SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insufficient output encoding. Read More
Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party services. Read More
Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments. Read More
SBA Research, the Vienna Competence Center for Information Security, will be funded for another four years within the framework of COMET – Competence Centers for Excellent Technologies Report of the FFG On 16 June 2020, the mid-term evaluation of SBA-K1, the COMET flagship research program of SBA Research, took… Read More
A total of eight female researchers have been nominated for this year’s Hedy Lamarr Prize of the City of Vienna. The prize is awarded to women in Austria for their outstanding achievements in the field of information technology. On October 1, the Hedy Lamarr Prize will be awarded for the… Read More
Alexandra Mai and Katharina Pfeffer present their paper „User Mental Models of Cryptocurrency Systems – A Grounded Theory Approach“ at this year’s SOUPS (Symposium on usable privacy and security). “ The sixteenth Symposium on Usable Privacy and Security (SOUPS) brings together an interdisciplinary group of… Read More
Innovative Solutions by joint Research Tangible results demonstrate the lasting benefit of the COMET program – from basic to applied research. 10 years of joint efforts in information security within the COMET program have led to a plethora of new and innovative approaches. cyan Security… Read More
On Tuesday, June 16th, 2020, our scientific work in our flagship activity, COMET, was evaluated by an international jury of experts. Due to the all-too-well known COVID-19 restrictions, the whole event had been moved to the virtual realm. That is to say, almost. It turns out that even a virtual… Read More
Security in the digital world is not only one of the main 2020 topics of the association fit4internet in cooperation with the Federal Ministry for Digitalization and Business Location (BMDW), but is also centrally dealt with in the new Digital Action Plan Austria. Respective future steps were presented by the… Read More
Christian Kudera spoke about cross-border interoperability of Corona tracing apps with Deutsche Welle.Read full article He was also quoted in a podcast about the cross-border functionality of Corona tracing apps by Deutschlandfunk Nova.Listen to the podcast
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page. ∞