XSS

Pierluigi Paganini June 18, 2015
Exclusive – Voidsec disclosed a number of flaws affecting Minds.com Platform

Security expert at Voidsec have analyzed the popular social networking minds.com disclosing a number of security vulnerabilities. Security expert at Voidsec, Paolo Stagno ( aka voidsec – [email protected] ) and Luca Poletti ( aka kalup – [email protected] ), have analyzed the popular social networking platform minds.com that is getting attention by media because it aims to give transparency and protection to user […]

Pierluigi Paganini April 27, 2015
WordPress fixed a Zero Day a few hours after its disclosure

WordPress has just released a critical update to fix a serious XSS vulnerability that allows attackers to easily hijack websites based on the popular CMS. A cross-site scripting vulnerability is threatening WordPress content management system platforms worldwide. The popular CMS is used by nearly 186,700 of the top one million websites. An attacker can exploit the […]

Pierluigi Paganini March 24, 2015
Adobe CVE-2011-2461 flaw is exploitable by 4 years although it was fixed

Security experts discovered that the Adobe CVE-2011-2461 vulnerability is exploitable by at least four years despite the company has issued a patch. Four years ago Adobe released a patch for the vulnerability CVE-2011-2461 that was affecting the Adobe Flex SDK 3.x and 4.x. The flaw was a cross-site scripting (XSS) vulnerability that allowed remote attackers to inject arbitrary […]

Pierluigi Paganini March 23, 2015
Ghost blogging platform affected by multiple vulnerabilities

A group of researchers from Voidsec have found six vulnerabilities in the Ghost blogging platform that allow privilege editing and DoS. Six vulnerabilities have been found affecting Ghost, the blogging platform coded in the Node.js born on October 2013. These vulnerability were discovered on January 26 by a group of researcher from Voidsec (voidsec, bughardy […]

Pierluigi Paganini February 13, 2015
How to remotely install malicious apps on Android devices

Security researchers discovered how to install and launch malicious applications remotely on Android devices exploiting two flaws. Security researchers have uncovered a couple of vulnerabilities in the Google Play Store that could allow cyber criminals to install and launch malicious apps remotely on Android mobile devices. The expert Tod Beardsley, technical lead for the Metasploit […]

Pierluigi Paganini February 04, 2015
Severe XSS flaw affects fully patched Internet Explorer

Security experts discovered a new severe XSS flaw affects fully patched Internet Explorer and exposes users to risks of attacks and identity theft. A new critical cross-site scripting (XSS) vulnerability affects fully patched versions of Internet Explorer, the flaw could be exploited by hackers to steal user sensitive data (i.e. login credentials) and inject malicious […]

Pierluigi Paganini February 03, 2015
About.com affected by XSS, XFS, Open Redirect Vulnerabilities since October 2014

The popular website About.com is affected by numerous security flaws that expose its users to XSS, XFS, Open Redirect attacks since October 2014. Wang Jing, a PhD student at the Nanyang Technological University in Singapore has discovered that the majority of the web page of About.com are vulnerable different types of attacks, including cross-site scripting […]

Pierluigi Paganini December 19, 2014
Several critical security vulnerabilities affect the Glassdoor website

The security expert  Mohamed M.Fouad discovered several critical security vulnerabilities at Glassdoor, which can lead to very harmful impact on all users. The Independent Security Researcher Mohamed M.Fouad has discovered  a lot of critical security vulnerabilities at Glassdoor that could lead to very harmful impact on all users.  Mohamed M.Fouad an Independent Security Researcher from Egypt. I […]

Pierluigi Paganini December 14, 2013
Google Vulnerabilities out of bounty program, how is it possible?

Experts at Hacker Online Club published a post on Google vulnerabilities that are currently not under bug bounty program of the company. Today I desire to propose the information on Un-patched Google Vulnerabilities  published on the web site Hackers Online Club trying to understand a hacker how could exploit them. The first Google Vulnerability is a […]

Pierluigi Paganini November 23, 2013
Hacking Google Gmail accounts exploiting password reset system flaw

Security researcher Oren Hafif demonstrated how to hack a Google Gmail account exploiting a serious flaw in the password reset process. A serious vulnerability in the password reset process of Google account allows an attacker to hijack any account, this is the sensational discovery made by security researchers Oren Hafif. “that password recovery is often in […]