Monthly Archives: September 2015
Google Is Teaching Cars To Drive Like Humans
Ubuntu Security Notice USN-2748-1
Ubuntu Security Notice 2748-1 – Benjamin Randazzo discovered an information leak in the md (multiple device) driver when the bitmap_info.file is disabled. A local privileged attacker could use this to obtain sensitive information from the kernel. Lureau discovered that the vhost driver did not properly release the userspace provided log file descriptor. A privileged attacker could use this to cause a denial of service (resource exhaustion). Various other issues were also addressed.
Centreon 2.6.1 Persistent Cross Site Scripting
Centreon version 2.6.1 suffers from a stored cross site scripting vulnerability.
WordPress Appointment Booking Calendar 1.1.7 SQL Injection
WordPress Appointment Booking Calendar plugin 1.1.7 suffers from a remote SQL injection vulnerability.
PCMan FTP Server 2.0.7 Directory Traversal
PCMan FTP Server version 2.0.7 suffers from a directory traversal vulnerability.
Vtiger CRM 6.3 Remote Code Execution
Vtiger CRM versions 6.3 and below suffer from an authenticated remote code execution vulnerability.
Centreon 2.6.1 Command Injection
Centreon version 2.6.1 suffers from a command injection vulnerability. The POST parameter ‘persistant’ which serves for making a new service run in the background is not properly sanitized before being used to execute commands. This can be exploited to inject and execute arbitrary shell commands as well as using cross site request forgery attacks.
IconLover 5.4.5 Stack Buffer Overflow
IconLover version 5.4.5 suffers from a stack buffer overflow vulnerability.
Photos In Wifi 1.0.1 File Upload
Photos in Wifi version 1.0.1 suffers from a remote shell upload vulnerability.