[FD] CVE-2014-2230 - OpenX Open Redirect Vulnerability

2014-10-16 Thread Jing Wang
Exploit Title: OpenX Open Redirect Vulnerability Product: OpenX Vendor: OpenX Vulnerable Versions: 2.8.10 and probably prior Tested Version: 2.8.10 Advisory Publication: OCT 8, 2014 Latest Update: OCT 8, 2014 Vulnerability Type: Open Redirect [CWE-601] CVE Reference: CVE-2014-2230 Risk Level:

[FD] New York Times nytimes.com Page Design XSS Vulnerability (Almost all Article Pages Before 2013 are Affected)

2014-10-16 Thread Jing Wang
New York Times nytimes.com Page Design XSS Vulnerability (Almost all Article Pages Before 2013 are Affected) Domain: http://www.nytimes.com/ Vulnerability Description: The vulnerability occurs at New York Times’s URLs. Nytimes (short for New York Times) uses part of the URLs to construct its

[FD] Bypassing blacklists based on IPy

2014-10-16 Thread Nicolas Grégoire
IPy is a Python class and tools for handling of IPv4 and IPv6 addresses and networks (https://github.com/haypo/python-ipy). This library is sometimes used to implement blacklists forbidding internal, private or loopback addresses. Using octal encoding (supported by urllib2), it is possible to