FlatPress 0.804-0.812.1 Local File Inclusion to Remote Command Execution

2009-09-29 Thread Giuseppe Fuggiano
Security Advisory - FlatPress 0.804-0.812.1 Local File Inclusion to Remote Command Execution Researcher Information -- Discovered by: Giuseppe `Zmax` Fuggiano Website: http://www.giusef.net Contact: giuseppe(dot)fuggiano(at)gmail(dot)com Product Information -

Adobe Photoshop Elements 8.0 Active File Monitor Service Bad Security Descriptor Local Elevation Of Privileges

2009-09-29 Thread nospam
Adobe Photoshop Elements 8.0 Active File Monitor Service Bad Security Descriptor Local Elevation Of Privileges by Nine:Situations:Group::bellick site: http://retrogod.altervista.org/ Tested on Microsoft Windows XP SP3 The "Adobe Active File Monitor V8" service is installed with an improper secu

Re: iphone email client does not validate ssl certificates

2009-09-29 Thread Steve Shockley
On 9/26/2009 5:54 AM, Pavel Machek wrote: Well... mujmail.org email client also does not validate ssl cerificates -- optionaly. Reasoning is that SSL with unverified certificate is still better than sending plaintext passwords. Does that count as a vulnerability? Yes; it's not that difficult f

WinRAR v3.80 - ZIP Filename Spoofing

2009-09-29 Thread chr1x
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ++ | ...| | ..''xxx'...| |..'xx