Faraday is a tool that introduces a new concept called IPE, or Integrated Penetration-Test Environment. It is a multiuser penetration test IDE designed for distribution, indexation and analysis of the generated data during the process of a security audit. The main purpose of Faraday is to re-use the available tools in the community to take advantage of them in a multiuser way.
Monthly Archives: October 2015
PHP-Fusion 7.02.07 Blind SQL Injection
PHP-Fusion versions 7.02.07 and below suffer from a remote blind SQL injection vulnerability in the admin panel.
LanSpy 2.0.0.155 Buffer Overflow
LanSpy version 2.0.0.155 suffers from a buffer overflow vulnerability.
WordPress Easy2Map 1.2.9 Local File Inclusion / Directory Traversal
WordPress Easy2Map plugin version 1.2.9 suffers from local file inclusion and directory traversal vulnerabilities.
WordPress Easy2Map 1.2.9 Cross Site Scripting
WordPress Easy2Map plugin version 1.2.9 suffers from a cross site scripting vulnerability.
WordPress ResAds 1.0.1 Cross Site Scripting
WordPress ResAds plugin version 1.0.1 suffers from multiple reflective cross site scripting vulnerabilities.
Ubuntu Security Notice USN-2762-1
Ubuntu Security Notice 2762-1 – Dmitry Vyukov discovered that the Linux kernel did not properly initialize IPC object state in certain situations. A local attacker could use this to escalate their privileges, expose confidential information, or cause a denial of service (system crash).
Ubuntu Security Notice USN-2763-1
Ubuntu Security Notice 2763-1 – Dmitry Vyukov discovered that the Linux kernel did not properly initialize IPC object state in certain situations. A local attacker could use this to escalate their privileges, expose confidential information, or cause a denial of service (system crash).
Ubuntu Security Notice USN-2764-1
Ubuntu Security Notice 2764-1 – Dmitry Vyukov discovered that the Linux kernel did not properly initialize IPC object state in certain situations. A local attacker could use this to escalate their privileges, expose confidential information, or cause a denial of service (system crash).
Ubuntu Security Notice USN-2765-1
Ubuntu Security Notice 2765-1 – Dmitry Vyukov discovered that the Linux kernel did not properly initialize IPC object state in certain situations. A local attacker could use this to escalate their privileges, expose confidential information, or cause a denial of service (system crash).