Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it easier for remote attackers to obtain access via unspecified vectors.
Monthly Archives: February 2015
CVE-2015-1456
Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which allows remote administrators to obtain sensitive information by reading the log at debug/startup/.
CVE-2015-1457
Fortinet FortiAuthenticator 3.0.0 allows local users to read arbitrary files via the -f flag to the dig command.
CVE-2015-1458
Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privileges by creating /tmp/privexec/dbgcore_enable_shell_access and executing the “shell” command.
CVE-2015-1459
Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the operation parameter to cert/scep/.
CVE-2015-1460
Huawei Quidway switches with firmware before V200R005C00SPC300 allows remote attackers to gain privileges via a crafted packet.
CVE-2015-1461 (clamav, fedora)
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda’s crypter or (2) mew packer file, related to a “heap out of bounds condition.”
CVE-2015-1462 (clamav, fedora)
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upx packer file, related to a “heap out of bounds condition.”
CVE-2015-1463 (clamav, fedora)
ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an “incorrect compiler optimization.”
My Little Forum 2.3.3 / 2.2 / 1.7 Cross Site Scripting
My Little Forum versions 2.3.3, 2.2, and 1.7 suffer from multiple cross site scripting vulnerabilities.