23-10-2011
Overview of Serbian banks security vulnerabilities / 2011
details


30-06-2011
Http Parameter Contamination (HPC)
HTTP PARAMETER CONTAMINATION (HPC) original idea comes from the innovative approach found in HPP research by exploring deeper and exploiting strange behaviors in Web Server components, Web Applications and Browsers as a result of query string parameter contamination with reserved or non expected characters.

Download: HTTP PARAMETER CONTAMINATION (HPC)

details


19-05-2011
MDaemon WorldClient Email Subject Script Insertion Vulnerability
Input passed via the email subject is not properly sanitised before being used in the WorldClient Summary page. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is being viewed.

Details


details


11-04-2011
IT Dashboard "value" Cross-Site Scripting Vulnerability
Input passed to the "value" POST parameter in /sites/all/modules/contrib/datatables/dataTables/m
edia/examples_support/editable_ajax.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Details
 
 
details


24-11-2010
webApp.secure "Content-Length" Denial of Service Vulnerability
The vulnerability is caused due to a NULL pointer dereference error when handling errors and can be exploited to cause the process to crash via e.g. a large HTTP "Content-Length" header value.

details


01-09-2010
UltraVNC Viewer Insecure Library Loading Vulnerability
A vulnerability has been discovered in UltraVNC Viewer, which can be exploited by malicious people to compromise a user's system.


details


23-04-2010
GetSimple CMS Multiple Cross-Site Scripting Vulnerabilities
Input appended to the URL after admin/components.php, admin/resetpassword.php, admin/settings.php, admin/support.php, admin/theme-edit.php, and admin/theme.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in the context of an affected site.
 
 
details


  [1] 2 3 4