[Full-disclosure] Remote command Injection in Creme Fraiche 0.6 Ruby Gem

2013-05-14 Thread Larry W. Cashdollar
TITLE: Remote command Injection in Creme Fraiche 0.6 Ruby Gem DATE: 5/14/2013 AUTHOR: Larry W. Cashdollar (@_larry0) DOWNLOAD: http://rubygems.org/gems/cremefraiche, http://www.uplawski.eu/technology/cremefraiche/ DESCRIPTION: Converts Email to PDF files. VENDOR: Notifed on 5/13/2013, provided

[Full-disclosure] Vulnerabilities in multiple plugins for WordPress with VideoJS

2013-05-14 Thread MustLive
Hello list! These are Cross-Site Scripting vulnerabilities in multiple plugins for WordPress with VideoJS. Earlier I've wrote about vulnerabilities in VideoJS (http://seclists.org/fulldisclosure/2013/May/21). This is popular video and audio player, which is used at hundreds thousands of web si

[Full-disclosure] [HITB-Announce] HITB Magazine Issue 010

2013-05-14 Thread Hafez Kamal
Hi everyone, A small reminder that article submissions for HITB Magazine Issue 010 are due tomorrow (15th May 2013). If you're interested in submitting please send your > 3000 word article to editor...@hackinthebox.org Topics of interest include, but are not limited to the following: Next ge