more than 6 mnths ago me and @HauntITBlog reported serious SQLi vuln to a vendor... still not patched -> their clients exposed. what to do?
-
-
Replying to @hasherezade
@hasherezade@HauntITBlog How many times have you reminded them?2 replies 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze@HauntITBlog we found this vuln during pentest for one of their client (but same problem is in all versions of their CMS)1 reply 0 retweets 0 likes -
Replying to @hasherezade
@hasherezade@HauntITBlog So, pretty big vuln indeed. I would contact them again before doing anything - which is the most responsible imho.2 replies 0 retweets 0 likes -
Replying to @bartblaze
@bartblaze@HauntITBlog I also think going full disclosure now will do no good, I re-checked some of their clients now and still data leaks1 reply 0 retweets 0 likes -
-
Replying to @bartblaze
@bartblaze@HauntITBlog but I am just thinking how to force them to treat this issue more seriously2 replies 0 retweets 0 likes -
Replying to @hasherezade
@hasherezade@bartblaze@h0wlu maybe we should ask their client$... after we'll get the logo ;]1 reply 0 retweets 0 likes
@HauntITBlog @hasherezade @h0wlu I guess that's also a possibility! ;)
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.