Category Archives: Full Disclosure

Full Disclosure

CVE-2014-8751 goYWP WebPress Multiple XSS (Cross-Site Scripting) Security Vulnerabilities

Posted by Jing Wang on Dec 09

*CVE-2014-8751 goYWP WebPress Multiple XSS (Cross-Site Scripting) Security
Vulnerabilities*

Exploit Title: goYWP WebPress Multiple XSS (Cross-Site Scripting) Security
Vulnerabilities
Product: WebPress
Vendor: goYWP
Vulnerable Versions: 13.00.06
Tested Version: 13.00.06
Advisory Publication: Dec 09, 2014
Latest Update: Dec 09, 2014
Vulnerability Type: Cross-Site Scripting [CWE-79]
CVE Reference: CVE-2014-8751
Credit: Wang Jing [SPMS, Nanyang…

NEW VMSA-2014-0013 – VMware vCloud Automation Center product updates address a critical remote privilege escalation vulnerability

Posted by VMware Security Response Center on Dec 09

————————————————————————
VMware Security Advisory

Advisory ID: VMSA-2014-0013
Synopsis: VMware vCloud Automation Center product updates address a
critical remote privilege escalation vulnerability
Issue date: 2014-12-09
Updated on: 2014-12-09 (Initial Advisory)
CVE number: CVE-2014-8373

————————————————————————

1. Summary…

Interesting Backdoor

Posted by Alfred Baroti on Dec 09

Hi,
I was wondering if someone found something similar with this. I didn’t find anything similar with this before.

Here is:

root () pay1-test:~# ssh zimadmin () 0
zimadmin () 0’s password:
——-;i——————————————
—–.,if——————————————
—–,tLE,————–..:;ji———————
—-;ittL;———-.;;;tjfGj.———————…

Humhub SQL injection and multiple persistent XSS vulnerabilities

Posted by A. W. on Dec 09

[+] Humhub [1] SQL injection vulnerability
[+] Discovered by: Jos Wetzels, Emiel Florijn
[+] Affects: Humhub <= 0.10.0-rc.1

The Humhub social networking kit versions 0.10.0-rc.1 and prior suffer
from an SQL injection vulnerability, which has now been resolved in
cooperation with the vendor [2], in its notification listing
functionality allowing an attacker to obtain backend database access.
In the actionIndex() function located in…

Coinbase User Enumeration

Posted by stephen () averagesecurityguy info on Dec 08

Coinbase User Enumeration
=========================
The Coinbase web site allows user enumeration, which would normally not be a big deal, but in this case, we are able to
enumerate a users username, “real name”, and an MD5 hash of the user’s email address. Using a large list of email
addresses and a tool like hashcat it is possible to determine the email address for many of these users. Keep in mind
that the real name is user…

[SE-2014-02] Google App Engine Java security sandbox bypasses (project pending completion / action from Google)

Posted by Security Explorations on Dec 06

Hello All,

We discovered multiple security issues in Google App Engine that allow
for a complete Java VM security sandbox escape.

There are more issues pending verification – we estimate them to be in
the range of 30+ in total.

Quick summary of our developments so far:
– we bypassed GAE whitelisting of JRE classes / achieved complete Java VM
security sandbox escape (17 full sandbox bypass PoC codes exploiting 22
issues in total),
– we…

NASA Orion – Bypass, Persistent Issue & Embed Code Execution Vulnerability

Posted by Vulnerability Lab on Dec 05

Document Title:
===============
NASA Orion – Bypass, Persistent Issue & Embed Code Execution Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1339

[VU#666988] US CERT

Vulnerability Magazine:
http://magazine.vulnerability-db.com/?q=articles/2014/12/05/nasa-mars-orion-program-researcher-reveals-vulnerability-boarding-pass

Reference Article:…