PHP version 5.5.33 suffers from an invalid memory write condition in phar on filename with in the name.
Monthly Archives: March 2016
Axil CMS 0.1 SQL Injection
Axil CMS version 0.1 suffers from a remote SQL injection vulnerability that allows for login bypass.
Axil CMS 3.0 Cross Site Scripting
Axil CMS version 3.0 suffers from a cross site scripting vulnerability.
Cybercriminals are overcoming language and time zone barriers to cooperate on making malware more dangerous – ZDNet
Cybercriminals are overcoming language and time zone barriers to cooperate on making malware more dangerous – ZDNet
The Spreading Epidemic of Hospital Ransomware – Motherboard
Cybercriminals are targeting the weaknesses in hospitals to wreak havoc and rake in profits – Motherboard
Apache Jetspeed Arbitrary File Upload
This Metasploit module exploits the unsecured User Manager REST API and a ZIP file path traversal in Apache Jetspeed-2, versions 2.3.0 and unknown earlier versions, to upload and execute a shell. Note: this exploit will create, use, and then delete a new admin user. Warning: in testing, exploiting the file upload clobbered the web interface beyond repair. No workaround has been found yet. Use this module at your own risk. No check will be implemented.
DSA-3538 libebml – security update
Several vulnerabilities were discovered in libebml, a library for
manipulating Extensible Binary Meta Language files.
DSA-3536 libstruts1.2-java – security update
It was discovered that libstruts1.2-java, a Java framework for MVC
applications, contains a bug in its multi-page validation code. This
allows input validation to be bypassed, even if MPV is not used
directly.
DSA-3537 imlib2 – security update
Several vulnerabilities were discovered in imlib2, an image
manipulation library.
Metaphor Stagefright Implementation
Included in this archive is a whitepaper called Metaphor – A (real) real-life Stagefright exploit. It presents a thorough research on libstagefright and new techniques used to bypass ASLR. This archive also includes the Metaphor exploit that leverages CVE-2015-3864.