BugTraq Mode:
(Page 11 of 1700)  < Prev  6 7 8 9 10 11 12 13 14 15 16  Next >
Persistent Cross-Site Scripting in Magic Fields 1 WordPress Plugin 2016-08-15
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Persistent Cross-Site Scripting in Magic Fields 1 WordPress Plugin
------------------------------------------------------------------------

Burak Kelebek, July 2016

-------------------------------------------------------------

[ more ]  [ reply ]
Persistent Cross-Site Scripting in Magic Fields 2 WordPress Plugin 2016-08-15
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Persistent Cross-Site Scripting in Magic Fields 2 WordPress Plugin
------------------------------------------------------------------------

Burak Kelebek, July 2016

-------------------------------------------------------------

[ more ]  [ reply ]
Cross-Site Scripting in Link Library WordPress Plugin 2016-08-15
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Cross-Site Scripting in Link Library WordPress Plugin
------------------------------------------------------------------------

Burak Kelebek, July 2016

------------------------------------------------------------------------

A

[ more ]  [ reply ]
Ajax Load More Local File Inclusion vulnerability 2016-08-15
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Ajax Load More Local File Inclusion vulnerability
------------------------------------------------------------------------

Burak Kelebek, July 2016

------------------------------------------------------------------------

Abstr

[ more ]  [ reply ]
Cross-Site Scripting/Cross-Site Request Forgery in Peter's Login Redirect WordPress Plugin 2016-08-15
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Cross-Site Scripting/Cross-Site Request Forgery in Peter's Login
Redirect WordPress Plugin
------------------------------------------------------------------------

Yorick Koster, July 2016

-------------------------------------

[ more ]  [ reply ]
Cross-Site Request Forgery vulnerability in Email Users WordPress Plugin 2016-08-15
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Cross-Site Request Forgery vulnerability in Email Users WordPress Plugin
------------------------------------------------------------------------

Julien Rentrop, July 2016

------------------------------------------------------

[ more ]  [ reply ]
Cross-Site Scripting vulnerability in Google Maps WordPress Plugin 2016-08-15
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Cross-Site Scripting vulnerability in Google Maps WordPress Plugin
------------------------------------------------------------------------

Julien Rentrop, July 2016

------------------------------------------------------------

[ more ]  [ reply ]
Cross-Site Request Forgery in Photo Gallery WordPress Plugin allows deleting of images 2016-08-15
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Cross-Site Request Forgery in Photo Gallery WordPress Plugin allows
deleting of images
------------------------------------------------------------------------

Umit Aksu, July 2016

---------------------------------------------

[ more ]  [ reply ]
Stored Cross-Site Scripting vulnerability in Photo Gallery WordPress Plugin 2016-08-15
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Stored Cross-Site Scripting vulnerability in Photo Gallery WordPress
Plugin
------------------------------------------------------------------------

Umit Aksu, July 2016

--------------------------------------------------------

[ more ]  [ reply ]
Cross-Site Request Forgery in Photo Gallery WordPress Plugin allows adding of images 2016-08-15
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Cross-Site Request Forgery in Photo Gallery WordPress Plugin allows
adding of images
------------------------------------------------------------------------

Umit Aksu, July 2016

-----------------------------------------------

[ more ]  [ reply ]
Cross-Site Request Forgery in Photo Gallery WordPress Plugin allows deleting of galleries 2016-08-15
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Cross-Site Request Forgery in Photo Gallery WordPress Plugin allows
deleting of galleries
------------------------------------------------------------------------

Umit Aksu, July 2016

------------------------------------------

[ more ]  [ reply ]
Taser Axon Dock (Body-Worn Camera Docking Station) v3.1 - Authentication Bypass 2016-08-15
reggie dodd30 gmail com
[TITLE]
Taser Axon Dock (Body-Worn Camera Docking Station) v3.1 - Authentication Bypass

[CREDITS & AUTHORS]
Reginald Dodd
https://www.linkedin.com/in/reginalddodd

[VENDOR & PRODUCT]
Taser International Inc.
Axon Dock - Body-Worn Camera Docking Station
https://www.axon.io/products/dock

[SUMMARY]
T

[ more ]  [ reply ]
PayPal Inc BB #127 - 2FA Bypass Vulnerability 2016-08-15
Vulnerability Lab (research vulnerability-lab com)
Document Title:
===============
PayPal Inc BB #127 - 2FA Bypass Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1903

Release Date:
=============
2016-08-12

Vulnerability Laboratory ID (VL-ID):
====================================
1903

[ more ]  [ reply ]
Stash v1.0.3 CMS - SQL Injection Vulnerability 2016-08-15
Vulnerability Lab (research vulnerability-lab com)
Document Title:
===============
Stash v1.0.3 CMS - SQL Injection Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1899

Release Date:
=============
2016-08-10

Vulnerability Laboratory ID (VL-ID):
====================================
189

[ more ]  [ reply ]
Linksys E2500 and E1200 (Unauth Command Injection) 2016-08-14
samhuntley84 gmail com
Linksys E2500 and E1200 suffer from missing command injection issue in parental control parameters. This allows an attacker to change the control the device remotely.

Combining the attack of no authorization control, it allows an attacker to actually execute unauthenticated command injection attack

[ more ]  [ reply ]
Linksys E1200 and E2500 (Missing authorization on parental control) 2016-08-14
samhuntley84 gmail com


Linksys E1200 hardware version 2.2 and firmware version 2.0.07 (build 2) suffer from missing authorization control on parental control page. This allows an attacker to change the parental controls set up by parents to keep kids safe from visiting adult sites and probably compromise a kid?s device

[ more ]  [ reply ]
Reflected Cross Site Scripting (XSS) Vulnerability in nopcommerce 3.70 2016-08-15
tal argoni (talargoni gmail com)
Security Advisory
CVE-ID: N/A
Topic: Reflected Cross Site Scripting (XSS) Vulnerability in
"successful registration" page
Class: Input Validation
Severity: Medium
Discovery: 2016-04-28
Vendor Notification: 2016-04-28
Vendor response: 2016-05-30
Vendor Patch:

[ more ]  [ reply ]
OpenCart 2.0.3.1 Cross Site Scripting Vulnerability (product_id - GET) 2016-08-13
hamedizadi gmail com
###########################

# OpenCart 2.0.3.1 Cross Site Scripting Vulnerability

###########################

Information
--------------------
Author: Hamed Izadi
Email: array("hamedizadi", "@", "gmail", ".com");
Name: XSS Vulnerability in OpenCart
Affected Software : OpenCart
Affected Versions:

[ more ]  [ reply ]
OpenCart 2.0.3.1 Cross Site Scripting Vulnerability (product_id - GET) 2016-08-13
hamedizadi gmail com
###########################

# OpenCart 2.0.3.1 Cross Site Scripting Vulnerability

###########################

Information
--------------------
Author: Hamed Izadi
Email: ("hamedizadi", "@", "gmail", ".com");
Name: XSS Vulnerability in OpenCart
Affected Software : OpenCart
Affected Versions: v2.0

[ more ]  [ reply ]
OpenCart 2.0.3.1 Cross Site Scripting Vulnerability (product_id - GET) 2016-08-13
hamedizadi gmail com
###########################

# OpenCart 2.0.3.1 Cross Site Scripting Vulnerability

###########################

Information
--------------------
Author: Hamed Izadi
Email: ("hamedizadi", "@", "gmail", ".com");
Name: XSS Vulnerability in OpenCart
Affected Software : OpenCart
Affected Versions: v2.0

[ more ]  [ reply ]
WSO2-CARBON v4.4.5 CSRF / DOS 2016-08-13
hyp3rlinx lycos com
[+] Credits: John Page aka HYP3RLINX

[+] Website: hyp3rlinx.altervista.org

[+] Source: http://hyp3rlinx.altervista.org/advisories/WSO2-CARBON-v4.4.5-CSRF-DOS.t
xt

[+] ISR: ApparitionSec

Vendor:
============
www.wso2.com

Product:
==================
Ws02Carbon v4.4.5

WSO2 Carbon is the core p

[ more ]  [ reply ]
WSO2 CARBON v4.4.5 PERSISTENT XSS COOKIE THEFT 2016-08-13
hyp3rlinx lycos com
[+] Credits: John Page aka HYP3RLINX

[+] Website: hyp3rlinx.altervista.org

[+] Source: http://hyp3rlinx.altervista.org/advisories/WSO2-CARBON-v4.4.5-PERSISTENT
-XSS-COOKIE-THEFT.txt

[+] ISR: ApparitionSec

Vendor:
=============
www.wso2.com

Product:
==================
Ws02Carbon v4.4.5

WSO2

[ more ]  [ reply ]
WSO2-CARBON v4.4.5 LOCAL FILE INCLUSION 2016-08-13
apparitionsec gmail com
[+] Credits: John Page aka HYP3RLINX

[+] Website: hyp3rlinx.altervista.org

[+] Source: http://hyp3rlinx.altervista.org/advisories/WSO2-CARBON-v4.4.5-LOCAL-FILE
-INCLUSION.txt

[+] ISR: ApparitionSec

Vendor:
===============
www.wso2.com

Product:
====================
Ws02Carbon v4.4.5

WSO2 Car

[ more ]  [ reply ]
WSO2 IDENTITY-SERVER v5.1.0 XML External-Entity 2016-08-13
hyp3rlinx lycos com
[+] Credits: John Page aka HYP3RLINX

[+] Website: hyp3rlinx.altervista.org

[+] Source: http://hyp3rlinx.altervista.org/advisories/WSO2-IDENTITY-SERVER-v5.1.0-X
ML-External-Entity.txt

[+] ISR: ApparitionSec

Vendor:
=============
www.wso2.com

Product:
============================
Wso2 Identity

[ more ]  [ reply ]
[SECURITY] [DSA 3648-1] wireshark security update 2016-08-12
Moritz Muehlenhoff (jmm debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
-
Debian Security Advisory DSA-3648-1 security (at) debian (dot) org [email concealed]
https://www.debian.org/security/ Moritz Muehlenhoff
August 12, 2016

[ more ]  [ reply ]
[security bulletin] HPSBGN03630 rev.2 - HP Operations Manager for Unix, Solaris, and Linux using Apache Commons Collections (ACC), Remote Code Execution 2016-08-12
security-alert hpe com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Note: the current version of the following document is available here:
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=
emr_n
a-c05206507

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c05206507
Version: 2

HPSBGN03630 r

[ more ]  [ reply ]
[security bulletin] HPSBHF03440 rev.1 - HPE iLO 3 using JQuery, Remote Cross-Site Scripting (XSS) 2016-08-12
security-alert hpe com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Note: the current version of the following document is available here:
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=
emr_n
a-c05232730

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c05232730
Version: 1

HPSBHF03440 r

[ more ]  [ reply ]
[CVE-2016-3089] Apache OpenMeetings XSS in SWF panel 2016-08-12
Maxim Solodovnik (solomax666 gmail com)
Severity: Moderate

Vendor: The Apache Software Foundation

Versions Affected: Apache OpenMeetings 3.1.0

Description: The value of the URL's "swf" query parameter is
interpolated into the JavaScript tag without being escaped, leading to
the reflected XSS.

All users are recommended to upgrade to Ap

[ more ]  [ reply ]
[SECURITY] [DSA 3647-1] icedove security update 2016-08-11
Moritz Muehlenhoff (jmm debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
-
Debian Security Advisory DSA-3647-1 security (at) debian (dot) org [email concealed]
https://www.debian.org/security/ Moritz Muehlenhoff
August 11, 2016

[ more ]  [ reply ]
Defense in depth -- the Microsoft way (part 42): Sysinternals utilities load and execute rogue DLLs from %TEMP% 2016-08-11
Stefan Kanthak (stefan kanthak nexgo de)
Hi @ll,

several of Microsoft's Sysinternals utilities extract executables
to %TEMP% and run them from there; the extracted executables are
vulnerable to DLL hijacking, allowing arbitrary code execution in
every user account and escalation of privilege in "protected
administrator" accounts [*].

* C

[ more ]  [ reply ]
(Page 11 of 1700)  < Prev  6 7 8 9 10 11 12 13 14 15 16  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus