A list of my findings of security vulnerabilities and weaknesses: Navigate CMSFindings from a live bug hunting exercise on Navigate CMS.Sean WrightSean WrightMotorola - Directory Traversal InvestigationWriteup of my further investigation of the Motorola MBP853 camera.Sean WrightSean WrightScottish Power - Open RedirectAn open redirect finding on the Scottish Power website, which allowed for an attacker to redirect the user to a site of their choosing.Sean WrightSean WrightSky - Plain Text Data Transmission (CVE-2018-18908 )CVE-2018-18908: The Sky Go Windows Desktop application performs several requests over plain HTTP.Sean WrightSean WrightCVE-2018-12499The Motorola MBP853 firmware does not correctly validation server certificates. This allows for a Man in The Middle (MiTM) attack to take place between a Motorola MBP853 camera and the servers which communicates with.Sean WrightSean WrightLogitech - HTTPS Downgrade VulnerabilityA finding from the Logitech support page which resulted in the login form loading and submitting over HTTP (instead of HTTPS).Sean WrightSean WrightEdinburgh CouncilFinding The landing page for the Edinburgh Council is servered over plain HTTP. This is vulnerable to Man in The Middle (MiTM) attacks. Since the login page to one’s council account is served from this page, an attacker who has managed to get MiTM could change the link to pointSean WrightSean Wright