Secunia has published an advisory related to a "0day" vulnerabilty (http://ivanobinetti.blogspot.com/2012/02/forkcms-325-csrf-and-xss-0day.html which I've discovered in the past days and regarding a CSRF (Cross Site Request Forgery) which affects ForkCMS 3.2.5 and lower.
Secunia tested this vulnerability also in 3.2.6 version, latest release which ForkCMS team published few days ago.
As I already said in my advisory I think that ForkCMS in a very nice CMS which, with some security improvements, can become a great cms. May be that I will use it in the future.
Following you can read more details about Secunia Advisory:
https://secunia.com/advisories/48067
Also PacketStorm has published this Advisory:
http://packetstormsecurity.org/files/110069/sa48067.txt
Secunia - Fork CMS Vulnerability
0 commenti Filed Under: Secunia
D-Link DSL-2640B "0day" Vulnerabilities
SecurityFocus (http://www.securityfocus.com/) has assigned me three BID (Bugtraq ID) related to "0day" Dlink and Cisco Linksys vulnerabilities regarding design flaws and exploitable using CSRF:
Following you can read more details about them:
http://www.securityfocus.com/bid/52096
http://www.securityfocus.com/bid/52129
http://www.securityfocus.com/bid/52105
0 commenti Filed Under: 0day Vulnerabilities, hardware, Web Vulnerabilities
DFLabs PTK <= 1.0.5 Multiple Vulnerabilities (Steal Authentication Credentials)
Today also PacketStorm published the new "0day" vulnerability that affects DFLabs PTK 1.0.5 and lower versions.
http://packetstormsecurity.org/files/110102/DFLabs-PTK-1.0.5-Cross-Site-Request-Forgery.html
0 commenti Filed Under: 0day Vulnerabilities, Web Vulnerabilities
DFLabs PTK <= 1.0.5 Multiple Vulnerabilities (Steal Authentication Credentials)
Today I've discovered multiple vulnerabilities into DFLabs PTK 1.0.5 (latest release) and lower.
Offensive Security Exploit DB has already published this "0day" vulnerability:
http://www.exploit-db.com/exploits/18513/
0 commenti Filed Under: 0day Vulnerabilities, Web Vulnerabilities
D-Link DSL-2640B Authentication Bypass
New "0day" vulnerability found.
For more details:
http://www.exploit-db.com/exploits/18511/
http://packetstormsecurity.org/files/110117/D-Link-DSL-2640B-Authentication-Bypass.html
http://www.securityfocus.com/bid/52129
0 commenti Filed Under: 0day Vulnerabilities, hardware, Web Vulnerabilities
ForkCMS 3.2.5 CSRF and XSS "0day" Vulnerabilities
To download my Original Advisory:
https://sites.google.com/site/ivanobinetti/ForkCMS%203.2.5%20CSRF%20and%20XSS%20vulnetabilities.txt?attredirects=0&d=1
Other pubblication related to these vulnerabilities:
http://packetstormsecurity.org/files/110048/ForkCMS-3.2.5-Cross-Site-Request-Forgery-Cross-Site-Scripting.html
http://www.exploit-db.com/exploits/18505/
http://secunia.com/advisories/48067
http://osvdb.org/show/osvdb/79444
http://xforce.iss.net/xforce/xfdb/73394
http://www.securelist.com/en/advisories/48067
www.1337day.com/exploits/17557
0 commenti Filed Under: 0day Vulnerabilities, Web Vulnerabilities
Cisco Linksys WAG54GS (ADSL Router) change admin password
http://www.exploit-db.com/exploits/18503/
http://packetstormsecurity.org/files/110040/Cisco-Linksys-WAG54GS-Cross-Site-Request-Forgery.html
http://www.securityfocus.com/bid/52105
You can simply modify this exploit in order to change other router's parameters.
Enjoy it!
0 commenti Filed Under: 0day Vulnerabilities, hardware, Web Vulnerabilities