CVE-2015-0551

Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web Publishers 6.5 SP7 before P25; and Documentum Task Space 6.7SP1 before P31 and 6.7SP2 before P23 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVE-2015-1966

Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before FP17, 6.2.1 before FP9, and 6.2.2 before FP15, as used in Security Access Manager for Mobile and other products, allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to the (1) ERROR_DESCRIPTION and (2) TOKEN:RelayState macros.

CVE-2015-4524

Unrestricted file upload vulnerability in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web Publishers 6.5 SP7 before P25; and Documentum Task Space 6.7SP1 before P31 and 6.7SP2 before P23 allows remote authenticated users to execute arbitrary code by uploading a file to the backend Content Server.

Google HTTP Live Headers v1.0.6 – Client Side Cross Site Scripting Web Vulnerability

Posted by Vulnerability Lab on Jul 04

Document Title:
===============
Google HTTP Live Headers v1.0.6 – Client Side Cross Site Scripting Web Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1541

Release Date:
=============
2015-07-02

Vulnerability Laboratory ID (VL-ID):
====================================
1541

Common Vulnerability Scoring System:
====================================
3.3

Product & Service…

Ebay Inc Magento Bug Bounty #16 – CSRF Web Vulnerability

Posted by Vulnerability Lab on Jul 04

Document Title:
===============
Ebay Inc Magento Bug Bounty #16 – CSRF Web Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1472

Ebay Inc Security ID: EIBBP-31808

Release Date:
=============
2015-07-02

Vulnerability Laboratory ID (VL-ID):
====================================
1472

Common Vulnerability Scoring System:
====================================
2.5

Product & Service…

WK UDID v1.0.1 iOS – Command Inject Vulnerability

Posted by Vulnerability Lab on Jul 04

Document Title:
===============
WK UDID v1.0.1 iOS – Command Inject Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1539

Release Date:
=============
2015-07-01

Vulnerability Laboratory ID (VL-ID):
====================================
1539

Common Vulnerability Scoring System:
====================================
5.6

Product & Service Introduction:
===============================…

CVE-2015-0547

The D2CenterstageService.getComments service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.

CVE-2015-0548

The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.