Subscribe via feed.
Posts under XSS

Apple Security Advisory 2012-09-12-1

Apple Security Advisory 2012-09-12-1 – iTunes 10.7 is now available and addresses multiple memory corruption issues in webkit.

Tags: , ,

Secunia Security Advisory 50618

Secunia Security Advisory – Multiple vulnerabilities have been reported in Apple iTunes, which can be exploited by malicious people to compromise a user’s system.

Tags: , , , ,

[papers] – CVE-2012-4681 Technical Analysis Report

Posted by q121q under exploit, hhu, m$, XSS (No Respond)

CVE-2012-4681 Technical Analysis Report

Tags: , ,

[webapps] – Trend Micro InterScan Messaging Security Suite Stored XSS and CSRF

Posted by admin under exploit, m$, Security, XSS (No Respond)

Trend Micro InterScan Messaging Security Suite Stored XSS and CSRF

Tags: , ,

[papers] – Detecting and Exploiting XSS Vulnerabilities with Xenotix XSS Exploit Framework

Posted by tirosh under exploit, m$, XSS (No Respond)

Detecting and Exploiting XSS Vulnerabilities with Xenotix XSS Exploit Framework

Tags: , , , ,

[webapps] – Clipster Video Persistent XSS Vulnerability

Posted by whisla13 under exploit, m$, Security, XSS (No Respond)

Clipster Video Persistent XSS Vulnerability

Tags: , , , ,

Secunia Security Advisory 50545

Secunia Security Advisory – Apple has issued an update for Java for Mac OS X.

Tags: , , , ,

Apple Security Advisory 2012-09-05-1

Apple Security Advisory 2012-09-05-1 – An opportunity for security-in-depth hardening is addressed by updating to Java version 1.6.0_35.

Tags: , , ,

[webapps] – OTRS Open Technology Real Services 3.1.8 and 3.1.9 XSS Vulnerability

Posted by Bailey under exploit, m$, Security, XSS (No Respond)

OTRS Open Technology Real Services 3.1.8 and 3.1.9 XSS Vulnerability

Tags: , , ,

Java 7 Applet Remote Code Execution

This Metasploit module exploits a vulnerability in Java 7, which allows an attacker to run arbitrary Java code outside the sandbox. The vulnerability seems to be related to the use of the newly introduced ClassFinder#resolveClass in Java 7, which allows the sun.awt.SunToolkit class to be loaded and modified. Please note this flaw is also being exploited in the wild, and there is no patch from Oracle at this point

Tags: , ,