Subscribe via feed.
Archive for February, 2016

Chamilo LMS Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Chamilo LMS suffers from a persistent cross site scripting vulnerability.

Adobe Cross Site Scripting / Open Redirect

Posted by deepcore under exploit (No Respond)

Adobe’s site suffered from cross site scripting and open redirection vulnerabilities.

[webapps] – SOLIDserver <=5.0.4 – Local File Inclusion Vulnerability

Posted by deepcore under Security (No Respond)

SOLIDserver <=5.0.4 – Local File Inclusion Vulnerability

Tags: ,

Prezi Bug Bounty #5 – CS Cross Site & Redirect Vulnerability

Posted by deepcore under exploit (No Respond)

An independent vulnerability laboratory researcher discovered a client-side redirect web vulnerability in the official Prezi web-application.

Ebay Cross Site Scripting

Posted by deepcore under exploit (No Respond)

ebay.com suffered from a cross site scripting vulnerability.

Vesta Control Panel 0.9.8-15 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Vesta Control Panel versions 0.9.8-15 and below suffer from a persistent cross site scripting vulnerability via the user agent.

Umbraco SSRF / Cross Site Request Forgery / Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Umbraco versions prior to 7.4.0 suffers from server-side request forgery, cross site request forgery, and cross site scripting vulnerabilities.

Comodo Internet Security VNC Server Exposure

Posted by deepcore under exploit (No Respond)

Comodo Internet Security installs GeekBuddy which installs a weakly secure exposed VNC server.

osCommerce 2.3.4 Local File Inclusion / Cross Site Request Forgery

Posted by deepcore under exploit (No Respond)

osCommerce version 2.3.4 suffers from cross site request forgery and local file inclusion vulnerabilities.

osCmax 2.5.4 Code Execution / CSRF / Local File Inclusion

Posted by deepcore under exploit (No Respond)

osCmax version 2.5.4 suffers from code execution, cross site request forgery, and local file inclusion vulnerabilities.