Saturday, 21 February 2015

2015羊年的新春對聯集錦 - 午馬未羊

beautiful-photos-13



2015羊年的新春對聯集錦 - 午馬未羊

上聯:馬馳萬裏 下聯:羊戀千山
上聯:羊肥馬壯 下聯:國富民豐
上聯:雲邊雁斷 下聯:隴上羊歸
上聯:壹元復始 下聯:萬象更新
上聯:材源茂盛 下聯:人壽年豐
上聯:四海生色 下聯:五湖呈祥
上聯:江山不老 下聯:神州永春
上聯:百花齊放 下聯:萬木爭榮
上聯:擡頭見喜 下聯:舉步生風
上聯:五金利市 下聯:萬象回春
上聯:國強民富 下聯:政通人和
上聯:人歡馬叫 下聯:春和景明
上聯:舉國安定 下聯:全民團結
上聯:春燕剪柳 下聯:喜鵲登梅
上聯:黨興軍旺 下聯:法嚴政明
上聯:君民義重 下聯:魚水情深
上聯:國家興旺 下聯:人民安康
上聯:海闊魚躍 下聯:天高鳥飛
上聯:鴻鵠得誌 下聯:桃李爭春
上聯:六畜興旺 下聯:五谷豐登
上聯:北鬥光明春臺起鳳 下聯:南溟壯闊羊角搏鵬
上聯:碧草白羊三春圖畫 下聯:金戈鐵馬萬裏征途
上聯:福鹿吉羊三元開泰 下聯:堯天舜日萬象更新
上聯:過佳節方知紅日暖 下聯:度陽春倍覺黨恩深
上聯:立誌當懷虎膽馳騁 下聯:求知莫畏羊腸扶搖
上聯:綠草如茵羊盈瑞氣 下聯:紅桃似火猴沐春風
上聯:時雨春風五羊獻穗 下聯:堯天舜日百鳳朝陽
上聯:送馬年春花融白雪 下聯:迎羊歲喜鵲鬧紅梅
上聯:萬象更新山青水秀 下聯:五羊獻瑞日麗春華
上聯:壹派生機陽春映日 下聯:滿天煥彩浩氣騰雲
上聯:倡廉反腐清風兩袖 下聯:知恥明榮正氣滿腔
上聯:春滿人間百花吐艷 下聯:福臨小院四季常安
上聯:佳節迎春春生笑臉 下聯:豐收報喜喜上眉梢
上聯:辭舊歲革除舊習慣 下聯:迎新春描繪新藍圖
上聯:發展安定團結形勢 下聯:完成經濟調整任務
上聯:錦繡前程千帆競渡 下聯:長征路上萬馬奔騰
上聯:壯誌淩雲紅心向黨 下聯:春風送暖瑞氣盈門
上聯:軍愛民同心幹四化 下聯:民擁軍並肩保國防
上聯:手握五尺嚴陣以待 下聯:胸懷四化眾誌成城
上聯:面向世界虛懷請教 下聯:腳踏實地循序漸進
上聯:萬象更新精神煥發 下聯:百花齊放春滿人間
上聯:服務周到群眾滿意 下聯:態度和善顧客稱心
上聯:萬紫千紅百花爭艷 下聯:五湖四海壹體同春
上聯:科學春天百花齊放 下聯:人間美景四化宏圖
上聯:加強社會主義法制 下聯:堅持人民民主專政
上聯:安定團結四海添喜 下聯:政策稱心五虎逢春
上聯:選賢任能唯才是舉 下聯:勵精圖治振興在望
上聯:炊煙裊裊 家家忙年飯 下聯:清風陣陣 處處樂新春
上聯:春回大地 形勢壹片好 下聯:香飄神州 風光無限新

Wednesday, 11 February 2015

CVE-2014-9560 Softbb.net SoftBB SQL Injection Security Vulnerabilities


deep-web-binary





Exploit Title: Softbb.net SoftBB /redir_last_post_list.php post Parameter SQL Injection
Product: SoftBB (mods)
Vendor: Softbb.net
Vulnerable Versions: v0.1.3
Tested Version: v0.1.3
Advisory Publication: Jan 10, 2015
Latest Update: Jan 10, 2015
Vulnerability Type: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
CVE Reference: CVE-2014-9560
CVSS Severity (version 2.0):
CVSS v2 Base Score: 7.5 (HIGH) (AV:N/AC:L/Au:N/C:P/I:P/A:P) (legend)
Impact Subscore: 6.4
Exploitability Subscore: 10.0 
Credit: Wang Jing [Mathematics, Nanyang Technological University (NTU), Singapore]






https://hackertopic.wordpress.com/2015/02/12/cve-2014-9560-softbb-net-softbb-sql-injection-security-vulnerabilities-2/






CVE-2014-9561 Softbb.net SoftBB XSS (Cross-Site Scripting) Security Vulnerability

binary-option-mobile-phone

Exploit Title: Softbb.net SoftBB /redir_last_post_list.php post Parameter XSS
Product: SoftBB (mods)
Vendor: Softbb.net
Vulnerable Versions: v0.1.3
Tested Version: v0.1.3
Advisory Publication: Jan 10, 2015
Latest Update: Jan 10, 2015
Vulnerability Type: Cross-Site Scripting [CWE-79]
CVE Reference: CVE-2014-9561
CVSS Severity (version 2.0):
CVSS v2 Base Score: 4.3 (MEDIUM) (AV:N/AC:M/Au:N/C:N/I:P/A:N) (legend)
Impact Subscore: 2.9
Exploitability Subscore: 8.6
Credit: Wang Jing [Mathematics, Nanyang Technological University (NTU), Singapore]


CVE-2014-7294 NYU OpenSSO Integration Open Redirect Security Vulnerability

examine_binary-300x215



Exploit Title: NYU OpenSSO Integration Logon Page url Parameter Open Redirect
Product: OpenSSO Integration
Vendor: NYU
Vulnerable Versions: 2.1 and probability prior
Tested Version: 2.1
Advisory Publication: DEC 29, 2014
Latest Update: DEC 29, 2014
Vulnerability Type: Open Redirect [CWE-601]
CVE Reference: CVE-2014-7294
CVSS v2 Base Score: 5.8 (MEDIUM) (AV:N/AC:M/Au:N/C:P/I:P/A:N) (legend)
Impact Subscore: 4.9
Exploitability Subscore: 8.6
Credit: Wang Jing [CCRG, Nanyang Technological University (NTU), Singapore]



http://www.inzeed.com/kaleidoscope/open-redirect/cve-2014-7294-nyu-opensso-integration-open-redirect-security-vulnerability/

CVE-2014-7293 NYU OpenSSO Integration XSS (Cross-Site Scripting) Security Vulnerability

Link-Building-Strategies2
Exploit Title: NYU OpenSSO Integration Logon Page url Parameter XSS
Product: OpenSSO Integration
Vendor: NYU
Vulnerable Versions: 2.1 and probability prior
Tested Version: 2.1
Advisory Publication: DEC 29, 2014
Latest Update: DEC 29, 2014
Vulnerability Type: Cross-Site Scripting [CWE-79]
CVE Reference: CVE-2014-7293
Risk Level: Medium
CVSS v2 Base Score: 4.3 (MEDIUM) (AV:N/AC:M/Au:N/C:N/I:P/A:N) (legend)
Credit: Wang Jing [CCRG, Nanyang Technological University (NTU), Singapore]



https://inzeed.wordpress.com/2015/02/10/cve-2014-7293-nyu-opensso-integration-xss-cross-site-scripting-security-vulnerability/


CVE-2014-8752 JCE-Tech "Video Niche Script" XSS (Cross-Site Scripting) Security Vulnerability

MIDI_188_computer_smart_phone_with_GPS_and_wifi_windows_mobile_6_1


Exploit Title: JCE-Tech "Video Niche Script" /view.php Multiple Parameters XSS
Product: "Video Niche Script"
Vendor: JCE-Tech
Vulnerable Versions: 4.0
Tested Version: 4.0
Advisory Publication: Nov 18, 2014
Latest Update: Nov 18, 2014
Vulnerability Type: Cross-Site Scripting [CWE-79]
CVE Reference: CVE-2014-8752
CVSS Severity (version 2.0):
CVSS v2 Base Score: 4.3 (MEDIUM) (AV:N/AC:M/Au:N/C:N/I:P/A:N) (legend)
Impact Subscore: 2.9
Exploitability Subscore: 8.6 
Credit: Wang Jing [CCRG, Nanyang Technological University, Singapore]

https://biyiniao.wordpress.com/2015/02/10/cve-2014-8752-jce-tech-video-niche-script-xss-cross-site-scripting-security-vulnerability/

CVE-2014-9558 SmartCMS Multiple SQL Injection Security Vulnerability











Exploit Title: Smartwebsites SmartCMS v.2 Multiple SQL Injection Security Vulnerabilities
Product: SmartCMS v.2
Vendor: Smartwebsites
Vulnerable Versions: v.2
Tested Version: v.2
Advisory Publication: Jan 22, 2015
Latest Update: Jan 22, 2015
Vulnerability Type: Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) (CWE-89)
CVE Reference: CVE-2014-9558
CVSS Severity (version 2.0):
CVSS v2 Base Score: 7.5 (HIGH) (AV:N/AC:L/Au:N/C:P/I:P/A:P) (legend)
Impact Subscore: 6.4
Exploitability Subscore: 10.0
Credit: Wang Jing [MAS, Nanyang Technological University (NTU), Singapore]


https://mathfas.wordpress.com/2015/02/11/cve-2014-9558-smartcms-multiple-sql-injection-security-vulnerability/