Cross-site scripting (XSS) vulnerability in info.php in TomatoCart 1.1.8.6.1 allows remote attackers to inject arbitrary web script or HTML via the faqs_id parameter.
Monthly Archives: October 2014
CVE-2014-3978
SQL injection vulnerability in TomatoCart 1.1.8.6.1 allows remote authenticated users to execute arbitrary SQL commands via the First Name and Last Name fields in a new address book contact.
CVE-2014-8331
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3236 before E3276sTCPU-V200R002B470D13SP00C00 and E3276sWebUI-V100R007B100D03SP01C03 and E3276 before E3236sTCPU-V200R002B146D41SP00C00 and E3236sWebUI-V100R007B100D03SP01C03 allow remote attackers to hijack the authentication of administrators for requests that (1) change configuration settings or (2) use device functions.
CVE-2014-5276
Multiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to inject arbitrary web script or HTML via (1) an uploaded profile picture or (2) the edit parameter to profiles/index.php.
CVE-2014-8330
Cross-site scripting (XSS) vulnerability in EspoCRM allows remote authenticated users to inject arbitrary web script or HTML via the Name field in a new account.
CVE-2014-5275
Multiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) password, (2) email, or (3) id parameter.
Facebook scans ‘paste sites’ for leaked usernames and passwords
Facebook has a system in place to scan public ‘paste’ sites for email address and password combinations to stay one step ahead of possible leaks, according to The Register.
The post Facebook scans ‘paste sites’ for leaked usernames and passwords appeared first on We Live Security.
![]()
AST-2014-011: Asterisk Susceptibility to POODLE Vulnerability
Posted by Asterisk Security Team on Oct 20
Asterisk Project Security Advisory – AST-2014-011
Product Asterisk
Summary Asterisk Susceptibility to POODLE Vulnerability
Nature of Advisory Unauthorized Data Disclosure
Susceptibility Remote Unauthenticated Sessions
Severity Medium…
Newtelligence dasBlog 2.3 Open Redirect
Newtelligence dasBlog versions 2.1 through 2.3 suffer from an open redirection vulnerability.
OpenMRS 2.1 Access Bypass / XSS / CSRF
OpenMRS version 2.1 suffers from access bypass, cross site request forgery, and cross site scripting vulnerabilities.