Arbitrary File Upload in '1 Flash Gallery' Wordpress Plugin

2011-09-07 Thread supernothing
Vulnerability The '1 Flash Gallery' WordPress plugin (http://wordpress.org/extend/plugins/1-flash-gallery/) is vulnerable to an arbitrary file upload vulnerability. This vulnerability is present from version 1.30 until version 1.5.7. The plugin has been downloaded an estimated 460,000

Remote Password Disclosure Vulnerability in RXS-3211 IP Camera + others

2011-05-25 Thread supernothing
-==Description==- The RXS-3211 IP camera, among others, is vulnerable to remote password disclosure, which can be exploited by an unauthenticated attacker with a single UDP packet. The problem exists in the camera management protocol used by the devices, which sends the administrator password a