Subscribe via feed.
Posts under XSS

[webapps] – Dr. Web Control Center 6.00.3.201111300 XSS Vulnerability

Posted by q121q under exploit, m$, Security, XSS (No Respond)

Dr. Web Control Center 6.00.3.201111300 XSS Vulnerability

Tags: , ,

Secunia Security Advisory 50058

Secunia Security Advisory – Multiple vulnerabilities have been reported in Apple Safari for Mac OS X, which can be exploited by malicious people to conduct cross-site scripting and spoofing attacks, disclose sensitive information, bypass certain security restrictions, and compromise a user’s system.

Tags: , , , ,

Secunia Security Advisory 50068

Secunia Security Advisory – A weakness and a vulnerability have been reported in Apple Xcode, which can be exploited by malicious people to disclose potentially sensitive information, hijack a user’s session, and bypass certain security restrictions.

Tags: , ,

iOS SSL Kill Switch

This is a MobileSubstrate extension to disable certificate validation within NSURLConnection in order to facilitate black-box testing of iOS Apps. Once installed on a jailbroken device, iOS SSL Kill Switch patches NSURLConnection to override and disable the system’s default certificate validation as well as any kind of custom certificate validation (such as certificate pinning).

Tags: , , ,

Apple Security Advisory 2012-07-25-2

Apple Security Advisory 2012-07-25-2 – Xcode 4.4 is now available and addresses SSL and keychain access vulnerabilities.

Tags: , , , ,

[papers] – Bypassing Spam Filters Using Homographs

Posted by paintmylove18 under exploit, m$, XSS (No Respond)

Bypassing Spam Filters Using Homographs

Tags: , ,

Apple Security Advisory 2012-07-25-1

Apple Security Advisory 2012-07-25-1 – A cross-site scripting issue existed in the handling of feed:// URLs in Safari.

Tags: , ,

[webapps] – SpiceWorks 5.3.75941 Stored XSS and Post-Auth SQL Injection

Posted by mehdibob under exploit, m$, Security, XSS (No Respond)

SpiceWorks 5.3.75941 Stored XSS and Post-Auth SQL Injection

Tags: , , ,

[webapps] – AlienVault OSSIM 3.1 Reflected XSS and Blind SQL Injection

Posted by ehsan under exploit, m$, Security, XSS (No Respond)

AlienVault OSSIM 3.1 Reflected XSS and Blind SQL Injection

Tags: , , , ,

[webapps] – Ipswitch WhatsUp Gold 15.02 Stored XSS – Blind SQLi – RCE

Posted by admin under exploit, m$, Security, XSS (No Respond)

Ipswitch WhatsUp Gold 15.02 Stored XSS – Blind SQLi – RCE

Tags: , , ,