HP Security Bulletin HPSBMU02830 SSRT100889 2 - A potential security vulnerability has been identified with HP Data Protector. This vulnerability could be locally exploited to allow an increase of privilege. Revision 2 of this advisory.
d31c0fd64bd23aa84b53b48a34166955482010fec5b0872d0ef36e0201d02251
This is a whitepaper called On WebSockets in Penetration Testing. It goes into detail discussing the vulnerability attack surface with WebSockets and the complications involved for penetration testing.
a8b8492359ecd117e96f3ad36d86915bffba40beab8909428765442c3848ab6b
D-Link DIR-635 suffers from cross site request forgery and multiple cross site scripting vulnerabilities.
9f5aeb25f45b5c7859957c04d42fa54170e29e93b7f0b36b152822e378687b11
WAF-FLE is a console for ModSecurity. It allows modsec administrators to view and search events logged by mlogc or mlog2waffle. The dashboard shows a graphical view of events, and when combined with the powerful drill-down filter allows quick searching for relevant events. Events can be viewed in detail, whether sent by one or many sensors.
f31029e3107c00a5828eaac9ee79751bd70f293a167bf45ae69647f29b31deb0
In module wpsio.dll in WPS Office, a BSTR string stored in the file is copied to the stack buffer without strict length inspection leading to a stack buffer overflow. Proof of concept included.
38358e22e0283cc8f63c3c5da968863cd9aeb2e6d05f82b21fb4a56fc9a8dd4e
This is a presentation that discusses low level exploitation such as stack buffer overflows, null pointer exceptions, etc. It offers decent examples and explanations.
cf8f57a23f2830b47616375181328e0335105ea381d3428a3f1e91d4ded96b96
This tool demonstrates how to decode Internet Explorer 7, 8 and 9 passwords. Win32 binary and source code included.
154f902b038e28989bd7e2d0c9a2631f3b724a69beba0004b9362dd04a64951a
Borland Silk Central version 12.1 TeeChart Pro active-x control suffers from an AddSeries remote code execution vulnerability.
3487efa60e709db37782fa39c6eb16e87b57eb70ce5b1c0251f9a7ceec7a159a
Borland Caliber version 11.0 Quiksoft EasyMail SMTP object suffers from buffer overflow vulnerabilities.
aae8950056570990cc0938976eec20957c20f9394f5b40c527b4b831ee1b5e5f
CMS Cameron McKenna 2013 suffers from a cross site scripting vulnerability. The vendor has been notified of this issue. Note that this advisory has site-specific information.
9bb471ef068545d2955c05c1c10076f6f1d8c862aa331fcdf79fbb9334231220