Category Archives: Full Disclosure

Full Disclosure

CVE-2016-6662 – MySQL Remote Root Code Execution / Privilege Escalation ( 0day )

Posted by Dawid Golunski on Sep 12

Vulnerability: MySQL Remote Root Code Execution / Privilege Escalation 0day
CVE: CVE-2016-6662
Severity: Critical
Affected MySQL versions (including the latest):
<= 5.7.15
<= 5.6.33
<= 5.5.52

Discovered by:
Dawid Golunski
http://legalhackers.com

An independent research has revealed multiple severe MySQL vulnerabilities.
This advisory focuses on a critical vulnerability with a CVEID of CVE-2016-6662.
The vulnerability affects MySQL…

Persistent Cross-Site Scripting in Woocommerce WordPress plugin

Posted by Summer of Pwnage on Sep 10

————————————————————————
Persistent Cross-Site Scripting in Woocommerce WordPress plugin
————————————————————————
Sipke Mellema, July 2016

————————————————————————
Abstract
————————————————————————
A vulnerability exists in the Woocommerce API that allows…

Authorization bypass in InfiniteWP Admin Panel

Posted by Summer of Pwnage on Sep 10

————————————————————————
Authorization bypass in InfiniteWP Admin Panel
————————————————————————
Sipke Mellema, July 2016

————————————————————————
Abstract
————————————————————————
An authorization bypass was found in the InfiniteWP Admin Panel that
allows…

Command injection in InfiniteWP Admin Panel

Posted by Summer of Pwnage on Sep 10

————————————————————————
Command injection in InfiniteWP Admin Panel
————————————————————————
Sipke Mellema, July 2016

————————————————————————
Abstract
————————————————————————
The InfiniteWP Admin Panel can be used to execute arbitrary system
commands….

Reflected Cross-Site Scripting vulnerability in MailPoet Newsletters plugin

Posted by Summer of Pwnage on Sep 10

————————————————————————
Reflected Cross-Site Scripting vulnerability in MailPoet Newsletters
plugin
————————————————————————
Sipke Mellema, July 2016

————————————————————————
Abstract
————————————————————————
A Cross-Site Scripting vulnerability was found…

CVE request – Samsumg Mobile Phone SVE-2016-6248: SystemUI Security issue

Posted by 0xr0ot on Sep 08

Hi,

Description of the potential vulnerability:
SVE-2016-6248: SystemUI Security issue
Severity: Medium
Affected versions: L(5.0/5.1), M(6.0) devices with Exynos7420 chipset
Reported on: June 7, 2016
Disclosure status: Privately disclosed.
The vulnerability exists due to a null pointer dereference on fimg2d driver.
The patch verifies if the object is null before dereferencing it.

Fix:…

CVE-2016-4264 Adobe ColdFusion <= 11 XXE Vulnerability

Posted by Dawid Golunski on Sep 08

Vulnerability: Adobe ColdFusion <= 11 XXE Injection
CVE: CVE-2016-4264
Vendor ID: APSB16-30
Discovered by: Dawid Golunski (http://legalhackers.com)

Adobe ColdFusion in versions 11 and below is vulnerable to XXE
Injection when processing untrusted office documents.

Depending on a web application’s functionality and the attacker’s ability to
supply a malicious document to be processed by a vulnerable ColdFusion
application, this…

cve request: Airmail URLScheme render and file:// xss vulnerability

Posted by redrain root on Sep 08

Airmail is a popular email client on iOS and OS X.
I found a vulnerability in airmail of the latest version which could cause
a file:// xss and arbitrary file read.

Author: redrain, yu.hong () chaitin com
Date: 2016-08-15
Version: 3.0.2 and earlier
Platform: OS X and iOS
Site: http://airmailapp.com/
Vendor: http://airmailapp.com/
Vendor Notified: 2016-08-15

Vulnerability:
There is a file:// xss in airmail version 3.0.2 and earlier.
The app can…