New User, Welcome!     Login

David Vieira/Kurz

[MajorSecurity Advisory #64]Apple Safari 4.0.4 Denial of Service

Vendor-Status: informed
Advisory-Status: published on 02-02-2010

Credits
============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.info

Affected Products:
============
Apple Safari browser 4.0.4 an prior

[MajorSecurity Advisory #65]Motorola Milestone Smartphone Denial of Service

Vendor-Status: informed
Advisory-Status: published on 02-02-2010

Credits
============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.info

Affected Products:
============
Motorola Milestone(Droid) smartphone Browser with following useragent:

[MajorSecurity-SA-2012-014]Apple Safari on iOS 5.1 - Adressbar spoofing vulnerability

Vendor-URL: http://www.apple.com/
Advisory-Status: published

Credits
=============
Discovered by: David Vieira-Kurz of MajorSecurity

Affected Products
=============
Apple Mobile Safari on iOS 5.1
Prior versions may also be affected

[MajorSecurity Advisory #55]moziloCMS - Directory Traversal, Cross Site Scripting and Session Fixation Issues

Vendor-Status: informed
Advisory-Status: published

Credits
============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.info

Affected Products:
----------------------------
moziloCMS 1.10.1 and prior

[MajorSecurity Advisory #53]BLUEPAGE CMS - Cross Site Scripting and Session Fixation Issues

Vendor-Status: informed
Advisory-Status: published

Credits
============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.de

Affected Products:
----------------------------
BLUEPAGE CMS 2.5 and prior

[MajorSecurity Advisory #59]PHP <=5.3 - mysqli_real_escape_string() full path disclosure

Vendor-Status: informed
Advisory-Status: published

Credits
============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.info

Affected Products:
----------------------------
PHP 5.3 and prior

Re: [MajorSecurity SA-081]Contao CMS 2.9.2 - Persistent Cross Site Scripting Issue

> Vendor-URL: http://www.contao.org/
> Advisory-Status: published
> 
> Credits
> =============
> Discovered by: David Vieira-Kurz
> 
> Affected Products:
> =============
> Contao CMS 2.9.2
> Prior versions may also be vulnerable

[MajorSecurity SA-079]PHPKIT WCMS - Multiple stored Cross Site Scripting Issues

Vendor-URL: http://www.phpkit.com/
Advisory-Status: published

Credits
=============
Discovered by: David Vieira-Kurz of MajorSecurity

Original Advisory
=============
http://www.majorsecurity.net/phpkit-wcms-xss-stored.php


[MajorSecurity SA-068]Anantasoft Gazelle CMS - change admin password via Cross-site Request Forgery

Vendor-Status: informed
Advisory-Status: published

Credits
============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.info/penetrationstest.php

Affected Products:
----------------------------
Anantasoft Gazelle CMS 1.0

Social Engine 2.7 CRLF Injection + SQL injection

Vendor-Status: informed
Advisory-Status: published

Credits
************************
Discovered by: David Vieira-Kurz of HACKATTACK IT SECURITY GmbH
http://www.HACKATTACK.at || http://www.HACKATTACK.eu

Affected Products:
----------------------------
Social Engine 2.7 and prior

[MajorSecurity SA-073]Subdreamer CMS - SQL injection vulnerability

Vendor-URL: http://www.subdreamer.com/
Advisory-Status: published

Credits
=============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.net/penetrationstest.php

Original Advisory
=============
http://www.majorsecurity.net/subdreamer_cms_sql_injection.php

[MajorSecurity Advisory #56]moziloWiki - Directory Traversal, XSS and SessionFixation Issues

Vendor-Status: informed
Advisory-Status: published

Credits
============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.de

Affected Products:
----------------------------
moziloWiki 1.0.1 and prior

[MajorSecurity SA-080]WordPress 3.0.1 - Cross Site Scripting Issue

Vendor-URL: http://www.wordpress.org/
Advisory-Status: published

Credits
=============
Discovered by: David Vieira-Kurz of MajorSecurity

Affected Products:
=============
WordPress 3.0.1
Prior versions may also be vulnerable

[MajorSecurity SA-076]Conpresso CMS - Cross site Scripting vulnerabilities

Vendor-URL: http://www.conpresso.com/
Advisory-Status: published

Credits
=============
Discovered by: David Vieira-Kurz of MajorSecurity

Original Advisory
=============
http://www.majorsecurity.net/conpresso_cms_xss.php


[MajorSecurity Advisory #57]PHP <=5.3 - preg_match() full path disclosure

Vendor-Status: informed
Advisory-Status: published

Credits
============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.info

Affected Products:
----------------------------
PHP 5.3 and prior

Re: HostAdmin 3.* Remote File Include Vulnerabilities

Dear SecurityFocus moderators.
Unfortunelly this bug was not found by Am!r (IrIsT?) like it has been credited in this advisory. It was originally discovered by David Vieira-Kurz of MajorSecurity and published on June 3rd 2006. 

BugTraq-iD: 345993 --> http://www.securityfocus.com/archive/1/435993

and BID: 18284 --> 
http://www.securityfocus.com/bid/18284

Original advisory: http://www.majorsecurity.de/index_2.php?major_rls=major_rls9


[MajorSecurity SA-081]Contao CMS 2.9.2 - Persistent Cross Site Scripting Issue

Vendor-URL: http://www.contao.org/
Advisory-Status: published

Credits
=============
Discovered by: David Vieira-Kurz

Affected Products:
=============
Contao CMS 2.9.2
Prior versions may also be vulnerable

[MajorSecurity Advisory #52]ActualAnalyzer family - Cross Site Scripting Issues

Vendor-Status: informed
Advisory-Status: published

Credits
============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.de

Affected Products:
----------------------------
ActualAnalyzer Server 8.37 and prior

[MajorSecurity Advisory #54]xt:Commerce - Cross Site Scripting and Session Fixation Issues

Vendor-Status: informed
Advisory-Status: published

Credits
============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.de

Affected Products:
----------------------------
xt:Commerce 3.04 and prior

[MajorSecurity SA-075]CMS RedAks 2.0 - SQL injection vulnerability

Vendor-URL: http://www.redaks.com/
Advisory-Status: published

Credits
=============
Discovered by: David Vieira-Kurz of MajorSecurity

Original Advisory
=============
http://www.majorsecurity.net/redaks_cms_sql_injection.php


HACKATTACK Advisory 20081016]WEB//NEWS SQL Injection and Cookie Manipulation

Vendor-Status: informed
Advisory-Status: published

Credits
============
Discovered by: David Vieira-Kurz
http://www.HACKATTACK.at / www.HACKATTACK.eu

Affected Products:
----------------------------
WEB//NEWS 1.4 and prior

[MajorSecurity SA-074]CMS RedAks 2.0 - Multiple Cross-site Scripting issues

Vendor-URL: http://www.redaks.com/
Advisory-Status: published

Credits
=============
Discovered by: David Vieira-Kurz of MajorSecurity

Original Advisory
=============
http://www.majorsecurity.net/redaks_CMS_xss.php


Simploo CMS Community Edition - Remote PHP Code Execution Issue

Vendor-URL: http://www.simploo.de/
Advisory-Status: published

Credits
=============
Discovered by: David Vieira-Kurz of MajorSecurity

Affected Products:
=============
Simploo CMS 1.7.1 and prior


[MajorSecurity SA-070]Plume CMS - change Admin Password via Cross-site Request Forgery

Vendor-URL: http://www.plume-cms.net/
Advisory-Status: published

Credits
============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.info/penetrationstest.php

Affected Products:
----------------------------
Plume CMS 1.2.4

[MajorSecurity SA-069]Invision Power Board - stored Cross site Scripting

Vendor-Status: informed
Advisory-Status: published

Credits
============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.info/penetrationstest.php


Affected Products:
----------------------------

[HACKATTACK Advisory 20081203]Pro Clan Manager 0.4.2 - Session Fixation

Vendor-Status: informed
Advisory-Status: not yet published

Credits
************************
Discovered by: David Vieira-Kurz
http://www.HACKATTACK.at || http://www.HACKATTACK.eu

Affected Products:
----------------------------
Pro Clan Manager 0.4.2 and prior

[MajorSecurity SA-071]phpFaber CMS - Multiple stored Cross-site Scripting issues

Vendor-URL: http://www.phpfaber.com/
Advisory-Status: published

Credits
=============
Discovered by: David Vieira-Kurz
http://www.majorsecurity.net/penetrationstest.php

Original Advisory
=============
http://www.majorsecurity.net/phpFaber_CMS_xss.php

[HACKATTACK Advisory 20081127]Social Impress CMS 1.1 - Session Fixation

Vendor-Status: informed
Advisory-Status: not yet published

Credits
************************
Discovered by: David Vieira-Kurz
http://www.HACKATTACK.at || http://www.HACKATTACK.eu

Affected Products:
----------------------------
Impress CMS 1.1 and prior

[HACKATTACK Advisory 25012009]ConPresso CMS 4.07 - Session Fixation, XFS, XSS

Vendor-Status: informed
Advisory-Status: not yet published

Credits
************************
Discovered by: David Vieira-Kurz
http://www.HACKATTACK.at 

Affected Products:
----------------------------
ConPresso CMS 4.07 and prior



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!