[FD] DefenseCode Security Advisory: Magento 0day Arbitrary File Upload Vulnerability (Remote Code Execution, CSRF)

2017-04-12 Thread DefenseCode
DefenseCode Security Advisory Magento 0day Arbitrary File Upload Vulnerability (Remote Code Execution, CSRF) Advisory ID: DC-2017-04-003 Software: Magento CE Software Language: PHP Version: 2.1.6 and below Vendor Status: Vendor contacted / Not fixed Release

[FD] DefenseCode ThunderScan SAST Advisory: 53+ WordPress plugins by BestWebSoft Multiple Cross-Site Scripting (XSS) Vulnerabilities

2017-04-12 Thread DefenseCode
, vulnerabilities confirmed Release Date: 20170412 Risk: Medium # Advisory Overview BestWebSoft published more than 50 plugins to the wordpress.org site. Almost all plugins contain the Panel - a component designed for overview and management of various BestWebSoft plugins - both the ones

[FD] Proxifier for Mac 2.19 local root privesc

2017-04-12 Thread Mark Wadham
With CVE-2017-7643 I disclosed a command injection vulnerablity in the KLoader binary that ships with Proxifier <= 2.18. Unfortunately 2.19 is also vulnerable to a slightly different attack that yields the same result. When Proxifier is first run, if the KLoader binary is not suid root it

[FD] c0c0n X August 17-19, 2017 Call for Papers Open

2017-04-12 Thread Prajwal Panchmahalkar
______ __ __ / _ \ / _ \ \ \ / / ___| | | | ___| | | |_ __ _\ V / / __| | | |/ __| | | | '_ \__> < | (__| |_| | (__| |_| | | | |/ . \ \___|\___/ \___|\___/|_| |_| /_/ \_\