[Full-disclosure] etoro.it vulnerable to XSS

2012-09-29 Thread tig3rhack
The famous online trading website is vulnerable to an XSS attack Poc: http://www.etoro.it/educazione/node/1008/10%22%20onMouseOver=%22alert%28document.cookie%29%22 Info: https://tig3rblog.wordpress.com/2012/09/29/etoro-it-vulnerable-to-xss/ ___

[Full-disclosure] LG NAS Users and password hash disclosure

2012-09-29 Thread anon6436
# Exploit Title: LG NAS Users and password hash disclosure # Date: 2012-09-29 # Vendor Homepage: http://www.lg.com/ # Version: = firmware_2660 # Tested on: N2B1 Network Storage # Vendor notification: Not notified due to the stupid nature of the vuln.. This vulnerability has been discovered on LG

Re: [Full-disclosure] Foxit Reader suffers from Division By Zero

2012-09-29 Thread Mario Vilas
[image: Inline image 1] On Sat, Sep 29, 2012 at 4:01 AM, kaveh ghaemmaghami kavehghaemmagh...@googlemail.com wrote: Title: Foxit Reader suffers from Division By Zero Version : 5.4.3.0920 Date : 2012-09-28 Vendor : http://www.foxitsoftware.com/

Re: [Full-disclosure] Foxit Reader suffers from Division By Zero

2012-09-29 Thread Nick Boyce
On Sat, Sep 29, 2012 at 8:01 AM, kaveh ghaemmaghami kavehghaemmagh...@googlemail.com wrote: Title: Foxit Reader suffers from Division By Zero Version : 5.4.3.0920 [...] division by zero vulnerability during the handling of the pdf files. that will trigger a denial of