WordPress <=v4.4 Username Exists Information Disclosure

2015-12-11 Thread John SECURELI.com
Information security research credited to John Martinelli @ SECURELI.com. (j...@secureli.com) - Affects: WordPress <=v4.4 Vulnerability: Information Disclosure CVE-ID: Pending Impact: Username exists disclosure on /wp-login.php - By default, WordPress <=4.4 discloses whether a

Executable installers are vulnerable^WEVIL (case 7): 7z*.exe allows remote code execution with escalation of privilege

2015-12-11 Thread Stefan Kanthak
Hi @ll, the executable installers [°] of 7-Zip (see ) and ALL self-extracting archives created with 7-Zip are vulnerable: 1. They load and execute a rogue/bogus/malicious UXTheme.dll ['] eventually found in the directory they are started from (the "application

ORGIN STUDIOS Cms Multiple Vulnerability

2015-12-11 Thread iedb . team
sql and Xss Vulnerability in ORGIN STUDIOS Cms All Version # # # @@@@@@@ @@@@@ @@@ # @@@@@@@@@ @@ @@@ @@@@@ # @@@@@@@@@@@