On Windows 8.1 update the system call NtApphelpCacheControl (the code is actually in ahcache.sys) allows application compatibility data to be cached for quick reuse when new processes are created. A normal user can query the cache but cannot add new cached entries as the operation is restricted to administrators. This is checked in the function AhcVerifyAdminContext. This function has a vulnerability where it doesn't correctly check the impersonation token of the caller to determine if the user is an administrator. This is the proof of concept code.
4387300ba77e15e0631150dc8f5e6d6796881e5dae56738966df02c9bed1bbf8
Debian Linux Security Advisory 3117-1 - Several vulnerabilities were found in PHP, a general-purpose scripting language commonly used for web application development.
7d72e3f4f47e027cbf3343d2b8bfa07020b1d96f4c460ba3076f76640b61a190
Cookie Manager is a cookie stealer for XSS to find and mint cookies using PHP.
756e791982a5216ef6c867d101ff896b06fba5694e0cfe949c6033c90b6ab4bb
Digital Whisper Electronic Magazine issue 57. Written in Hebrew.
efc2c9a1b7dc5a137767e933136cb01aaa0bca7df0a32a03e8f4b38a253b49f0