Category Archives: Full Disclosure

Full Disclosure

Blubrry PowerPress Security Advisory – XSS Vulnerability – CVE-2015-1385

Posted by Onur Yilmaz on Jan 30

Information
————
Advisory by Netsparker
Name: XSS Vulnerability in Blubrry PowerPress
Affected Software : Blubrry PowerPress
Affected Versions: 6.0 and possibly below
Vendor Homepage : https://wordpress.org/plugins/powerpress/
Vulnerability Type : Cross-site Scripting
Severity : Important
CVE-ID: CVE-2015-1385
Netsparker Advisory Reference : NS-15-001

Description
———–
By exploiting a Cross-site scripting vulnerability the attacker…

Symantec Encryption Management Server < 3.2.0 MP6 – Remote Command Injection

Posted by Paul Craig on Jan 30

Vantage Point Security Advisory 2014-007
========================================

Title: Symantec Encryption Management Server – Remote Command Injection
ID: VP-2014-007
Vendor: Symantec
Affected Product: Symantec Encryption Gateway
Affected Versions: < 3.2.0 MP6
Product Website: http://www.symantec.com/en/sg/gateway-email-encryption/
Author: Paul Craig <paul[at]vantagepoint[dot]sg>

Summary:
———
Symantec Gateway Email Encryption…

NEW VMSA-2015-0002 VMware vSphere Data Protection product update addresses a certificate validation vulnerability

Posted by VMware Security Response Center on Jan 29

————————————————————————
VMware Security Advisory

Advisory ID: VMSA-2015-0002
Synopsis: VMware vSphere Data Protection product update addresses a
certificate validation vulnerability.
Issue date: 2015-01-29
Updated on: 2015-01-29 (Initial Advisory)
CVE number: CVE-2014-4632

————————————————————————

1. Summary…