EMC VPLEX GeoSynchrony code levels 5.4 SP1 and 5.4 SP1 P1 contain a vulnerability that allows a user password to be logged in plaintext when the user attempts to login via the NAVISPEHERE Graphical User Interface (GUI) that could potentially be exploited by malicious users.
Monthly Archives: November 2015
WordPress Users Ultra 1.5.50 Unrestricted File Upload
WordPress Users Ultra plugin version 1.5.50 suffers from an unrestricted file upload vulnerability.
Google AOSP Email App HTML Injection
Google AOSP email application versions up to 7.0 suffer from an html injection vulnerability.
Linux/x64 Egghunter Shellcode
24 bytes small x64 Linux egghunter shellcode.
Vuln: Oracle Java SE CVE-2015-4732 Remote Security Vulnerability
Oracle Java SE CVE-2015-4732 Remote Security Vulnerability
Vuln: Oracle Java SE CVE-2015-4843 Remote Security Vulnerability
Oracle Java SE CVE-2015-4843 Remote Security Vulnerability
DSA-3399 libpng – security update
Several vulnerabilities have been discovered in the libpng PNG library.
The Common Vulnerabilities and Exposures project identifies the
following problems:
Adobe Releases Security Updates for ColdFusion, LiveCycle Data Services, and Adobe Premiere Clip
Original release date: November 17, 2015
Adobe has released security updates to address multiple vulnerabilities in ColdFusion, LiveCycle Data Services, and Adobe Premiere Clip. Exploitation of some of these vulnerabilities may allow a remote attacker to take control of an affected system.
Users and administrators are encouraged to review Adobe Security Bulletins for ColdFusion, LiveCycle Data Services, and Adobe Premier Clip and apply the necessary updates.
This product is provided subject to this Notification and this Privacy & Use policy.
CVE-2015-6357: Cisco FireSIGHT Management Center SSL Validation Vulnerability
Posted by Matthew Flanagan on Nov 17
Title: Cisco FireSIGHT Management Center Certificate Validation
Vulnerability
Blog URL:
http://wadofstuff.blogspot.com.au/2015/11/cve-2015-6357-firepwner-exploit-for.html
Vendor: Cisco
Product: FireSIGHT Management Center
Affected Versions: 5.2.x, 5.3.x, 5.4.x
Advisory URL:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151116-fmc
CVE: CVE-2015-6357
CVSS: 5.1
The Cisco FireSIGHT Management Center appliance is…
zTree v3 Security Advisory – XSS Vulnerability – CVE-2015-7348
Posted by Onur Yilmaz on Nov 17
Information
——————–
Advisory by Netsparker.
Name: Multiple XSS Vulnerabilities in zTree v3
Affected Software : zTree
Affected Versions: v3.5.19.1 and possibly below
Vendor Homepage : https://github.com/zTree/zTree_v3
Vulnerability Type : Cross-site Scripting
Severity : Important
Status : Fixed
CVE-ID : CVE-2015-7348
Netsparker Advisory Reference : NS-15-019
Description
——————–
By exploiting a Cross-site scripting…