To read more about Secunia's Advisory:
Secunia SA39961 Advisory
In this blog are reported some of my observations about information security. I hope they can be useful for you.
0 commenti Filed Under: Secunia
Secunia has published my new security Adsvisory regarding a new vulnerability found in latest release (and lower) of Contao CMS(fka TYPOlight). This vulnerability allows an attacker to delete administrator/users, articles, news, newsletter andmodify many other parameters.
To read Secunia's Advisory:
http://secunia.com/advisories/48180/
To learn more about my Original Advisory:
http://ivanobinetti.blogspot.com/2012/02/contaocms-fka-typolight-211-csrf-delete.html
0 commenti Filed Under: Secunia
Today Secunia published a my security Adsvisory regarding a new vulnerability found in Webfolio CMS which allows to add a new administrator account, modify published web pages and change many other parameters of latest release (and below) of Webfolio CMS.
To read Secunia's Advisory:
http://secunia.com/advisories/48190
For know more about my original Advisory:
http://ivanobinetti.blogspot.com/2012/02/webfoliocms-114-csrf-add-adminmodify.html
0 commenti Filed Under: Secunia
Secunia has published an advisory related to a "0day" vulnerabilty (http://ivanobinetti.blogspot.com/2012/02/forkcms-325-csrf-and-xss-0day.html which I've discovered in the past days and regarding a CSRF (Cross Site Request Forgery) which affects ForkCMS 3.2.5 and lower.
Secunia tested this vulnerability also in 3.2.6 version, latest release which ForkCMS team published few days ago.
As I already said in my advisory I think that ForkCMS in a very nice CMS which, with some security improvements, can become a great cms. May be that I will use it in the future.
Following you can read more details about Secunia Advisory:
https://secunia.com/advisories/48067
Also PacketStorm has published this Advisory:
http://packetstormsecurity.org/files/110069/sa48067.txt
0 commenti Filed Under: Secunia