| lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
|
Open Source and information security mailing list archives
| ||
|
Message-ID: <14833966e3c.f43a443960037.3741503082944933346@vexatioustendencies.com> Date: Mon, 01 Sep 2014 16:44:49 -0700 From: "Voxel@...ht" <voxelnight@...atioustendencies.com> To: <fulldisclosure@...lists.org> Subject: [FD] Wordpress Plugin Vulnerability Dump - Part 1 Multiple vulnerabilities in multiple plugins: Easy Media Gallery v1.2.59 - CSRF (leading to XSS) WP RSS Multi Importer v3.11 - CSRF Ready! Ecommerce v0.5.0 - CSRF, XSS Ready! Google Maps v1.1.5 - CSRF (leading to XSS) Ready! Coming Soon v0.5.0 - CSRF, XSS Contact Form v3.82 - (minor) CSRF WP Photo Album Plus v5.4.5 - XSS Details and POCs located: https://vexatioustendencies.com/wordpress-plugin-vulnerability-dump-part-1/ (Many) more to follow. -Voxel@...ht _______________________________________________ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Powered by blists - more mailing lists