Fixes CVE-2015-3258 & CVE-2015-3279
Monthly Archives: July 2015
Fedora 22 Security Update: springframework-3.2.14-1.fc22
CVE-2015-0551
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web Publishers 6.5 SP7 before P25; and Documentum Task Space 6.7SP1 before P31 and 6.7SP2 before P23 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-1966
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before FP17, 6.2.1 before FP9, and 6.2.2 before FP15, as used in Security Access Manager for Mobile and other products, allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to the (1) ERROR_DESCRIPTION and (2) TOKEN:RelayState macros.
CVE-2015-4524
Unrestricted file upload vulnerability in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web Publishers 6.5 SP7 before P25; and Documentum Task Space 6.7SP1 before P31 and 6.7SP2 before P23 allows remote authenticated users to execute arbitrary code by uploading a file to the backend Content Server.
Google HTTP Live Headers v1.0.6 – Client Side Cross Site Scripting Web Vulnerability
Posted by Vulnerability Lab on Jul 04
Document Title:
===============
Google HTTP Live Headers v1.0.6 – Client Side Cross Site Scripting Web Vulnerability
References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1541
Release Date:
=============
2015-07-02
Vulnerability Laboratory ID (VL-ID):
====================================
1541
Common Vulnerability Scoring System:
====================================
3.3
Product & Service…
Ebay Inc Magento Bug Bounty #16 – CSRF Web Vulnerability
Posted by Vulnerability Lab on Jul 04
Document Title:
===============
Ebay Inc Magento Bug Bounty #16 – CSRF Web Vulnerability
References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1472
Ebay Inc Security ID: EIBBP-31808
Release Date:
=============
2015-07-02
Vulnerability Laboratory ID (VL-ID):
====================================
1472
Common Vulnerability Scoring System:
====================================
2.5
Product & Service…
WK UDID v1.0.1 iOS – Command Inject Vulnerability
Posted by Vulnerability Lab on Jul 04
Document Title:
===============
WK UDID v1.0.1 iOS – Command Inject Vulnerability
References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1539
Release Date:
=============
2015-07-01
Vulnerability Laboratory ID (VL-ID):
====================================
1539
Common Vulnerability Scoring System:
====================================
5.6
Product & Service Introduction:
===============================…
CVE-2015-0547
The D2CenterstageService.getComments service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.
CVE-2015-0548
The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.