WordPress Simple Add Pages Or Posts plugin version 1.6 suffers from a cross site request forgery vulnerability.
Monthly Archives: January 2016
HSBC’s online banking services hit with cyberattack
HSBC in the UK has revealed via Twitter that its internet banking services were targeted by cybercriminals this morning (January 29th), which it has “successfully defended”.
The post HSBC’s online banking services hit with cyberattack appeared first on We Live Security.
![]()
HP Security Bulletin HPSBGN03542 1
HP Security Bulletin HPSBGN03542 1 – A vulnerability in Apache Commons Collections for handling Java object deserialization was addressed by HPE Operations Manager for Windows. The vulnerability could be exploited remotely to allow remote code execution. Revision 1 of this advisory.
Kaspersky Lab Receives Full Marks from AV-TEST for Small Business Endpoint Protection on Windows 10
Businesses ‘still naïve to the risks of cybercrime’
Close to half all businesses in the UK are of the opinion that they are safe from cybercrime, according to new research. They believe the risks are minute.
The post Businesses ‘still naïve to the risks of cybercrime’ appeared first on We Live Security.
![]()
ProjectSend r582 Bypass / SQL Injection / File Read
ProjetSend version r582 suffers from authentication bypass, remote SQL injection, insecure direct object reference, and directory traversal / arbitrary file read vulnerabilities.
Apache Hive 1.0.1 / 1.1.0 / 1.2.1 Authorization Bug Disclosure
Some partition-level operations exist that do not explicitly also authorize privileges of the parent table. This can lead to issues when the parent table would have denied the operation, but no denial occurs because the partition-level privilege is not checked by the authorization framework, which defines authorization entities only from the table level upwards. This issue is known to affect Hive clusters protected by both Ranger as well as SqlStdHiveAuthorization. Apache Hive versions 1.0.0 through 1.0.1, 1.1.0 through 1.1.1, and 1.2.0 through 1.2.1 are affected.
HP Security Bulletin HPSBHF03535 3
HP Security Bulletin HPSBHF03535 3 – Potential security vulnerabilities in Adobe Flash have been addressed with HPE iMC Service Health Manager (SHM) and iMC PLAT. The vulnerabilities could be exploited remotely resulting in execution of code, Denial of Service (DoS), or other impacts to affect confidentiality, integrity, and availability. Revision 3 of this advisory.
HP Security Bulletin HPSBHF03538 1
HP Security Bulletin HPSBHF03538 1 – Potential security vulnerabilities in Adobe Flash have been addressed with HPE iMC Service Health Manager (SHM), and iMC PLAT. The vulnerabilities could be exploited remotely resulting in execution of code or Denial of Service (DoS). Revision 1 of this advisory.
Netlife Photosuite Pro – Client Side Cross Site Scripting Vulnerability
Posted by Vulnerability Lab on Jan 29
Document Title:
===============
Netlife Photosuite Pro – Client Side Cross Site Scripting Vulnerability
References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1692
Release Date:
=============
2016-01-29
Vulnerability Laboratory ID (VL-ID):
====================================
1692
Common Vulnerability Scoring System:
====================================
3.3
Product & Service Introduction:…