Security
-
High-Tech Bridge announces capital increase and adapted expansion strategy for 20127 February 2012, 9:02 am
High-Tech Bridge increases its nominal share-capital to CHF 3M and announces its development strategy for 2012....
-
High-Tech Bridge partners with LODH’s E-MERGING Platform1 December 2011, 8:14 am
High-Tech Bridge is proud to announce partnership with Lombard Odier’s E-MERGING....
-
High-Tech Bridge joins Online Trust Alliance1 November 2011, 11:11 am
High-Tech Bridge joins Online Trust Alliance (OTA) as a General Member....
-
High-Tech Bridge joins OWASP as Supporter Organization19 October 2011, 9:25 am
High-Tech Bridge joins Open Web Application Security Project (OWASP) as Supporter Organization....
-
High-Tech Bridge joins PCI Security Standards Council26 September 2011, 3:48 pm
High-Tech Bridge joins PCI Security Standards Council (SSC) as a Participating Organization....
-
New Members at Advisory Board6 September 2011, 12:39 pm
High-Tech Bridge has elected the official legal representative and new Advisory Board members....
-
High-Tech Bridge invests in R&D16 March 2011, 12:51 am
High-Tech Bridge increases equity capital to CHF 2m and announces expansion on Swiss and International IT Security markets....
-
New Board member at High-Tech Bridge2 February 2011, 9:44 pm
High-Tech Bridge Board of Directors has elected a new member for 2011....
-
New Expert Services of High-Tech Bridge11 January 2011, 3:28 pm
Malware Analysis and Reverse Engineering expert services are now available for our customers....
-
High-Tech Bridge obtains ISO 27001 certification20 December 2010, 11:00 pm
After capital increase and reinforcement of Management High-Tech Bridge has successfully obtained ISO 27001 certification....
-
La Banque Suisse: High-Tech Bridge Investit22 February 2012, 11:59 am
High-Tech Bridge Investit...
-
PenTest Magazine Extra, No.2: Interview with Marsel Nizamutdinov15 February 2012, 3:47 pm
Interview with Marsel Nizamutdinov...
-
Market: High-Tech Bridge - Contrer les forces du mal15 February 2012, 3:45 pm
High-Tech Bridge - Contrer les forces du mal...
-
L'AGEFI: Développement de la gamme de services8 February 2012, 4:23 pm
Développement de la gamme de services...
-
Le Matin, Tribune de Genève: Entre manif et révolution, Anonymous multiplie les attaques23 January 2012, 5:32 pm
Entre manif et révolution, Anonymous multiplie les attaques...
-
Handelszeitung: Wirtschaftsinformationen - Wer die Konkurrenzschlagen will, muss wissen, was diese vorhat.23 January 2012, 9:33 am
Wirtschaftsinformationen - Wer die Konkurrenzschlagen will, muss wissen, was diese vorhat....
-
PenTest Magazine: XSS & CSRF: Practical exploitation of post-authentication vulnerabilities
in web applications.18 January 2012, 11:40 am
XSS & CSRF: Practical exploitation of post-authentication vulnerabilities
in web applications....
-
Swiss Banking YearBook 2011-2012: Investing into your corporate security is like paying your insurance.29 December 2011, 12:35 pm
Investing into your corporate security is like paying your insurance....
-
Market: High-Tech Bridge et la Sécurité Informatique.20 December 2011, 2:57 pm
High-Tech Bridge et la Sécurité Informatique....
-
Yahoo! News: High-Tech Bridge Nominates Marsel Nizamutdinov as Head of R&D.6 December 2011, 1:11 pm
High-Tech Bridge Nominates Marsel Nizamutdinov as Head of R&D....
-
[HTB23076]: Multiple vulnerabilities in Elefant CMS22 February 2012, 1:16 pm
Product: Elefant CMS v1.1.3 betaVulnerability Type: SQL Injection, XSS (Cross Site Scripting)Risk level: Medium Creater: Elefant CMSVendor Notification: 2012-02-22 14:16:07Public Disclosure: 14 March 2012 Vulnerability Details: To be disclosed on 14 March 2012...
-
[HTB23073]: Multiple XSS in Chyrp21 February 2012, 11:00 pm
Product: Chyrp v2.5b1Vulnerability Type: Cross Site Scripting (XSS)Risk level: Medium Creater: ChyrpVendor Notification: 2012-02-01 13:05:09Public Disclosure: 22 February 2012 CVE Reference(s): CVE-2012-1001Vulnerability Details: High-Tech Bridge SA Security Research Lab has discovered multiple vulnerabilities in Chyrp, which can be exploited to perform Cross Site Scripting attacks.
1) Cross Site Scripting (XSS) in Chyrp: CVE-2012-1001
1.1 Input passed via the "content" POST parameter to /incl...
-
[HTB23075]: Multiple XSS in Fork CMS15 February 2012, 12:03 pm
Product: Fork CMS v3.2.5Vulnerability Type: Cross Site Scripting (XSS)Risk level: Medium Creater: Fork CMSVendor Notification: 2012-02-15 13:03:31Public Disclosure: 7 March 2012 Vulnerability Details: To be disclosed on 7 March 2012...
-
[HTB23072]: Multiple vulnerabilities in LEPTON14 February 2012, 11:00 pm
Product: LEPTON v1.1.3Vulnerability Type: Local File Inclusion, SQL Injection, Cross Site Scripting (XSS)Risk level: High Creater: LEPTON ProjectVendor Notification: 2012-01-25 13:48:34Public Disclosure: 15 February 2012 CVE Reference(s): CVE-2012-0998, CVE-2012-0999, CVE-2012-1000Vulnerability Details: High-Tech Bridge SA Security Research Lab has discovered multiple vulnerabilities in LEPTON, which can be exploited to perform Local File Inclusion, Cross Site Scripting and SQL Injection attacks...
-
[HTB23071]: Multiple vulnerabilities in 11in114 February 2012, 11:00 pm
Product: 11in1 v1.2.1 stable 12-31-2011Vulnerability Type: Local File Inclusion, Сross-Site Request Forgery (CSRF)Risk level: High Creater: 11in1Vendor Notification: 2012-01-25 13:48:26Public Disclosure: 15 February 2012 CVE Reference(s): CVE-2012-0996, CVE-2012-0997Vulnerability Details: High-Tech Bridge SA Security Research Lab has discovered multiple vulnerabilities in 11in1, which can be exploited to perform Local File Inclusion and Сross-Site Request Forgery (CSRF) attacks.
1) Local File...
-
[HTB23074]: Multiple XSS in Dotclear8 February 2012, 11:44 am
Product: Dotclear v2.4.1.2Vulnerability Type: Cross Site Scripting (XSS)Risk level: Medium Creater: DotclearVendor Notification: 2012-02-08 12:44:58Public Disclosure: 29 February 2012 Vulnerability Details: To be disclosed on 29 February 2012...
-
[HTB23070]: Multiple vulnerabilities in ZENphoto7 February 2012, 11:00 pm
Product: ZENphoto v1.4.2Vulnerability Type: PHP Code Execution, SQL Injection, XSSRisk level: High Creater: ZENphotoVendor Notification: 2012-01-18 12:23:20Public Disclosure: 8 February 2012 CVE Reference(s): CVE-2012-0993, CVE-2012-0994, CVE-2012-0995Vulnerability Details: High-Tech Bridge SA Security Research Lab has discovered multiple vulnerabilities in ZENphoto, which can be exploited to perform arbitrary PHP code execution, sql injection and cross site scripting attacks.
1) Arbitrary PHP ...
-
[HTB23069]: Multiple vulnerabilities in OpenEMR31 January 2012, 11:00 pm
Product: OpenEMR v4.1.0Vulnerability Type: Local File Inclusion, Arbitrary Command ExecutionRisk level: High Creater: OEMRVendor Notification: 2012-01-11 11:08:05Public Disclosure: 1 February 2012 CVE Reference(s): CVE-2012-0991, CVE-2012-0992Vulnerability Details: High-Tech Bridge SA Security Research Lab has discovered multiple vulnerabilities in OpenEMR, which can be exploited to perform local file inclusion and arbitrary command execution attacks.
1) Multiple Local File Inclusion vulnerabil...
-
[HTB23068]: Multiple vulnerabilities in OSclass24 January 2012, 11:00 pm
Product: OSclass v2.3.3Vulnerability Type: SQL Injection, XSS (Cross Site Scripting)Risk level: High Creater: osclass.orgVendor Notification: 2012-01-04 14:53:54Public Disclosure: 25 January 2012 CVE Reference(s): CVE-2012-0973, CVE-2012-0974Vulnerability Details: High-Tech Bridge SA Security Research Lab has discovered multiple vulnerabilities in OSclass, which can be exploited to perform cross-site scripting and sql injection attacks.
1) SQL Injection in OSclass: CVE-2012-0973.
Input passed ...
-
[HTB23067]: CSRF (Cross-Site Request Forgery) in DClassifieds24 January 2012, 11:00 pm
Product: DClassifieds v0.1 finalVulnerability Type: CSRF (Cross-Site Request Forgery)Risk level: Low Creater: www.dclassifieds.euVendor Notification: 2012-01-04 14:53:48Public Disclosure: 25 January 2012 CVE Reference(s): CVE-2012-0990Vulnerability Details: High-Tech Bridge SA Security Research Lab has discovered vulnerability in DClassifieds, which can be exploited to perform Сross-Site Request Forgery (CSRF) attacks.
The application allows authorized users to perform certain actions via HTTP...