Vulnerabilities in developer.apple.com
Posted by YGN Ethical Hacker Group on Jul 01Vulnerabilities via URL Redirector in developer.apple.com
1. VULNERABILITY DESCRIPTION
Arbitrary URL Redirect
======================
POC (Browsers: All)
https://developer.apple.com/membercenter/urlRedirect.action?fullURL=http://attacker.in/malware_exists_in_this_page
Issue References:
OWASP Top 10 A10...
Mini PHP Shell 27.9 V2 Released
Mini PHP Shell 27.9 V2 Released
According to Developer jos_ali_joe and "This is a continuation of PHP Shell Mini 27.9 V1 , Editing Shell...
SoftMP3 SQL Injection
SoftMP3 suffers from a remote SQL injection vulnerability.
Source: SoftMP3 SQL Injection
www.wattpad.com XSS
ant4g0nist has discovered a vulnerability in www.wattpad.com, which could be exploited by malicious people to conduct XSS attacks.
Source: www.wattpad.com XSS
Clipbucket 2.4 RC2 645 SQL Injection
A SQL injection vulnerability in Clipbucket version 2.4 RC2 645 can be exploited to extract arbitrary data. In some environments it may be possible...
[local] – Free MP3 CD Ripper 1.1 Universal DEP Bypass Exploit
Source: - Free MP3 CD Ripper 1.1 Universal DEP Bypass Exploit
Windows Antihazard Helper
Windows Antihazard Helper is a fake Antivirus. This rogue displays fake alerts to scare users. It replaces Windows AntiHazard Center, Windows Process Director, Windows...
[webapps] – D-Link DSL-526B ADSL2+ AU_2.01 – Unauthenticated Remote DNS Change
D-Link DSL-526B ADSL2+ AU_2.01 - Unauthenticated Remote DNS Change
Source: - D-Link DSL-526B ADSL2+ AU_2.01 - Unauthenticated Remote DNS Change
Old Dogs And New Tricks: Do You Know Where Your Handles Are?
This paper offers incremental research in the area of untrusted program input via synchronization handle manipulations. Unlike the Michal Zalewski paper on Delivering Signals...
Facebook Session Sidejacking
A session sidejacking vulnerability was discovered in Facebook.com.
Source: Facebook Session Sidejacking


