ICNA

Iranian Cyber News Agency

Vulnerability

Iran Cyber Security Group WordPress Theme XSS Discovery

Hackers of Iran Cyber Security Group have discover new cross-site scripting -XSS- bug in a WordPress theme: WordPress ThemeRush Theme Details of bug is here: https://cxsecurity.com/issue/WLB-2016110161 Author : Iran Cyber Security Group -By C10N3R Se7eN- email: [email protected] Greetz & contact: Greetz To…

Iranonymous Find SQLi, Admin Page Bypass & Ajax File Download Bugs

Hackers of security group Iranonymous -Iranian Anonymous- have discover new file download admin page bypass and SQL Injection bugs: WordPress Plugin N-Media 1.4 Arbitrary File Download Vulnerability faracorp design Sql injection Vulnerability WordPress Plugin N-Media 1.4 Arbitrary File Download Vulnerability The…

Ashiyane DST Discover WordPress Userpro Remote File Upload Bug

Userpro Wordpress Userpro Remote File Upload Security researchers at Iranian team Ashiyane Digital Security Team have discover remote file upload vulnerability in Wordpress -Google Dork: inurl:/wp-content/plugins/userpro/- Vulnerability risk is rated as high by cxsecurity.com This module -requires using Metasploit- exploits an arbitrary…

Gray Hat Group Find Pixel2URL XSS Bug

Hacker MR.BL4CK of Gray Hat Group have discover new bug: Pixel2URL Cross Site Scripting -XSS- XSS -Cross Site Scripting- is type of computer security vulnerability found in web applications enable attackers to inject client-sides script into web pages viewed by other users Vendor is: http://pixel2url.com/ Greetz…

Termint Team Find resane-pardaz SQLi Bug

Iranian Hackers of famous Termint Team is make discover of SQL Injection bug: Termint Team Find resane-pardaz SQL injection Bug Details is here: https://cxsecurity.com/issue/WLB-2016090177 SQLi -SQL injection- is code injection technique used to attack data application have malicious SQL statements is inserted into entry fields…

Ashiyane DST Discover Google Docs XSPA/SSRF

Iranian hackers of Ashiyane Digital Security Team is make discover of XSPA/SSRF -Cross Site Port Attack/Server Side Request Forgery- vulnerability in Google Docs The vulnerability is find by Ehsan Hosseini , V For Vendetta , Und3rgr0und Author: Ashiyane Digital Security Team Vendor…

ICSG Discover Easy File Sharing Web Server Buffer Overflow

Hackers of the Iran Cyber Security Group -ICSG- have discover buffer overflow in web applications: Easy File Sharing Web Server 7.2 SEH Buffer Overflow (EggHunter) Vendor Homepage: http://www.sharing-file.com Software Link: http://www.sharing-file.com/efssetup.exe Exploit link: https://cxsecurity.com/issue/WLB-2016090019 Iran Cyber Security Group say: Discovered…

Linux Professional Institute Has LFP Bug

This filesystem vulnerability in website of Linux Professional Institute Inc. (LPI) was discovered by Nafiseh Hosseinzadeh under the name N_H and she reported her discovery on reputable foreign website CXSecurity.com. In many other countries including U.S. and European countries work…

American University Washington XSS Vulnerability

Iranian researcher And hacker 4TT4CK3R is make discover of XSS bug: American University Washington XSS Vulnerability 4TT4CK3R is find vulnerability in search feature of website which is law school of American University Washington Home Page of American University Washington: http://american.edu Vuln…

sir.h4m1d Find Admin Bypass Scripts Payment Gateway Bug

Hackers from the Iran Cyber Security Group is make discover of way to bypass access to payment gateways sir.h4m1d of Iran Cyber Security Group is make discover: Admin Bypass Scripts Payment Gateway Full detail is here is show that bypass is…