross-site Scripting
- Disclosure Date: 16 Oct 2019
- Title: WiKID Systems 2FA Enterprise Server processPref.jsp SQL Injection
- Disclosure Date: 16 Oct 2019
- Title: WiKID Systems 2FA Enterprise Server Cross-site Request Forgery
- Disclosure Date: 16 Oct 2019
- Title: WiKID Systems 2FA Enterprise Server Logs.jsp SQL Injection
- Disclosure Date: 16 Oct 2019
- Title: WiKID Systems 2FA Enterprise Server adm_usrs.jsp Cross-site Scripting
- Disclosure Date: 16 Oct 2019
- Title: MITREid Connect header.tag/topbar.tag Cross-Site Scripting
- Disclosure Date: 3 Jan 2020
- Title: Castel NextGen DVR - Privilege Escalation
- Disclosure Date: 3 Jun 2020
- Title: Castel NextGen DVR - Authorization Bypass
- Disclosure Date: 3 Jun 2020
- Title: Castel NextGen DVR - Cleartext Credentials
- Disclosure Date: 3 Jun 2020
- Title: Castel NextGen DVR - CSRF
- Disclosure Date: 3 Jun 2020