Multiple cross-site scripting (XSS) vulnerabilities in Etiko CMS allow remote attackers to inject arbitrary web script or HTML via the (1) page_id parameter to loja/index.php or (2) article_id parameter to index.php.
Monthly Archives: October 2014
CVE-2014-8506 (etiko_cms)
Multiple SQL injection vulnerabilities in Etiko CMS allow remote attackers to execute arbitrary SQL commands via the (1) page_id parameter to loja/index.php or (2) article_id parameter to index.php.
Digital Dating @ 50+
I noticed that this past weekend marked a lesser holiday known as âSweetest Dayâ (also known as a Hallmark holiday), which is celebrated in some parts of the U.S. â largely in the Midwest and Northeast. Â Very similar to Valentineâs Day, it offers an opportunity to bestow candy and cards to those you are âsweet on.â

Itâs a holiday my generation grew up with, though Iâm not sure how the holiday is faring in terms of current popularity. But it brought to mind the latest stats on Internet dating: more than a whopping 41,000,000 Americans have gone online to find a match or a date.
Increasingly, itâs the most popular way for people over 50 to meet and marry. Research suggests that Boomers who date online is now growing two times as fast as the number of younger users. According to recent research by eHarmony, the biggest growth segment in online dating for the next decade is going to be the 55-64 age group.
Match.com, one of the largest online dating sites, claims that 25 percent of its membership is between the ages of 50 and 65 and Boomer members have grown 90 percent in the last 5 years. With at 21 million plus members, thatâs approximately 5 million Boomers on Match.com alone! Â Â (You can find all sorts of online dating stats, if you are interested, on Statisticbrain.)
There also has been a notable rise in dating sites specifically catering to Boomers and Seniors, such as Ourtime.com, SilverSingles.com and SeniorPassions.com.
Why this growth? A study conducted for OurTime.com reveals unmarried people over 50 consider companionship more important now than they did during their 20s. There also are numerous studies that support a correlation between oneâs interpersonal relationships and their health and longevity. Plus, letâs face it, dating can fun!
But for many people (Boomers and not), especially those who are newly single because of divorce or death, the thought of dating and finding a partner also can be daunting and scary. And though societyâs comfort level has grown with the emergence of respected online dating communities over the last decade, a healthy amount of cautiousness persists â and rightly so.
So, where to start?
If youâre trying online dating for the first time, or even if youâve tried it before and it didnât work out, and you may want to try it again, you should look at one of our own resources, the AVG Guide to Dating Safely Online (free download here).
In the meantime, here are a few tips:
- Figure out what you want. You may want to date only people your age and in your local geography. Or you may have certain religious affiliations, or hobbies, or interests that you are looking for in a potential partner. With literally thousands of dating sites out there, you have options to tailor your search to your desire.
- Once youâve narrowed down the sites and apps you would consider signing up to, look for any articles, blog posts or social commentary that illustrate other usersâ experiences. Are there any problems, such as privacy concerns, associated with the site?
- Use technology that you are comfortable with. There are of course many dating sites that are pretty much like digital classifieds. But increasingly there are other options, such as mobile apps that let you find singles in the area. Â (More than half of eHarmony users now use mobile devices to interact with the dating service.)
- Â Don’t provide intimate details about yourself until you feel comfortable with the person you are dealing with. By the same token, realize that any content you share – from your interests to your photos – becomes the property of that site, and you lose the rights to control how itâs used. That means your picture could pop up as a âDate Of The Weekâ promotion â or your dating profiles can turn up on Internet searches. So look in the privacy settings to make sure yours is only available to other users logged into the site.
Readers of my column know that Iâm a big fan of second acts (and third acts, and beyond!). And that doesnât only apply to careers â but to relationships as well. J So whether you decide to try online dating â or to go the old fashioned route â I say do some homework and then just go for it!
On a separate note, but on the topic of choices: Iâm delighted to report that I have just learned that I have been selected to speak at SXSW 2015 Interactive on âBoardroom or Baby? The Choices Women Have in Tech.â A big thank you to everyone who supported me and voted for my submission. I hope to see many of you in Austin next March 13-17!
![]()
![]()
Kaspersky Lab and LifeJourney Help Students Learn About STEM Careers
CVE-2014-7178 – Remote Command Execution in Enalean Tuleap
Posted by Portcullis Advisories on Oct 28
Vulnerability title: Tuleap <= 7.4.99.5 Remote Command Execution in Enalean Tuleap
CVE: CVE-2014-7178
Vendor: Enalean
Product: Tuleap
Affected version: 7.4.99.5 and earlier
Fixed version: 7.5
Reported by: Jerzy Kramarz
Details:
Tuleap does not validate the syntax of the requests submitted to SVN handler pages in order to validate weather request
passed to passthru() function are introducing any extra parameters that would be executed in the…
CVE-2014-7177 – External XML Entity Injection in Enalean Tuleap
Posted by Portcullis Advisories on Oct 28
Vulnerability title: Tuleap <= 7.2 External XML Entity Injection in Enalean Tuleap
CVE: CVE-2014-7177
Vendor: Enalean
Product: Tuleap
Affected version: 7.2 and earlier
Fixed version: 7.4.99.5
Reported by: Jerzy Kramarz
Details:
A multiple XML External Entity Injection has been found and confirmed within the software as an authenticated user.
Successful attack could allow an authenticated attacker to access local system files. The following…
CVE-2014-7176 – Authenticated Blind SQL Injection in Enalean Tuleap
Posted by Portcullis Advisories on Oct 28
Vulnerability title: Tuleap <= 7.4.99.5 Authenticated Blind SQL Injection in Enalean Tuleap
CVE: CVE-2014-7176
Vendor: Enalean
Product: Tuleap
Affected version: 7.4.99.5 and earlier
Fixed version: 7.5
Reported by: Jerzy Kramarz
Details:
SQL injection has been found and confirmed within the software as an authenticated user. A successful attack could
allow an authenticated attacker to access information such as usernames and password hashes…
CVE-2014-4974 – Kernel Memory Leak in ESET Multiple Windows Products
Posted by Portcullis Advisories on Oct 28
Vulnerability title: Kernel Memory Leak in ESET Multiple Windows Products
CVE: CVE-2014-4974
Vendor: ESET
Product: Multiple Windows Products
Affected version: 5.0 – 7.0
Fixed version: Build 1212
Reported by: Kyriakos Economou
Details:
The latest, and earlier versions, of ESET Smart Security and ESET Endpoint Security products for Windows XP OS allow
any local user to leak privileged information from kernel memory by exploiting a vulnerability…
[ MDVSA-2014:210 ] mariadb
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 _______________________________________________________________________ Mandriva Linux Security Advisory MDVSA-2014:210 http://www.mandriva.com/en/support/security/ _______________________________________________________________________ Package : mariadb Date : October 28, 2014 Affected: Business Server 1.0 _______________________________________________________________________ Problem Description: Multiple vulnerabilities has been discovered and corrected in mariadb: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:INNODB DML FOREIGN KEYS (CVE-2014-6464). Unspecified vulnerability in Oracle MySQL Server 5.5.39 and eariler and 5.6.20 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:OPTIMIZER (CVE-2014-6469). Unspecified vulnerabilit
DAVOSET 1.2.1
DAVOSET is a tool for committing distributed denial of service attacks using execution on other sites.