ush.it
ush.it - a beautiful place
http://www.ush.it/free-services/fortune
Ushit - a beautiful place. October 10, 2005 at 7:00 pm - 44 words, reading time 0 minutes. Following this link you can download the complete database dump or the php generator, also structure-only dump is proveded, enjoy! Need professional Information Security services? Scripts & Classes. Encoding and decoding in 14 formats.
ush.it
ush.it - a beautiful place
http://www.ush.it/2011/04/07/pixelpost-(calendar-addon-116)-173-multiple-vulnerabilities
Ushit - a beautiful place. Pixelpost (Calendar addon 1.1.6) 1.7.3 Multiple vulnerabilities. April 7, 2011 at 5:46 pm - Filed under aa, bb - 1033 words, reading time 3 minutes - Permalink. Curr month=4&curr year=2011&showimage=3&category=10' AND '1'='1 http:/ www.example.com/pixelpost/index.php? Need professional Information Security services? Scripts & Classes. Encoding and decoding in 14 formats.
ush.it
ush.it - a beautiful place
http://www.ush.it/2009/06/13/sugarcrm-520e-remote-code-execution
Ushit - a beautiful place. SugarCRM 5.2.0e Remote Code Execution. June 13, 2009 at 6:44 pm - Filed under aa, bb - 1524 words, reading time 5 minutes - Permalink. Some time ago we found a way to trick the email attachment validation code of SugarCRM leading to arbitrary file uploads. The bypass is quite interesting: don't give up against filename validation routines! Need professional Information Security services? Scripts & Classes. Encoding and decoding in 14 formats.
ush.it
ush.it - a beautiful place
http://www.ush.it/2009/10/25/jetty-6x-and-7x-multiple-vulnerabilities
Ushit - a beautiful place. Jetty 6.x and 7.x Multiple Vulnerabilities. October 25, 2009 at 5:00 am - Filed under aa, bb - 2607 words, reading time 8 minutes - Permalink. Null & name.length() 0) { Cookie cookie = new Cookie(name,value); if (age! Null & age.length() 0) cookie.setMaxAge(Integer.parseInt(age) ; response.addCookie(cookie); } } - 8 - 8 - 8 - 8 - 8 - 8 - 8 - 8 - 8 - 8 - 8 - 8 - 8 - 8 - 8 - 8 - 8 - The problem also exists for other demo pages, see for example the "/test/jsp/expr&...Name=CVE-2003...
ush.it
ush.it - a beautiful place
http://www.ush.it/2012/11/22/arc-v2011-12-01-multiple-vulnerabilities
Ushit - a beautiful place. ARC v2011-12-01 Multiple vulnerabilities. November 22, 2012 at 11:34 am - Filed under aa, bb - 1408 words, reading time 4 minutes - Permalink. Simone "negator" Onofri and Luca "beinux3" Napolitano found multiple issues in ARC2, providing RDF and SPARQL functionalities to PHP applications and working with MySQL as backend. Found vulnerabilities include SQL Injection and XSS. User iam:user lol*/ OR (SELECT sleep(5) =1- ? Need professional Information Security services?
wisec.it
Wisec - The WIse SECurity
http://www.wisec.it/index.php
Flash Application Testing: A New Vector for XSS and Cross Site Flashing. IE and Firefox Digest Authentication Request Splitting. Php import req var globals overwrite Advisory. Subverting Ajax - The Paper. Adobe Plugin Multiple Vulnerabilities. Wisec@23rd.CCC Congress in Berlin - 29th Dec. 2006 - Subverting Ajax. SecSearch. Search Engine for Security Community. Mysql COM TABLE DUMP Flaws. Mysql Anonymous login Flaw. A new project to stop embed passwords in Php scripts: PassBroker. PHP shmop safemode bypass.
ush.it
ush.it - a beautiful place
http://www.ush.it/2009/05/12/formmail-192-multiple-vulnerabilities
Ushit - a beautiful place. FormMail 1.92 Multiple Vulnerabilities. May 12, 2009 at 4:19 am - Filed under aa, bb - 1928 words, reading time 6 minutes - Permalink. Do you remember FormMail? Recipient=foobar@ush.it&subject=1&redire ct=javascript:alert(%27USH%27); Response: $ curl -kis "http:/ 127.0.0.1/FormMail.pl? Recipient=foobar@ush.it&sub ject=1&redirect=http:/ www.example.com%0D%0aSet-Cookie:auth%3DUSH;vuln%3 DHTTPHeaderInjection;" Can be verified with the obvious "javascript:alert(document...Recipient...
ush.it
ush.it - a beautiful place
http://www.ush.it/2009/03/03/zabbix-162-frontend-multiple-vulnerabilities
Ushit - a beautiful place. Zabbix 1.6.2 Frontend Multiple Vulnerabilities. March 3, 2009 at 9:10 pm - Filed under aa, bb - 1792 words, reading time 5 minutes - Permalink. Multiple Vulnerabilities exist in Zabbix front end software ranging from Remote Code Execution (RCE), to Cross Site Request Forgery (CSRF) and Local File Inclusion (LFI). Isset($ REQUEST[$field]) return FALSE; if(zbx strstr($expression,"{}") &! Config=0&save&alias=alias&name=foo&surname=foo&user type=3& lang=lang&theme=theme&autologout=...
ush.it
ush.it - a beautiful place
http://www.ush.it/2010/11/16/vtiger-crm-520-multiple-vulnerabilities
Ushit - a beautiful place. Vtiger CRM 5.2.0 Multiple Vulnerabilities. November 16, 2010 at 10:46 pm - Filed under aa, bb - 1279 words, reading time 4 minutes - Permalink. Need professional Information Security services? Scripts & Classes. Encoding and decoding in 14 formats.