This is our version of SSL test tool mainly meant for your Internal assessment which you can't use famous online SSL labs scanner . We don't re-invent the wheel but combine all the best tools together with our own checks that we think other tools are missing. Running several tools each time has made us sick. With this Breacher tool, you will get all what you need. Version: 20141019 Download: http://yehg.net/lab/pr0js/tools/breacher-optimized.zip Price: Donationware Supported Checks Main SSL Checks ------------------------ 1. HeartBleed 2. ChangeCipherSpecs Injection 3. POODLE (due to SSLv3 support) 4. BEAST 5. BREACH 6. Lucky13 7. CRIME & TIME (If CRIME is detected, TIME will also be reported) 8. RC4 support 9. Forward Secrecy support 10. SSLv2 support 11. Weak ciphers check (LOW,ANON,NULL,EXPORT) 12. Insecure Renegotiation Certificate Validation Check ---------------------------------- 1. Certificate expiration 2. Insufficient public key-le
The Elgg 1.7.10 and lower versions are vulnerable to Cross Site Scripting and SQL Injection.
Elgg is an award-winning social networking engine, delivering the building blocks that enable businesses, schools, universities and associations to create their own fully-featured social networks and applications. Well-known Organizations with networks powered by Elgg include: Australian Government, British Government, Federal Canadian Government, MITRE, The World Bank, UNESCO, NASA, Stanford University, Johns Hopkins University and more (http://elgg.org/powering.php)
3. VULNERABILITY DESCRIPTION
The "internalname" parameter is not properly sanitized, which allows attacker to conduct Cross Site Scripting attack. This may allow an attacker to create a specially crafted URL that would execute arbitrary script code in a victim's browser. The "tag_names" is not properly sanitized, which allows attacker to conduct SQL Injection att