Law makers in Britain are discussing a dramatic increase in sentencing for serious hacking offences, according to The Register. Currently in discussion in the country’s upper house, The House of Lords, the move looks to overhaul the Computer Misuse Act 1990, and includes a possible life sentence for serious hackers.
The Ubercart module provides a shopping cart and e-commerce features for Drupal.
Cross Site Request Forgery (CSRF)
The country administration links are not properly protected. A malicious user could trick a store administrator into enabling or disabling a country by getting them to visit a specially-crafted URL.
CVE identifier(s) issued
A CVE identifier will be requested, and added upon issuance, in accordance
with Drupal Security Team processes.
Versions affected
Ubercart 7.x-3.x versions prior to 7.x-3.8.
Ubercart 6.x-2.x versions prior to 6.x-2.14.
Drupal core is not affected. If you do not use the contributed Ubercart module,
there is nothing you need to do.
Solution
Install the latest version:
If you use the Ubercart module for Drupal 7.x, upgrade to Ubercart 7.x-3.8
If you use the Ubercart module for Drupal 6.x, upgrade to Ubercart 6.x-2.14
This module enables you to to target any malicious software directed at a Web site, whether it be a spambot, ill-designed search engine bot, or system crackers. It blocks such access and then logs their attempts.
Information Disclosure
The module doesn’t sufficiently sanitize log data, allowing usernames and passwords to get included in its logs.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission “administer bad behavior”.
CVE identifier(s) issued
A CVE identifier will be requested, and added upon issuance, in accordance
with Drupal Security Team processes.
Versions affected
badbehavior 6.x-2.x versions prior to 6.x-2.2216.
badbehavior 7.x-2.x versions prior to 7.x-2.2216.
Drupal core is not affected. If you do not use the contributed Bad Behavior module,
there is nothing you need to do.
Multiple cross-site scripting (XSS) vulnerabilities in the search.php in LiteCart 1.1.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query parameter or (2) QUERY_STRING.
Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin/admin.php.
Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the “tftp:// DHCPv6 boot option.”
gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.