Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime exception and application crash) via a crafted Indusoft Project file.
Monthly Archives: September 2015
DHS working on ‘self-destructing’ security chip for smartphones
A security chip that self-protects the device it is embedded in is being developed by the Department for Homeland Security.
The post DHS working on ‘self-destructing’ security chip for smartphones appeared first on We Live Security.
NHS Approved Apps Are Leaking Patient Data
Watch Live: Snowden Treaty Asks Nations To Resist Mass Surveillance
Porn Sites Hit By Malware Hidden In Adverts
KARMA POLICE: GCHQ Spooks Spied On Every Web User Ever
CVE-2015-5075 – Cross-Site Request Forgery In X2Engine Inc. X2Engine
Posted by Portcullis Advisories on Sep 25
Vulnerability title: Cross-Site Request Forgery In X2Engine Inc. X2Engine
CVE: CVE-2015-5075
Vendor: X2Engine Inc.
Product: X2Engine
Affected version: 4.2
Fixed version: 5.2
Reported by: Simone Quatrini
Details:
It was discovered that no protection against Cross-site Request Forgery attacks was implemented, resulting in an
attacker being able to able to force the creation of a new administrative account.
Further details at:…
CVE-2015-5076 – Vulnerability title: Reflective XSS In X2Engine Inc. X2Engine
Posted by Portcullis Advisories on Sep 25
Vulnerability title: Reflective XSS In X2Engine Inc. X2Engine
CVE: CVE-2015-5076
Vendor: X2Engine Inc.
Product: X2Engine
Affected version: 4.2
Fixed version: 5.2
Reported by: Simone Quatrini
Details:
It was discovered that the web application was vulnerable to reflective Cross-Site Scripting where user supplied data
is used to generate the subsequent response. This is a normal feature of many applications, however, in this instance
the…
CVE-2015-5074 – Arbitrary File Upload In X2Engine Inc. X2Engine
Posted by Portcullis Advisories on Sep 25
Vulnerability title: Arbitrary File Upload In X2Engine Inc. X2Engine
CVE: CVE-2015-5074
Vendor: X2Engine Inc.
Product: X2Engine
Affected version: 4.2
Fixed version: 5.2
Reported by: Simone Quatrini
Details:
It was discovered that authenticated users were able to upload files of any type providing that the file did not have
an extension that was listed in the following blacklist:
const EXT_BLACKLIST =…
Virus Bulletin small talk: Diversity in tech
Ahead of next week’s Virus Bulletin conference, ESET’s Lysa Myers offers a teaser of what to expect of her “small talk” with colleague Stephen Cobb.
The post Virus Bulletin small talk: Diversity in tech appeared first on We Live Security.