2014-09-26

Contact Form 7 Integrations 1.0 - 1.3.10, Reflected XSS

The Contact Form 7 Integrations plugin for WordPress suffers from a Reflected XSS attack on a file which is included by the default plugin installation, named ‘includes/toAdmin.php’. If both the ‘uE’ and ‘uC’ QSAs are provided the input provided is...

2014-09-26

mod_jrun on Apache 2.4 (Ubuntu 14.04 + ColdFusion 9)

After updating my ColdFusion 9 development machine from Apache 2.2 to version 2.4, Apache simply refused to come back up. The root cause of this was the mod_jrun22 module complaining about a missing symbol. After some Googling, I found others...

2014-09-26

Easy MailChimp Forms 3.0 - 5.0.6, Persistent XSS

Due to exposing a single AJAX function to anonymous users by using the ‘nopriv’ method of adding AJAX actions, anonymous users are able to update the settings for this plugin, including updating the Custom Opt-In Message with HTML content. Utilizing...

2014-09-25

Infusionsoft Gravity Forms Add-on 1.5.3 - 1.5.10, Arbitrary File Upload

The Infusionsoft Gravity Forms Add-on plugin for WordPress has a script included in the default plugin installation which is intended to allow the user to re-generate certain templates, however there is no authentication required to access this...

2014-08-05

Wordpress Flash Uploader 3.1.2, Arbitrary Command Execution

Arbitary command execution. Requires authentication. A user with access to the settings panel to the WordPress Flash Uploader has the ability to execute arbitary shell commands via specially crafted form input. While it is true, that if an attacker...

2014-08-01

Gravity Upload Ajax 1.1, Arbitrary File Upload

Arbitrary file upload in Gravity Upload Ajax 1.1 allows remote unauthenticated user to upload files of any type. Provides the ability to upload a PHP shell.

Previous