Announcing cross_fuzz, a potential 0-day in circulation, and more

2011-01-03 Thread Michal Zalewski
Hi list, == SUMMARY == I am happy to announce the availability of cross_fuzz - an amazingly effective but notoriously annoying cross-document DOM binding fuzzer that helped identify about one hundred bugs in all browsers on the market - many of said bugs exploitable - and is still finding more.

www.eVuln.com : SQL Injection in WikLink

2011-01-03 Thread bt
www.eVuln.com advisory: SQL Injection in WikLink Summary: http://evuln.com/vulns/170/summary.html Details: http://evuln.com/vulns/170/description.html ---Summary--- eVuln ID: EV0170 Software: WikLink Vendor: n/a Version: 0.1.3 Critical Level: medium Type: SQL Injection Status:

Geeklog 1.7.1 = Cross Site Scripting Vulnerability

2011-01-03 Thread YGN Ethical Hacker Group
= Geeklog 1.7.1 = Cross Site Scripting Vulnerability = 1. OVERVIEW The Geeklog was vulnerable to Cross Site Scripting in its administration backend. 2. BACKGROUND Geeklog is a

[ACM, Ariadne Content Manager] unauth. SQL injection + user enumeration

2011-01-03 Thread Andrea Purificato
Hi sec-folks, I recently discuss with Ariadne team to public disclose two new different vulnerabilities found in Ariadne Content Manager (ACM). As the name says, ACM is an enterprise solution for content management mainly used by big private and public companies and institutions. This is the