Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before 1.4 for WordPress allows remote attackers to read arbitrary files via a full pathname in the requrl parameter.
Monthly Archives: June 2015
CVE-2015-5066 (genixcms)
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) content or (2) title field in an add action in the posts page to index.php or the (3) q parameter in the posts page to index.php.
CVE-2015-5067 (netweaver)
The (1) Cross-System Tools and (2) Data Transfer Workbench in SAP NetWeaver have hardcoded credentials, which allows remote attackers to obtain access via unspecified vectors, aka SAP Security Note 2059659 and 2057982.
CVE-2015-5068
XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted XML request, aka SAP Security Note 2159601.
HybridAuth Social Login – Less Critical – Access bypass – SA-CONTRIB-2015-127
- Advisory ID: DRUPAL-SA-CONTRIB-2015-127
- Project: HybridAuth Social Login (third-party module)
- Version: 7.x
- Date: 2015-June-24
- Security risk: 8/25 ( Less Critical) AC:Basic/A:None/CI:None/II:None/E:Theoretical/TD:Uncommon
- Vulnerability: Access bypass
Description
The HybridAuth Social Login module enables you to allow visitors to authenticate or login to a Drupal site using their identities from social networks like Facebook or Twitter.
The module allows account creation through social login when the configuration is set to allow user registration by administrators only.
This vulnerability is mitigated by the fact that a site must be configured to allow user registration by administrators only and that authenticated user accounts can access sensitive data that would otherwise not be shown to anonymous users.
CVE identifier(s) issued
- A CVE identifier will be requested, and added upon issuance, in accordance with Drupal Security Team processes.
Versions affected
- HybridAuth Social Login 7.x-2.x versions prior to 7.x-2.13.
Drupal core is not affected. If you do not use the contributed HybridAuth Social Login module, there is nothing you need to do.
Solution
Install the latest version:
- If you use the HybridAuth Social Login module for Drupal 7.x, upgrade to HybridAuth Social Login 7.x-2.13
Also see the HybridAuth Social Login project page.
Reported by
Fixed by
- Andrew Berezovsky the module maintainer
Coordinated by
- Klaus Purer of the Drupal Security Team
Contact and More Information
The Drupal security team can be reached at security at drupal.org or via the contact form at https://www.drupal.org/contact.
Learn more about the Drupal Security team and their policies, writing secure code for Drupal, and securing your site.
Follow the Drupal Security Team on Twitter at https://twitter.com/drupalsecurity
Proposed Change to ICANN Domain Anonymity Rule Worries Privacy Advocates
A proposed change to the way that registrars treat the private contact details for domain owners could make it easier for anyone to get information on people who use proxy services.
Critical vulnerabilities in Windows and Adobe Reader exposed by hacker
A hacker has published an extensive list of Adobe Reader and Windows vulnerabilities based on his research into a relatively obscure area of font management.
The post Critical vulnerabilities in Windows and Adobe Reader exposed by hacker appeared first on We Live Security.
![]()
25 years of security and innovation
It’s Panda’s Birthday. But this 2015 is not an ordinary anniversary. Tomorrow, June 25th, we turn 25, no more, no less!
Panda was born in 1990, which was also the date of the World Wide Web development, what a coincidence, right? It has been 25 years in which we had time to do many things but, at the same time, time has flied! 25 years researching, developing, analyzing and protecting our customers, both corporate and home users, against all Internet threats.
Despite all we could tell you here, it wouldn’t be enough! So, we think the best thing that we can do is to give you an overview of our 25 years of history with images. Thank you so much to all of you who have been part of it! ![]()

CeBIT 2001
Bilbao Offices, 2001
CEBIT, 2002
CEBIT, 2003
9 years ago… PandaLabs (2006)

1st Security Blogger Summit, 2009
Old Offices in Tres Cantos (Madrid)

Panda Booth at SIMO. 2007
Open Windows Premiere. Madrid. 2014
Introducing Panda Security 2015 to the Media

Panda Kick Off. Bilbao. 2015
We’re Simplexity!
Congratulations and let’s enjoy another 25 years together! ![]()

The post 25 years of security and innovation appeared first on MediaCenter Panda Security.