Debian Linux Security Advisory 3779-1 – Several vulnerabilities were discovered in wordpress, a web blogging tool. They would allow remote attackers to hijack victims’ credentials, access sensitive information, execute arbitrary commands, bypass read and post restrictions, or mount denial-of-service attacks.
Monthly Archives: February 2017
Red Hat Security Advisory 2017-0226-01
Red Hat Security Advisory 2017-0226-01 – RabbitMQ is an implementation of AMQP, the emerging standard for high performance enterprise messaging. The RabbitMQ server is a robust and scalable implementation of an AMQP broker. Security Fix: A resource-consumption flaw was found in RabbitMQ Server, where the lengths_age or lengths_incr parameters were not validated in the management plugin. Remote, authenticated users with certain privileges could exploit this flaw to cause a denial of service by passing values which were too large.
Bitrix Site Manager Cross Site Scripting
Bitrix Site Manager suffers from a cross site scripting vulnerability.
Property Listing Script Blind SQL Injection
Property Listing Script suffers from a remote blind SQL injection vulnerability.
LogoStore SQL Injection
LogoStore suffers from a remote SQL injection vulnerability.
CVE-2017-5630
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.
Bugtraq: [SECURITY] [DSA 3779-1] wordpress security update
[SECURITY] [DSA 3779-1] wordpress security update
Bugtraq: ESA-2017-003: EMC Network Configuration Manager (NCM) Multiple Vulnerabilities
ESA-2017-003: EMC Network Configuration Manager (NCM) Multiple Vulnerabilities
Bugtraq: Cisco Security Advisory: Cisco Prime Home Authentication Bypass Vulnerability
Cisco Security Advisory: Cisco Prime Home Authentication Bypass Vulnerability
Bugtraq: [security bulletin] HPSBST03588 rev 1. – HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS, Remote Arbitrary Command Execution
[security bulletin] HPSBST03588 rev 1. – HPE StoreVirtual 4000 Storage and StoreVirtual VSA Software running LeftHand OS, Remote Arbitrary Command Execution