Resolved Bugs
1233327 – CVE-2015-3224 rubygem-web-console: IP whitelist bypass in Web Console
1233340 – CVE-2015-3224 rubygem-web-console: IP whitelist bypass in Web Console [fedora-all]<br
Security fix for CVE-2015-3224. Please note that since the security fix was not really backportable, I opted in for rebase.
Monthly Archives: June 2015
Fedora 22 Security Update: php-htmLawed-1.1.20-1.fc22
**1.1.20** – 9 June 2015. Fix for a potential security vulnerability arising from unescaped double-quote character in single-quoted attribute value of some deprecated elements when tag transformation is enabled; recognition for non-(HTML4) standard ‘allowfullscreen’ attribute of ‘iframe.’
Fedora 21 Security Update: rubygem-jquery-rails-3.1.0-3.fc21
WordPress Google Analyticator 6.4.9.3 CSRF
WordPress Google Analyticator plugin version 6.4.9.3 suffers from a cross site request forgery vulnerability.
CVE-2015-4201
The Gateway General Packet Radio Service Support Node (GGSN) component on Cisco ASR 5000 devices with software 17.2.0.59184 and 18.0.L0.59219 allows remote attackers to cause a denial of service (Session Manager restart) via an invalid TCP/IP header, aka Bug ID CSCut68058.
Bugtraq: ZTE ZXV10 W300 v3.1.0c_DR0 – UI Session Delete Vulnerability
ZTE ZXV10 W300 v3.1.0c_DR0 – UI Session Delete Vulnerability
Bugtraq: Ebay Magento Bug Bounty #17 – Client Side Cross Site Scripting Web Vulnerability
Ebay Magento Bug Bounty #17 – Client Side Cross Site Scripting Web Vulnerability
Bugtraq: Ebay Magento Bug Bounty #10 – Persistent Filename Vulnerability
Ebay Magento Bug Bounty #10 – Persistent Filename Vulnerability
Bugtraq: Ebay Magento Bug Bounty #12 – Cross Site Request Forgery Web Vulnerability
Ebay Magento Bug Bounty #12 – Cross Site Request Forgery Web Vulnerability
Cross-Site Request Forgery in Google Analyticator WordPress Plugin v6.4.9.3 before rev @1183563
Posted by Nitin Venkatesh on Jun 20
# Title: Cross-Site Request Forgery in Google Analyticator WordPress Plugin
v6.4.9.3 before rev @1183563
# Submitter: Nitin Venkatesh
# Product: Google Analyticator WordPress Plugin
# Product URL: https://wordpress.org/plugins/google-analyticator/
# Vulnerability Type: Cross-Site Request Forgery [CWE-352]
# Affected Versions: v6.4.9.3 before rev @1183563 and possibly earlier
# Tested versions: v6.4.9.3 rev @1168849
# Fixed Version: v6.4.9.3 rev…