[FD] United Airways® united.com Insecure Transmission of User Credentials

2014-07-14 Thread Joshua Smith
"This vulnerability has similar scope and threat as the HeartBleed bug.” — umm, no. This bug affects your creds at a single site. Please don’t over inflate. -kernelsmith Date: Sun, 13 Jul 2014 11:58:18 + From: Michael Scheidell To: "fulldisclosure@seclists.org" Subject: [FD] United Airwa

[FD] Puffin Web Browser Address Bar Spoofing Vulnerability puts Millions of users at risk

2014-07-14 Thread Rafay Baloch
Greetings, I have discovered an address bar spoofing vulnerability inside of Puffin Web browser which has user base of more than 10 million Google play and Mobo genie combined. (Just for android). A detailed writeup and a video demonstration and POC is available here: http://www.rafayhackingartic

[FD] [KIS-2014-08] OpenCart <= 1.5.6.4 (cart.php) PHP Object Injection Vulnerability

2014-07-14 Thread Egidio Romano
- OpenCart <= 1.5.6.4 (cart.php) PHP Object Injection Vulnerability - [-] Software Link: http://www.opencart.com/ [-] Affected Versions: Version 1.5.6.4 and prior ve