[FD] Unrestricted Upload/RCE in Neosense theme for WordPress

2016-09-19 Thread Walter Hop
d by dynamicpress - 19 Sep: Vulnerability published Credits: The vulnerability was found by Walter Hop, Slik BV, The Netherlands. -- Walter Hop | PGP key: https://lifeforms.nl/pgp ___ Sent through the Full Disclosure mailing list https://nma

[FD] Multiple vulnerabilities in InfiniteWP Admin Panel

2014-12-09 Thread Walter Hop
atches submitted to InfiniteWP - 27 Nov: InfiniteWP publishes version 2.4.3 with fix for issue 1 - 4 Dec: Incomplete fix reported to InfiniteWP - 9 Dec: InfiniteWP publishes version 2.4.4 with fix for issues 2-3 - 10 Dec: Vulnerabilities published - Credits The vulnerabilities were found by Walter H