more than 6 mnths ago me and @HauntITBlog reported serious SQLi vuln to a vendor... still not patched -> their clients exposed. what to do?
-
-
Replying to @hasherezade
@hasherezade@HauntITBlog How many times have you reminded them?2 replies 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze@HauntITBlog we found this vuln during pentest for one of their client (but same problem is in all versions of their CMS)1 reply 0 retweets 0 likes -
Replying to @hasherezade
@hasherezade@HauntITBlog So, pretty big vuln indeed. I would contact them again before doing anything - which is the most responsible imho.2 replies 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze@HauntITBlog I also think going full disclosure now will do no good, I re-checked some of their clients now and still data leaks1 reply 0 retweets 0 likes -
-
Replying to @bartblaze
@bartblaze@HauntITBlog but I am just thinking how to force them to treat this issue more seriously2 replies 0 retweets 0 likes
@hasherezade @HauntITBlog Agreed. Maybe this post can help? http://googleonlinesecurity.blogspot.be/2010/07/rebooting-responsible-disclosure-focus.html … (or someone who knows more about responsible disclosure)
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.