Newly added security tests, August 28, 2017: vBulletin and WordPress vulnerabilities

Newly added security tests, August 28, 2017: vBulletin and WordPress vulnerabilities

To help you keep up with the latest vulnerabilities, we add new security tests to Detectify on a regular basis. The latest additions to the tool cover everything from a vBulletin SQL injection to a DOM XSS in a WordPress.

Here are the new security tests that now run when you start a Detectify scan:

  • CVE-2016-6195 – Unauthenticated SQL Injection in VBulletin
  • PHP symfony debug toolbar disclosure
  • WordPress bridge-theme DOM XSS
  • Web Cache Deception updates

If you’d like to learn more about DOM XSS vulnerabilities, why not check out our write-up explaining how we invented the Tesla DOM DOOM XSS?

Happy scanning!
The Detectify Team


Source link

About Cybernoz

Security researcher and threat analyst with expertise in malware analysis and incident response.