Security

Path traversal in Photo Gallery may allow admins to read most files on the filesystem (WordPress plugin)

CVE-2017-7620 Mantis Bug Tracker 1.3.10 / v2.3.0 CSRF Permalink Injection

SSD Advisory – Linux Kernel XFRM Privilege Escalation

SSD Advisory – Linux Kernel AF_PACKET Use-After-Free

SSD Advisory – Webmin Multiple Vulnerabilities

SSD Advisory – PHP Melody Multiple Vulnerabilities

DefenseCode ThunderScan SAST Advisory: WordPress Ad Widget Plugin Local File Inclusion Security Vulnerability

DefenseCode ThunderScan SAST Advisory: WordPress Simple Login Log Plugin Multiple SQL Injection Security Vulnerabilities

WordPress does not hash or expire wp_signups.activation_key allowing an attacker with SQL injection to create accounts

DefenseCode Security Advisory: Magento Commerce CSRF, Stored Cross Site Scripting #1

Exploit toolkit for CVE-2017-8759 – Microsoft .NET Framework RCE (Builder + listener + video tutorial)

DefenseCode ThunderScan SAST Advisory: WordPress PressForward Plugin Security Vulnerability

DefenseCode ThunderScan SAST Advisory: WordPress Podlove Podcast Publisher Plugin Security Vulnerability

DefenseCode ThunderScan SAST Advisory: WordPress Easy Modal Plugin Multiple Security Vulnerabilities

Stop User Enumeration allows user enumeration via the REST API (WordPress plugin)

nuovo regolamento europeo privacy gdpr

Nuovo regolamento europeo Privacy (GDPR)

Evento gratuito: Nuovo regolamento europeo Privacy (GDPR): quali impatti su enti e aziende?  

Defense in depth — the Microsoft way (part 48): privilege escalation for dummies — they didn’t make SUCH a stupid blunder?

Garanzia Assicurativa Cyber Risk

Garanzia Assicurativa Cyber Risk

Alla luce dei recenti attacchi informatici e dell’aumentare dei ransomware (come WannaCry e Petya) la Secure Online Desktop in collaborazione con Broker Busani Stefano di Union Brokers (vedi PRESENTAZIONE BROKER) è lieta di presentare la Garanzia Assicurativa Cyber Risk come valido strumento per aumentare la sicurezza dei propri dati.   Garanzia Assicurativa Cyber Risk – Descrizione La Garanzia Assicurativa Cyber Risk protegge il cliente anche…

Multiple Local Privilege Escalation Vulnerabilities in Acunetix Web Vulnerability Scanner 11

DefenseCode ThunderScan SAST Advisory: WordPress AffiliateWP Plugin Security Vulnerability

DefenseCode ThunderScan SAST Advisory: WordPress Huge-IT Video Gallery Plugin Security Vulnerability

Joomla com_tag v1.7.6 – (tag) SQL Injection Vulnerability

Qualys Security Advisory – CVE-2017-1000367 in Sudo’s get_process_ttyname() for Linux

Defense in depth — the Microsoft way (part 48): privilege escalation for dummies — they didn’t make SUCH a stupid blunder?

Microsoft Dynamic CRM 2016 – Cross-Site Scripting vulnerability

Executable installers are vulnerable^WEVIL (case 52): escalation of privilege with Microsoft’s .NET Framework installers

Reflected XSS in WordPress Download Manager could allow an attacker to do almost anything an admin can (WordPress plugin)

DefenseCode ThunderScan SAST Advisory: WordPress All In One Schema.org Rich Snippets Plugin Security Vulnerability

[CVE-2017-5868] OpenVPN Access Server : CRLF injection with Session fixation

Stealing Windows Credentials Using Google Chrome

WordPress EELV Newsletter v4.5 – Multiple Vulnerabilities

Ransomware e BaaS

Episodi come quello accaduto ieri ci ricordano sempre più l’importanza di avere un backup. Il Backup in Cloud può essere una valida contromisura ai Ransomware. http://www.tgcom24.mediaset.it/mondo/hacker-europol-cyberattacco-senza-precedenti-serve-indagine_3071352-201702a.shtml

DefenseCode ThunderScan SAST Advisory: GOOGLE google-api-php-client Multiple Security Vulnerabilities

DefenseCode WebScanner DAST Advisory: WordPress User Access Manager Plugin Security Vulnerability

DefenseCode ThunderScan SAST Advisory: WordPress Tracking Code Manager Plugin Multiple Security Vulnerabilities

CSRF in wordpress plugin clean login allows remote attacker change wordpress login redirect url or logout redirect url to evil address

DefenseCode ThunderScan SAST Advisory: WordPress WebDorado Gallery Plugin SQL Injection Vulnerability

DefenseCode ThunderScan SAST Advisory: WordPress Spider Event Calendar Plugin SQL Injection Vulnerability

DefenseCode ThunderScan SAST Advisory: WordPress Facebook Plugin SQL Injection Vulnerability

Two Factor Authentication

Autenticazione a due fattori

Autenticazione a due fattori Proteggi la tua area utente con l’autenticazione a due fattori di  Google Authenticator Ora puoi proteggere la tua Area utente mediante Google Authenticator, in questo modo aggiungerai un ulteriore livello di sicurezza al tuo account Cloud.   Autenticazione a due fattori Come abilitare Google Authenticator sul tuo account Secure Online Desktop 1 Accedi alla tua Area…

Let's Encrypt

Certificati Let’s Encrypt gratuiti per tutti gli utenti Webhosting

Let’s Encrypt è una Certification Authority gratuita, automatizzata e open. L’obiettivo di Let’s Encrypt e del protocollo ACME è quello di rendere possibile la realizzazione di un server HTTPS e di ottenere automaticamente un certificato attendibile per i browser senza nessun intervento umano. Questo viene realizzato grazie all’esecuzione di un agent di gestione dei certificati installato sul web server. Con il nostro server Webhosting basato sulla…

Cross-Site Scripting vulnerability in Trust Form WordPress Plugin

Cross-Site Scripting vulnerability in WP-SpamFree Anti-Spam WordPress Plugin

Popup by Supsystic WordPress plugin vulnerable to Cross-Site Request Forgery

Stored Cross-Site Scripting vulnerability in User Login Log WordPress Plugin

Cross-Site Request Forgery & Cross-Site Scripting in Contact Form Manager WordPress Plugin

Stored Cross-Site Scripting vulnerability in Contact Form WordPress Plugin

Remote file upload vulnerability in WordPress Plugin Mobile App Native 3.0

00000

Cross-Site Request Forgery in WordPress Press This function allows DoS

Persistent Cross-Site Scripting in the WordPress NewStatPress plugin

Cross-Site Request Forgery in Atahualpa WordPress Theme

Cross-Site Scripting in Magic Fields 1 WordPress Plugin

Cross-Site Scripting in Google Analytics Dashboard WordPress Plugin

WordPress Adminer plugin allows public (local) database login

Cross-Site Request Forgery in WordPress Download Manager Plugin

Simple Ads Manager WordPress plugin unauthenticated PHP Object injection vulnerability

Cross-Site Request Forgery in Global Content Blocks WordPress Plugin

Cross-Site Request Forgery in File Manager WordPress plugin

Cross-Site Scripting vulnerability in WP-Filebase Download Manager WordPress Plugin

Admin Custom Login WordPress plugin custom login page affected by persistent Cross-Site Scripting

Admin Custom Login WordPress plugin affected by persistent Cross-Site Scripting via Logo URL field

Analytics Stats Counter Statistics WordPress Plugin unauthenticated PHP Object injection vulnerability

WordPress Plugin Kama Click Counter 3.4.9 – Blind SQL Injection

WordPress Plugin Easy Table 1.6 – Persistent Cross-Site Scripting

Persistent Cross-Site Scripting vulnerability in User Access Manager WordPress Plugin

Multiple blind SQL injection vulnerabilities in FormBuilder WordPress Plugin

Cross-Site Request Forgery vulnerability in FormBuilder WordPress Plugin allows plugin permissions modification

CMS Commander Client WordPress Plugin unauthenticated PHP Object injection vulnerability

Google Forms WordPress Plugin unauthenticated PHP Object injection vulnerability

New exploit for new vulnerability in WordPress Plugin + tutorial

Nginx (Debian-based + Gentoo distros) – Root Privilege Escalation [CVE-2016-1247 UPDATE]

Multiple vulnerabilities in cPanel <= 60.0.34

Stop User Enumeration does not stop user enumeration (WordPress plugin)

Zend Framework / zend-mail < 2.4.11 Remote Code Execution (CVE-2016-10034)

MySQL / MariaDB / PerconaDB – Privilege Escalation / Race Condition Exploit [CVE-2016-6663 / OCVE-2016-5616]

Cross-Site Scripting in Check Email WordPress Plugin

Cross-Site Scripting in All In One WP Security & Firewall WordPress Plugin

Nginx (Debian-based distros) – Root Privilege Escalation Vulnerability (CVE-2016-1247)

Stored Cross-Site Scripting vulnerability in 404 to 301 WordPress Plugin

Cross-Site Scripting in Calendar WordPress Plugin

Cross-Site Scripting vulnerability in Caldera Forms WordPress Plugin

Cross-Site Scripting vulnerability in Quotes Collection WordPress Plugin

MySQL / MariaDB / PerconaDB – Root Privilege Escalation Exploit ( CVE-2016-6664 / CVE-2016-5617 )

[oss-security] CVE request:Lynx invalid URL parsing with ‘?’

Iscriviti via RSS

Piu’ articoli…

Categorie …

Newsletter

Tags

z35W7z4v9z8w

Customers

Newsletter