Blind SQL Injection in WP Symposium allows unauthenticated attackers to access sensitive data (WordPress plugin)

Posted by dxw Security on Aug 12

Details
================
Software: WP Symposium
Version: 15.1
Homepage: https://wordpress.org/plugins/wp-symposium
Advisory report:
https://security.dxw.com/advisories/blind-sql-injection-in-wp-symposium-allows-unauthenticated-attackers-to-access-sensitive-data/
CVE: Awaiting assignment
CVSS: 6.4 (Medium; AV:N/AC:L/Au:N/C:P/I:N/A:P)

Description
================
Blind SQL Injection in WP Symposium allows unauthenticated attackers to access…

Reflected XSS in iframe allows unauthenticated users to do almost anything an admin can (WordPress plugin)

Posted by dxw Security on Aug 12

Details
================
Software: iframe
Version: 3.0
Homepage: http://wordpress.org/plugins/iframe/
Advisory report:
https://security.dxw.com/advisories/reflected-xss-in-iframe-allows-unauthenticated-users-to-do-almost-anything-an-admin-can/
CVE: Awaiting assignment
CVSS: 5.8 (Medium; AV:N/AC:M/Au:N/C:P/I:P/A:N)

Description
================
Reflected XSS in iframe allows unauthenticated users to do almost anything an admin can

Vulnerability…

Re: Mozilla extensions: a security nightmare

Posted by Thomas D. on Aug 12

Hi,

Mario Vilas wrote:

Correct.

OK, installing into %APPDATA% or %LOCALAPPDATA% will remove Windows’ tampering protection.
I hope you are not arguing that because nowadays many application will install into %APPDATA% or %LOCALAPPDATA% they
became “safe” because they are so many?!

Remember how the thing with %APPDATA% and %LOCALAPPDATA% started/became mainstream: There was a small search corp. who
thought they need to develop…

BigTree CMS 4.2.3 Multiple Cross-Site-Scripting Vulnerabilities

Posted by Curesec Research Team on Aug 12

BigTree CMS 4.2.3: Multiple Cross Site Scripting Vulnerabilities
Security Advisory – Curesec Research Team

Online Reference:
http://blog.curesec.com/article/blog/BigTree-CMS-423-Multiple-Cross-Site-Scripting-Vulnerabilities-38.html

1. Introduction

Affected Product: BigTree CMS 4.2.3
Fixed in: 4.2.4
Fixed Version Link:
https://github.com/bigtreecms/BigTree-CMS/archive/4.2.3.zip
Vendor Contact: contribute ()…

BigTree CMS 4.2.3 Multiple Sql Injections

Posted by Curesec Research Team on Aug 12

BigTree CMS 4.2.3: Multiple SQL Injection Vulnerabilities
Security Advisory – Curesec Research Team

Online-Reference:
http://blog.curesec.com/article/blog/BigTree-CMS-423-Multiple-SQL-Injection-Vulnerabilities-39.html

1. Introduction

Affected Product: BigTree CMS 4.2.3
Fixed in: 4.2.4
Fixed Version Link:
https://github.com/bigtreecms/BigTree-CMS/archive/4.2.3.zip
Vendor Contact: contribute ()…

CodoForum 3.3.1 Multiple Cross Site Scriptings

Posted by Curesec Research Team on Aug 12

CodoForum 3.3.1 Multiple Cross Site Scriptings
Security Advisory – Curesec Research Team
Online-Reference
http://blog.curesec.com/article/blog/CodoForum-331-Multiple-Cross-Site-Scripting-Vulnerabilities-40.html

1. Introduction

Affected Product: CodoForum 3.3.1
Fixed in: 3.4
Fixed Version Link:
https://bitbucket.org/evnix/codoforum_downloads/downloads/codoforum.v.3.4.build-19.zip

Vendor Contact: admin () codologic…

Thomson Reuters FATCA – Arbitrary File Upload

Posted by Etnies on Aug 12

Title: Thomson Reuters FATCA – Arbitrary File Upload
Author: Jakub Palaczynski
Date: 10. June 2015
CVE: CVE-2015-5951

Affected software:
==================

All versions of Thomson Reuters FATCA below v5.2

Exploit was tested on:
======================

Thomson Reuters FATCA v5.1.0.30

Description:
============

The Thomson Reuters for FATCA solution enables organizations to comply with
the key requirements of both CRS and FATCA.[1]…

php 7 use after free bug

Posted by 牛保龙 on Aug 12

i reported a use after free for php on hackerone.com,the bug :https://bugs.php.net/bug.php?id=70211.

Description: ———— the Hash table is full, resize it,ZEND_HASH_IF_FULL_DO_RESIZE(ht),but if one elment is
already allocate in the old memery and re-allocate in the new memry and the var_hash struct also exists the old memery
for the element, it can cause a use after free when unserialize() function has r/R referer. my english is poor. i…

CESA-2015:1586 Critical CentOS 5 firefox SecurityUpdate

CentOS Errata and Security Advisory 2015:1586 Critical

Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1586.html

The following updated files have been uploaded and are currently 
syncing to the mirrors: ( sha256sum Filename ) 

i386:
5662f3e3c540f0e4320228c555c87abde41261dfff759b7b3c6f7b3c3437ed2d  firefox-38.2.0-4.el5.centos.i386.rpm

x86_64:
5662f3e3c540f0e4320228c555c87abde41261dfff759b7b3c6f7b3c3437ed2d  firefox-38.2.0-4.el5.centos.i386.rpm
5c7e89558108d1165a1c19c11033f53bedd1069cf318b459bbdcb57398212309  firefox-38.2.0-4.el5.centos.x86_64.rpm

Source:
932cbc600b4b5244f367f376ef5a6698f82cf12f24e1d4afba479c2eeff0ac29  firefox-38.2.0-4.el5.centos.src.rpm



Mozilla Releases Security Updates for Firefox, Firefox ESR, and Firefox OS

Original release date: August 11, 2015

The Mozilla Foundation has released security updates to address critical vulnerabilities in Firefox, Firefox ESR, and Firefox OS. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.

Available updates include:

  • Firefox 40
  • Firefox ESR 38.2
  • Firefox OS 2.2

Users and administrators are encouraged to review the Security Advisories for Firefox, Firefox ESR, and Firefox OS and apply the necessary updates.


This product is provided subject to this Notification and this Privacy & Use policy.