[Full-disclosure] Web App Sec: (AT&T Corporation) former American Telecommunication & Telegraph Vulnerabilities (Cross-Site Scripting / OWASP Top 10)

2014-02-27 Thread Nicholas Lemonias.
_ .___ _ / _ \ | |/ _/ / /_\ \| |\_ \ /|\ |/\ \|__ /___/___ / \/\/ Corporation Published Report: 27/02/2014 Credits: Advanced Information Security Corporation, USA Severity: High/Critical (OWASP TOP 10) Ty

[Full-disclosure] Update: CVE-2014-0053 Information Disclosure when using Grails

2014-02-27 Thread Pivotal Security Team
CVE-2014-0053 Information Disclosure in Grails applications Severity: Important Vendor: Grails by Pivotal Product Affected: - Grails Resources plugin 1.0.0 to 1.2.5 Products known to depend on the affected product: - Grails 2.0.0 to 2.3.6 Description: The Grails resources plug-in, a default d

[Full-disclosure] Telekom Bug Bounty #12 - File Include Web Vulnerability

2014-02-27 Thread Vulnerability Lab
Document Title: === Telekom Bug Bounty #12 - File Include Web Vulnerability References (Source): http://www.vulnerability-lab.com/get_content.php?id=1178 Release Date: = 2014-02-27 Vulnerability Laboratory ID (VL-ID): ==

[Full-disclosure] Bluetooth Photo Share Pro v2.0 iOS - Multiple Vulnerabilities

2014-02-27 Thread Vulnerability Lab
Document Title: === Bluetooth Photo Share Pro v2.0 iOS - Multiple Vulnerabilities References (Source): http://www.vulnerability-lab.com/get_content.php?id=1218 Release Date: = 2014-02-27 Vulnerability Laboratory ID (VL-ID):

[Full-disclosure] SEC Consult SA-20140227-0 :: Local Buffer Overflow vulnerability in SAS for Windows (Statistical Analysis System)

2014-02-27 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20140227-0 > === title: Local Buffer Overflow vulnerability product: SAS for Windows (Statistical Analysis System) vulnerable version: SAS 9.2, 9