PHP import_request_variables() arbitrary variable overwrite

Comments (1)

Php Nuke “wild” POST XSS

To demonstrate the import_request_variables() bug i’ve exploited a XSS flaw in PHP NUKE 8.0 that has an anti-CSRF routine. The import_request_variables() vulnerability will permit you to exploit a wide range of vectors (XSS, remote file inclusion, remote code execution, SQL injections, etc.) on software that makes use of it.

Leave a Comment

Bad url redirections (AKA: Many thanks to our partners!)

Leave a Comment

Pseudo threading with BASH

Leave a Comment

Adobe Acrobat Reader Plugin: Multiple Vulnerabilities

Leave a Comment

Adobe Acrobat Reader Plugin: Multiple Vulnerabilities

Leave a Comment

EXIF Phun

Non so se avete letto il recente post di Tonu Samuel riguardo EXIF nelle jpeg, si e’ costruito un crawler e adesso sta facendo statistiche.

Praticamente le fotocamere si salvano un’anteprima e alcuni tag assieme all’immagine canonica. Piu’ o meno sapevo che le immagini si portavano dietro dei metadati ma non mi ero mai addentrato nell’argomento.

Leave a Comment

Translazioni open source a verona

Leave a Comment

n3td3v and infosecbofh quotes on fd aka full disclosure

Leave a Comment

Free Web Stat Multiple XSS Vulnerabilities

Leave a Comment

Older Posts »