May 2017 Summaries
2 posts from Detectify
Filter
Month:
Year:
Post Summaries
Back to Blog
Detectify, a security service tool, is regularly updated to ensure users are protected against the latest threats. Recent additions to its security tests include vulnerabilities such as CVE-2017-5614, an open redirect issue in cgiemail, CVE-2017-5615, which involves HTTP response splitting in cgiemail, and CVE-2017-5616, a reflected XSS vulnerability in cgiemail. The tool also addresses WordPress vulnerabilities, including CVE-2017-8295, an unauthorized password reset, CVE-2016-10033, a remote code execution (RCE), and issues like XSS in tracking-code-manager, unauthenticated log download in download-monitor, and CSRF vulnerabilities in plugin-organizer and clean-login.
May 11, 2017
70 words in the original blog post.
Detectify Crowdsource, a security platform launched six months ago, has engaged ethical hackers worldwide to enhance internet security by identifying vulnerabilities that affect multiple websites. The platform operates like a bug bounty program, with submissions reviewed and incorporated into Detectify's scanner, which has resulted in over 4,000 hits on various vulnerabilities, including remote code execution, SQL injection, cross-site scripting, and more. With a 75% acceptance rate for nearly 200 submissions, the majority of findings have been related to WordPress vulnerabilities, followed by Joomla!, Drupal, and Magento. Crowdsource emphasizes a diverse community of researchers, each with unique styles and focuses, and aims to continue expanding its network of skilled hackers to maintain a cutting-edge security scanner. Noteworthy contributions include a 14-year-old guest blogger's discovery of a stored XSS vulnerability, highlighting the platform's potential for significant impact.
May 03, 2017
489 words in the original blog post.