Our public security advisories

PHP Self Cross Site Scripting in MantisBT 1.2.x

MantisBT installations 1.2.x up to 1.2.7 are vulnerable to Cross Site Scripting attacks due to lack of sanitation of the variable $_SERVER["PHP_SELF"]

Posted on Sep 13, 2011 

Read full advisory»

Anti-CSRF Filter Bypass SMF 2.0 / 1.1.14

The [img] BBCode tag anti-CSRF filter can be bypassed due to incorrect parsing of the 'action' variable, because of this it is possible to execute CSRF successfully.

Posted on Aug 23, 2011 

Read full advisory»

Huawei EchoLife HG520 RemoteManagement CSRF

Huawei EchoLife HG520 modems do not require authentication to access certain pages such as: '/Forms/access_cwmp_1', '/Forms/rpQos_1' and '/Forms/rpRManage_1'. A CSRF exploit can be used to enable remote administration inerfaces on the WAN.

Posted on Jun 08, 2010 

Read full advisory»

Huawei EchoLife HG520c Information Disclosure

Huawei EchoLife HG520 modems are vulnerable to an information disclosure vulnerability. Sensitive modem information can be accessed using a public URL in modems with the web interface activated.

Posted on May 16, 2010 

Read full advisory»

Huawei EchoLife HG520 Remote Information Disclosure

Huawei EchoLife HG520 modems are vulnerable to a remote information disclosure vulnerability. This vulnerability can be exploited by sending a specially crafted UDP packet that causes the modems to return sensitive information in clear text form.

Posted on May 13, 2010 

Read full advisory»

RSS Feed

Stay up to date on the latest security advisories released by Websec

Recent From Blog

Bypassing Web Application Firewalls with SQLMap Tamper Scripts
An introduction to SQLMap's new tamper scripts and how the can be used to bypass Web Application Firewalls and Intrusion Detection Systems.
Posted in SQL Injection WAF SQLMap Tamper Scripts Firewall

Optimized Blind MySQL Injection Data Retrieval
Demonstrates a method to extract data from a MySQL database using blind injection in fewer requests than currently known techniques such as the Bisection and Bit Shift method.
Posted in Blind Injection MySQL SQL Injection Database

mac2wepkey - Huawei default WEP generator
Huawei HG520 and HG530 routers are vulnerable to weak cipher attacks. It is possible to generate the default WEP/WPA key. The purpose of this post is to explain the process of developing a key generator for these devices.
Posted in mac2wepkey home gateway wep generator echolife hg530 huawei hg520

Last News

Apr 30, 2012
GuadalajaraCON 2012 by Websec

Mar 21, 2012
Conference on Cyberbulling at Westhill Institute
Websec had the opportunity to speak with students at the Westhill Institute about Cyberbulling and the threat it brings to young adults.