News Document Title: ==================== NATO Research and Technology Organisation fixed RFI [FIXED!] Release Date: ============= 2011-11-03 Laboratory Article: =================== A vulnerability researcher of the laboratory named Alexander Fuchs (f0x23) has discovered a critical vulnerability in the vendor website of the NATO Research and Technology Organisation. Successful exploitation of the detected file inclusion may result in dbms compromise, defacement, theft of webmail and login portal accounts or manipulation of service/application content. The vulnerability has been closed within 24 hours by the rto development team in cooperation with Benjamin Kunz Mejri. 2011-11-01: Vendor Notification 2011-11-01: Vendor Response/Feedback 2011-11-02: Vendor Fix/Patch 2011-11-02: Public or Non-Public Disclosure Advisory: http://www.vulnerability-lab.com/get_content.php?id=307