Joomla Showdown component version 1.5.0 suffers from a remote SQL injection vulnerability.
Monthly Archives: July 2016
Neoscreen 4.5 Blind SQL Injection
Neoscreen version 4.5 suffers from a remote blind SQL injection vulnerability.
Neoscreen 4.5 Authentication Bypass
Neoscreen version 4.5 suffers from an authentication bypass vulnerability.
DSA-3629 ntp – security update
Several vulnerabilities were discovered in the Network Time Protocol
daemon and utility programs:
DSA-3628 perl – security update
Multiple vulnerabilities were discovered in the implementation of the
Perl programming language. The Common Vulnerabilities and Exposures
project identifies the following problems:
Debian Security Advisory 3626-1
Debian Linux Security Advisory 3626-1 – Eddie Harari reported that the OpenSSH SSH daemon allows user enumeration through timing differences when trying to authenticate users. When sshd tries to authenticate a non-existing user, it will pick up a fixed fake password structure with a hash based on the Blowfish algorithm. If real users passwords are hashed using SHA256/SHA512, then a remote attacker can take advantage of this flaw by sending large passwords, receiving shorter response times from the server for non-existing users.
Cross-Site Scripting in Contact Form to Email WordPress Plugin
Posted by Summer of Pwnage on Jul 24
————————————————————————
Cross-Site Scripting in Contact Form to Email WordPress Plugin
————————————————————————
Burak Kelebek, July 2016
————————————————————————
Abstract
————————————————————————
A reflected Cross-Site Scripting (XSS) vulnerability has…
Cross-Site Scripting in Code Snippets WordPress Plugin
Posted by Summer of Pwnage on Jul 24
————————————————————————
Cross-Site Scripting in Code Snippets WordPress Plugin
————————————————————————
Burak Kelebek, July 2016
————————————————————————
Abstract
————————————————————————
A reflected Cross-Site Scripting (XSS) vulnerability has been found…
Joomla Huge IT Gallery 1.1.5 Cross Site Scripting / SQL Injection
Joomla Huge IT Gallery component version 1.1.5 suffers from cross site scripting and remote SQL injection vulnerabilities.
Hacker Downloaded Vine's Entire Source Code. Here’s How…
Guess What? Someone just downloaded Twitter’s Vine complete source code.
Vine is a short-form video sharing service where people can share 6-second-long looping video clips. Twitter acquired the service in October 2012.
Indian Bug bounty hunter Avinash discovered a loophole in Vine that allowed him to download a Docker image containing complete source code of Vine without any hassle.
<!–
![]()
