WPN-XM Serverstack v0.8.6 CSRF - MySQL / PHP.INI Hijacking

2016-04-10 Thread hyp3rlinx
[+] Credits: hyp3rlinx [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/WPNXM-CSRF.txt Vendor: === wpn-xm.org Product: == WPN-XM Serverstack for Windows - Version 0.8.6 WPN-XM is a free and

WPN-XM Serverstack v0.8.6 CSRF - MySQL / PHP.INI Hijacking

2016-04-10 Thread hyp3rlinx
[+] Credits: hyp3rlinx [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/WPNXM-CSRF.txt Vendor: === wpn-xm.org Product: == WPN-XM Serverstack for Windows - Version 0.8.6 WPN-XM is a free and

CSRF - MySQL / PHP.INI Hijacking

2016-04-10 Thread hyp3rlinx
[+] Credits: hyp3rlinx [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/WPNXM-CSRF.txt Vendor: === wpn-xm.org Product: == WPN-XM Serverstack for Windows - Version 0.8.6 WPN-XM is a free and

WPN-XM Serverstack v0.8.6 XSS

2016-04-10 Thread hyp3rlinx
[+] Credits: hyp3rlinx [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/WPNXM-XSS.txt Vendor: === wpn-xm.org Product: WPN-XM Serverstack for Windows - Version 0.8.6 WPN-XM is a free and open-source web server solution stack

CVE-2016-2170: Apache OFBiz information disclosure vulnerability

2016-04-10 Thread jler...@apache.org
== CVE-2016-2170: Apache OFBiz information disclosure vulnerability Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache OFBiz 13.07.02 and 13.07.01 Apache OFBiz 12.04.05 and earlier releases in the series (12.04.*) The

CVE-2015-3268: Apache OFBiz information disclosure vulnerability

2016-04-10 Thread jler...@apache.org
CVE-2015-3268: Apache OFBiz information disclosure vulnerability == Severity: Moderate Vendor: The Apache Software Foundation Versions Affected: Apache OFBiz 13.07.02 and 13.07.01 Apache OFBiz 12.04.05 and earlier releases in the series (12.04.*) The