Full Disclosure

Syndicate content
A lightly moderated high-traffic forum for disclosure of security information. Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue. The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip. Unfortunately, most of the posts are worthless drivel, so finding the gems takes patience.
Updated: 34 min 56 sec ago

[ISecAuditors Security Advisories] CSRF vulnerability in LinkedIn

26 March, 2013 - 03:34

Posted by ISecAuditors Security Advisories on Mar 26

=============================================
INTERNET SECURITY AUDITORS ALERT 2013-001
- Original release date: January 30th, 2013
- Last revised: March 25th, 2013
- Discovered by: Vicente Aguilera Diaz
- Severity: 4.3/10 (CVSSv2 Base Score)
=============================================

I. VULNERABILITY
-------------------------
CSRF vulnerability in LinkedIn

II. BACKGROUND
-------------------------
LinkedIn is a social networking service and...

[SECURITY] [DSA 2652-1] libxml2 security update

26 March, 2013 - 00:40

Posted by Michael Gilbert on Mar 25

-------------------------------------------------------------------------
Debian Security Advisory DSA-2652-1 security () debian org
http://www.debian.org/security/ Michael Gilbert
March 24, 2013 http://www.debian.org/security/faq
-------------------------------------------------------------------------

Package : libxml2
Vulnerability : external entity expansion
Problem...

Re: Fwd: Remote command injection vulnerability in Rosewill RSVA11001 (Hi3515 based)

25 March, 2013 - 10:12

Posted by Eric Urban on Mar 25

Rose will just responds to me with engrish when I email them. I have no
point of contact for hi silicon. I would gladly assist the manufacturer in
addressing this hole if put into contact with the right people.

Re: XSS vulnerability on WP-Banners-Lite (wordpress plugin)

25 March, 2013 - 08:29

Posted by Henri Salo on Mar 25

You can report next issue to the plugins<snip>wordpress.org address and they will
remove the plugin from showing up in plugin index site[1] or whatever it is
called and users can't install it using WordPress administrator-interface before
developer of the plugin has fixed the vulnerability. I will send the
plugins-guys email right now to get the process on-going. You can also directly
contact me in case you need help coordinating...

Re: Fwd: Remote command injection vulnerability in Rosewill RSVA11001 (Hi3515 based)

25 March, 2013 - 07:57

Posted by Henri Salo on Mar 25

Did you report this to the vendor?

Fwd: Remote command injection vulnerability in Rosewill RSVA11001 (Hi3515 based)

25 March, 2013 - 07:37

Posted by Eric Urban on Mar 25

I have been hacking on a Rosewill RSVA11001 for a while now, something to
suck up my free time. I had pulled apart the firmware previously but did
not succeed in finding a way to get a shell on the device. The box is
Hi3515 based, I found an exploit for another similar box (Ray Sharp) but it
did not work. The Rosewill firmware seems to use an executable that listens
on two ports rather one when communicating with the Windows-based control...

Re: [DC4420] DC4420 - London DEFCON - March meet - Tuesday 26th March 2013

25 March, 2013 - 07:35

Posted by Paul Dart on Mar 25

Hi all,

Could whoever has access to the Google Calendar update it for tomorrow's
meeting please (before they stop the service ;-)

Thanks and see you all tomorrow,

Paul

XSS vulnerability on WP-Banners-Lite (wordpress plugin)

25 March, 2013 - 06:53

Posted by Fernando A. Lagos B. on Mar 25

I. Background
--------------
[-] Affected plugin: WP Banners Lite
[-] Plugin Description: The plugin easily allows you to manage ad
banners on your site.
[-] Plugin URL: http://wordpress.org/extend/plugins/wp-banners-lite/
[-] Tested Version: 1.29, 1.31, 1.40
[-] Reported: YES - but no answer
[-] Report Date: 03/12/13
[-] Published:
http://blog.zerial.org/seguridad/vulnerabilidad-en-plugin-para-wordpress-afecta-a-mas-de-200-sitios/

II. Details...

XSS vulnerabilities in ZeroClipboard and multiple web applications

24 March, 2013 - 18:19

Posted by MustLive on Mar 24

Hello list!

In February I've wrote about Cross-Site Scripting vulnerabilities in
ZeroClipboard and multiple web applications. This is additional information
on this topic.

XSS vulnerabilities in ZeroClipboard
http://securityvulns.ru/docs29105.html
XSS vulnerabilities in YAML, Multiproject for Trac, UserCollections for
Piwigo, TAO and TableTools for DataTables for jQuery
http://securityvulns.ru/docs29104.html
XSS vulnerabilities in...

Backupbuddy wordpress plugin - sensitive data exposure in importbuddy.php

24 March, 2013 - 04:04

Posted by Rob Armstrong on Mar 24

#
#
# Backupbuddy - sensitive data exposure in importbuddy.php
#
# "the premiere WordPress backup plugin to backup, restore and move
WordPress"
# http://ithemes.com/purchase/backupbuddy/
#
# known versions affected: v1.3.4, v2.1.4, v2.2.25, v2.2.28, v2.2.4, likely
other versions also
#
# impact:
# access to wordpress site and sql backups
# disclosure of server configuration information
#
# author: robarmstrong.te71 () gmail...

JAOW 2.4.8 XSS Vulnerability

24 March, 2013 - 04:03

Posted by metropolis haxor on Mar 24

Hi guys,
You can find the software affected at http://www.jaow.net/uploads/jaow_2.4.8.zip
Thanks,

Metropolis
###########################################
#
# Script Name : JAOW 2.4.8
#
# Version : 2.4.8
#
# Bug Type : XSS vulnerability
#
# Found by : Metropolis
#
# Home : http://metropolis.fr.cr
#
# Discovered : 23/03/2013
#
# Download app : http://www.jaow.net/uploads/jaow_2.4.8.zip
#
# Google search : Propuls� par Jaow 2.4.8 -
#...