Oracle Java SE CVE-2014-4263 Remote Security Vulnerability
Monthly Archives: October 2014
Tor-ramdisk i686 UClibc-based Linux Distribution x86_64 20141022
Tor-ramdisk is an i686 uClibc-based micro Linux distribution whose only purpose is to host a Tor server in an environment that maximizes security and privacy. Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. Security is enhanced by employing a monolithically compiled GRSEC/PAX patched kernel and hardened system tools. Privacy is enhanced by turning off logging at all levels so that even the Tor operator only has access to minimal information. Finally, since everything runs in ephemeral memory, no information survives a reboot, except for the Tor configuration file and the private RSA key which may be exported/imported by FTP. x86_64 version.
Tor-ramdisk i686 UClibc-based Linux Distribution x86 20141022
Tor-ramdisk is an i686 uClibc-based micro Linux distribution whose only purpose is to host a Tor server in an environment that maximizes security and privacy. Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. Security is enhanced by employing a monolithically compiled GRSEC/PAX patched kernel and hardened system tools. Privacy is enhanced by turning off logging at all levels so that even the Tor operator only has access to minimal information. Finally, since everything runs in ephemeral memory, no information survives a reboot, except for the Tor configuration file and the private RSA key which may be exported/imported by FTP. x86 version.
Centreon SQL / Command Injection
This Metasploit module exploits several vulnerabilities on Centreon 2.5.1 and prior and Centreon Enterprise Server 2.2 and prior. Due to a combination of SQL injection and command injection in the displayServiceStatus.php component, it is possible to execute arbitrary commands as long as there is a valid session registered in the centreon.session table. In order to have a valid session, all it takes is a successful login from anybody. The exploit itself does not require any authentication. This Metasploit module has been tested successfully on Centreon Enterprise Server 2.2.
TestLink 1.9.12 Path Disclosure
TestLink versions 1.9.12 and below suffer from a path disclosure weakness.
TestLink 1.9.12 PHP Object Injection
TestLink versions 1.9.12 and below suffer from a PHP object injection vulnerability in execSetResults.php.
OpenBSD 5.5 Local Kernel Panic
OpenBSD versions 5.5 and below local kernel panic proof of concept exploit for i386.
Dell SonicWall GMS 7.2.x Script Insertion
Dell SonicWall GMS version 7.2.x suffers from a script insertion vulnerability.
WordPress CP Multi View Event Calendar 1.01 SQL Injection
WordPress CP Multi View Event Calendar plugin version 1.01 suffers from a remote SQL injection vulnerability.
WordPress / Joomla Creative Contact Form 0.9.7 Shell Upload
WordPress / Joomla Creative Contact Form plugin versions 0.9.7 and below suffer from a remote shell upload vulnerability.