[Full-disclosure] Zabbix <= 1.8.1 SQL Injection

2010-04-01 Thread Dawid Golunski
= - Release date: April 1st, 2010 - Discovered by: Dawid Golunski - Severity: High = I. VULNERABILITY - Zabbix <= 1.8.1 SQL Injection II. BACKGROUND - Zabbix

[Full-disclosure] Invision Power Board <= 3.0.4 Local PHP File Inclusion and SQL Injection

2009-12-04 Thread Dawid Golunski
= - Release date: December 4th, 2009 - Discovered by: Dawid Golunski - Severity: Moderately High = I. VULNERABILITY - Invision Power Board <= 3.0.4 Local PHP File Inclusion and

Re: [Full-disclosure] ** FreeBSD local r00t zeroday

2009-12-01 Thread Dawid Golunski
Confirmed on FreeBSD 7.2-RELEASE (GENERIC). Dawid On 30 Nov 2009, at 22:12, Kingcope wrote: > ** FreeBSD local r00t 0day > Discovered & Exploited by Nikolaos Rangos also known as Kingcope. > Nov 2009 "BiG TiME" > > "Go fetch your FreeBSD r00tkitz" // http://www.youtube.com/watch?v=dDnhthI27Fg >

[Full-disclosure] WordPress <= 2.8.5 Unrestricted File Upload Arbitrary PHP Code Execution

2009-11-12 Thread Dawid Golunski
= - Release date: November 11th, 2009 - Discovered by: Dawid Golunski - Severity: Moderately High = I. VULNERABILITY - WordPress <= 2.8.5 Unrestricted File Upload Arbitrary PHP C