Cross-site scripting (XSS) vulnerability in the administration interface in the Path Breadcrumbs module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the “Administer Path Breadcrumbs” permission to inject arbitrary web script or HTML via unspecified vectors.
Monthly Archives: August 2015
Bugtraq: Re: Re: UAC Bypass Vulnerability on "Windows 7" in Windows Script Host
Re: Re: UAC Bypass Vulnerability on “Windows 7” in Windows Script Host
Bugtraq: [SECURITY] [DSA 3346-1] drupal7 security update
[SECURITY] [DSA 3346-1] drupal7 security update
Bugtraq: [security bulletin] HPSBGN03403 rev.1 – HP Virtualization Performance Viewer, Remote Unauthorized Disclosure of Information
[security bulletin] HPSBGN03403 rev.1 – HP Virtualization Performance Viewer, Remote Unauthorized Disclosure of Information
Bugtraq: [security bulletin] HPSBMU03401 rev.1 – HP Operations Manager for UNIX and Linux, Remote Unauthorized Modification, Disclosure of Information
[security bulletin] HPSBMU03401 rev.1 – HP Operations Manager for UNIX and Linux, Remote Unauthorized Modification, Disclosure of Information
NSF Awards $6M Grants for Internet of Things Security
The National Science Foundation awarded $6 million in grants to fund projects working toward securing networked things.
CVE-2014-2329
Multiple cross-site scripting (XSS) vulnerabilities in Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote authenticated users to inject arbitrary web script or HTML via the (1) agent string for a check_mk agent, a (2) crafted request to a monitored host, which is not properly handled by the logwatch module, or other unspecified vectors.
CVE-2014-2330
Multiple cross-site request forgery (CSRF) vulnerabilities in the Multisite GUI in Check_MK before 1.2.5i2 allow remote attackers to hijack the authentication of users for requests that (1) upload arbitrary snapshots, (2) delete arbitrary files, or possibly have other unspecified impact via unknown vectors.
CVE-2014-2331
Check_MK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted rules.mk file in a snapshot. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2330.
CVE-2014-2332
Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, related to “Insecure Direct Object References.” NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2330.