Cross-site scripting (XSS) vulnerability in editText.php in WonderCMS before 0.4 allows remote attackers to inject arbitrary web script or HTML via the content parameter.
Monthly Archives: January 2015
CVE-2011-5318
Multiple cross-site request forgery (CSRF) vulnerabilities in diafan.CMS before 5.1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify articles via a save_post action to admin/news/saveNEWS_ID/, (2) modify settings via a save_post action to admin/site/save2/, or (3) modify credentials via a save_post action to admin/usersite/save2/.
Digital Whisper Electronic Magazine #57
Digital Whisper Electronic Magazine issue 57. Written in Hebrew.
Sony execs turned to old BlackBerries from basement in wake of attack
Sony executives turned to old BlackBerries found in a basement in the firm’s California headquarters in, using SMS text messages and a ‘phone tree’ to communicate in the wake of the attack.
The post Sony execs turned to old BlackBerries from basement in wake of attack appeared first on We Live Security.
Nvidia breach – employee information leaks
Graphics card company Nvidia suffered a data breach in which private employee information was leaked, the company has revealed.
The post Nvidia breach – employee information leaks appeared first on We Live Security.
Bugtraq: [KIS-2014-15] Osclass <= 3.4.2 (ajax.php) Local File Inclusion Vulnerability
[KIS-2014-15] Osclass <= 3.4.2 (ajax.php) Local File Inclusion Vulnerability
Bugtraq: [KIS-2014-16] Osclass <= 3.4.2 (contact.php) Unrestricted File Upload Vulnerability
[KIS-2014-16] Osclass <= 3.4.2 (contact.php) Unrestricted File Upload Vulnerability
Bugtraq: [KIS-2014-18] Mantis Bug Tracker <= 1.2.17 (ImportXml.php) PHP Code Injection Vulnerability
[KIS-2014-18] Mantis Bug Tracker <= 1.2.17 (ImportXml.php) PHP Code Injection Vulnerability
Bugtraq: [KIS-2014-19] Symantec Web Gateway <= 5.2.1 (restore.php) OS Command Injection Vulnerability
[KIS-2014-19] Symantec Web Gateway <= 5.2.1 (restore.php) OS Command Injection Vulnerability
GLSA 201412-53 (Normal): mit-krb5
MIT Kerberos 5: User-assisted execution of arbitrary code