> dmcdonald.net / advisories > ──────────────────────────
Advisories & CVEs
disclosed vulnerabilities, coordinated where the vendor engaged, full disclosure where they did not.
── 2026 ──────────────────────────────────────
Dell ThinOS 10 protection mechanism failure
Dell ThinOS 10, versions prior to 2605_10.2100, contain a protection mechanism failure. An attacker with physical access could exploit this to gain unauthorised access to data. Full technical detail is being held for presentation at DEF CON 34.
IGEL OS GRUB shell escape
An attacker with physical access can manipulate the GRUB boot stage in IGEL OS to drop to a root shell. Affects IGEL OS 11 and 12.
Dell client BIOS weak password encoding (SPI flash recovery)
Dell client platform BIOS stores the administrator and user passwords XOR-encrypted in the SPI flash rather than as a one-way hash. A length mismatch between the password field and the key leaks the key alongside the ciphertext, so the password is recovered deterministically from a flash dump with no brute force and no known plaintext. Found jointly with Craig S. Blackie of MDSec while mapping where Dell keeps its BIOS settings on the flash.
Dell ThinOS 10 improper access control
Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information exposure. Also found independently by Christophe Schleypen of NATO Cyber Security Centre.
── 2025 ──────────────────────────────────────
Dell ThinOS unencrypted memory dumps
Dell ThinOS thin client platform marketed as having full disk encryption stored kernel memory dumps unencrypted, exposing process memory to anyone with physical access. Found on a client build review by reaching for screwdrivers rather than a checklist.
── 2011 ──────────────────────────────────────
One Click Orgs 1.4.1 Multiple Vulnerabilities
Four issues in a community legal-structure and voting tool: stored XSS, open URL redirection, second-order SMTP injection, email-address non-uniqueness. Originated from a London Hackspace post offering free testing for community projects; vendor was responsive, fixed everything, updated production. Clean good-faith disclosure outcome.
Pro Clan Manager 0.4.2 Multiple Vulnerabilities
SQL injection via eregi null-byte bypass (CVE-2011-4556); poor random password generation reducing the keyspace to ~90,000 candidates (CVE-2011-4557). Vendor discontinued the project in response.
── 2010 ──────────────────────────────────────
VWar 1.6.1 R2 Multiple Remote Vulnerabilities
Five bugs in VWar (PHP clan management system): SQL injection, stored XSS, broken access controls, weak password generation (system-seconds seed gives ~60 candidates), static session tokens. Disclosed to the developer in April 2008. The project was officially abandoned in response, with the developer publicly stating that VWar should no longer be used. Public release followed two years later.
read full advisory · Full Disclosure post · Original archive