WordPress CK-And-SyntaxHighLighter Arbitrary File Upload
Announce finding by Hekt0r – member of Iran Security Group- of discovering vulnerability -Wordpress ck-and-syntaxhighlighter Plugin Remote File Upload vulnerability- Remote File Inclusion allows an attacker to include a remote file, usually through a script on the web server. The…
Hekt0r Discovers J&W CMS SQL Vulnerability
Member of Iran Security Group, Hekt0r, discovered SQL Injection Vulnerability in J&W Communications CMS program. J&W Communications CMS program website is www.jw-com.com Credits from Hekt0r were: [+] Special Thanks: Root SmasheR, Mr.Moein, UmPire, Ali Ahmady, Saeed.Jok3r M4hdi, Black Hacker, Vahid…
Multiple CMS Vulnerabilities Discovered By IEDB
Security team Iranian Exploit Database – IEDB – and team IrIsT has discovered multiple vulnerabilities in CMS software by NeginGroup and rasanehpardaz. NeginGroup CMS has vulnerability of SQL injection and cross-site scripting – XSS. Rasanehpardaz CMS has vulnerability of only…
Tonel Team Discover SOFTWeb SQL Vulnerability
New SQL vulnerability in SOFTWeb Cmd has been discovered by Iranian security team Tonel Team. SOFTWeb Adaptive I.T. Solutions® is an innovative company that specializes in web – mobile application development and delivery of integrated technology services. Vulnerability discovered by…
Grey Hat Boys Discover Full Path Disclosure Vulnerabilities
Iranian security team Grey Hat Boys have discovered Full Path Disclosure – FPD – vulnerabilities in three different web software. OpenCart 1.5.4, WordPress wp-shopping-cart and CMSMadeSimple version 1.11.10 are found vulnerable by Grey Hat Boys. Full Path Disclosure vulnerabilities enable…
MyBB Heartbleed Exploit By E2MA3N
Iranian security researcher E2MA3N has made MyBB exploit program for Heartbleed vulnerability. E2MA3N in cooperation with Red Hat Hackers – RHH – made a small program to use on vulnerability CVE-2014-0160. Vulnerability CVE-2014-0160 or Heartbleed: The (1) TLS and (2)…
XSS Vulnerability In Pentagon Website By Dr.3v1l
Website of US military Pentagon Channel has discovered to contain cross-site scripting – XSS – vulnerability by Iranian hacker Dr.3v1l. XSS enables attackers to inject client-side script into Web pages viewed by other users. Dr.3v1l discovered and used vulnerability safely to prove…
Iran Security Group Discover XSS In Blogger CMS AR LoxBlog
Black V!per of Iran Security Group discover cross-site scripting – XSS – flaw on in common Blogger CMS platform LoxBlog. Black V!per showed kind and responsible act by contacting admin of LoxBlog to tell of bug with blog instead of…
M-tech SQL Injection Vulnerability Discovered by Tir3x
Iranian hacker Tir3x has discovered SQL vulnerability in M-tech software. Vulnerability allows SQL injection of M-tech web application software and has been tested on Windows and Linux.
Multiple ZenCart Vulnerabilities Discovered By UmPire
Iran Security Group member UmPire discovered multiple vulnerabilities in ZenCart software. Vulnerabilities include: – Cross Site Scripting Vulnerability – Full Path Disclosure – Sensitive phpinfo reading UmPire left greeting message: By UmPire from Iran Security Group(I.S.G) Tnx To: Root.Smasher|Black V!per|Mr.Moein|UmPire|Sultan Brain|Alireza_Promis M4hdi|Social Engineer|TaK.FaNaR|hack3core









