[FD] Backdoored Web Application v.1.0.2

2017-02-14 Thread MustLive
Hello participants of Mailing List. In December 2012 I released my Backdoored Web Application (BWA) (http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2012-December/008630.html) - a reference test of backdoors scanners. All qualitative scanners of backdoors must find it, otherw

[FD] ShadeYouVPN.com Client v2.0.1.11 for Windows Privilege Escalation

2017-02-14 Thread Kacper Szurek
# Exploit ShadeYouVPN.com Client v2.0.1.11 for Windows Privilege Escalation # Date: 14.02.2017 # Software Link: https://shadeyouvpn.com/ # Exploit Author: Kacper Szurek # Contact: https://twitter.com/KacperSzurek # Website: https://security.szurek.pl/ # Category: local 1. Description `ShadeYou` s

[FD] [Kodi v17.1] - Local File Inclusion

2017-02-14 Thread Eric Flokstra
# Exploit Title: Kodi - Local File Inclusion # Date: 12 February 2017 # Exploit Author: Eric Flokstra # Vendor Homepage: https://kodi.tv/ # Software Link: https://kodi.tv/download/ # Version: Kodi version 17.1 (Krypton), Chorus version 2.4.2 # Tested on: Linux # CVE: CVE-2017-5982 Kodi (formerly

[FD] CFP for Speaker Workshops at the Packet Hacking Village at DEF CON 25 Now Open

2017-02-14 Thread Ming
#Overview The Wall of Sheep would like to announce a call for presentations at DEF CON 25 at the Caesars Palace in Las Vegas, NV from Thursday, July 27th to Sunday, July 30th. This will be the 5th anniversary of our Speaker Workshops. The Wall of Sheep’s workshops goal is to deliver talks that inc

[FD] CVE-2017-5670 : Riverbed RiOS insecure cryptographic storage

2017-02-14 Thread Sydream Labs
# Riverbed RiOS insecure cryptographic storage (CVE-2017-5670) ## Description Riverbed Steelhead hardware appliances are used to optimize and accelerate network traffic. There can be implemented as TLS endpoints, so they have a secure vault aimed to store private TLS certificates for servers. The

[FD] WordPress Plugin Easy Table 1.6 - Persistent Cross-Site Scripting

2017-02-14 Thread Manuel Garcia Cardenas
= MGC ALERT 2017-001 - Original release date: Feb 07, 2017 - Last revised: Feb 12, 2017 - Discovered by: Manuel Garcia Cardenas - Severity: 4,8/10 (CVSS Base Score) = I. VULNERABILITY -