[FD] NibbleBlog 4.0.3 - CSRF - Not fixed

2015-09-02 Thread Curesec Research Team (CRT)
NibbleBlog 4.0.3: CSRF Security Advisory – Curesec Research Team 1. Introduction Affected Product: NibbleBlog 4.0.3 Fixed in: not fixed Fixed Version Link: n/a Vendor Contact: Website: http://www.nibbleblog.com/ Vulnerability Type: CSRF

[FD] NibbleBlog 4.0.3 - Code Execution - Not fixed

2015-09-02 Thread Curesec Research Team (CRT)
NibbleBlog 4.0.3: Code Execution Security Advisory – Curesec Research Team 1. Introduction Affected Product: NibbleBlog 4.0.3 Fixed in: not fixed Fixed Version Link: n/a Vendor Contact: Website: http://www.nibbleblog.com/ Vulnerability Type:

[FD] Serendipity 2.0.1 - Persistent XSS

2015-09-02 Thread Curesec Research Team (CRT)
Serendipity 2.0.1: Persistent XSS Security Advisory – Curesec Research Team 1. Introduction Affected Product: Serendipity 2.0.1 Fixed in: 2.0.2 Fixed Version Link: https://github.com/s9y/Serendipity/releases/download/2.0.2/serendipity-2.0.2.zip Vendor Contact:

[FD] PayPal Inc - Security Approval & 2FA Account Auth Bypass Session Vulnerability

2015-09-02 Thread Vulnerability Lab
*(o_O)! Document Title: === PayPal Inc - Security Approval & 2FA Account Auth Bypass Session Vulnerability References (Source): http://www.vulnerability-lab.com/get_content.php?id=1486 Video: http://www.vulnerability-lab.com/get_content.php?id=1485 Watch