Visa and MasterCard announce plans to discontinue password use on 3D Secure, Verify by Visa and SecureCode secure payment platforms.
Monthly Archives: November 2014
CVE-2014-8493 – ZTE ZXHN H108L Authentication Bypass
Posted by Project Zero Labs on Nov 17
About the software
==================
ZTE ZXHN H108L is provided by some large Greek ISPs to their
subscribers.
Vulnerability Details
=====================
CWMP configuration is accessible only through the Administrator account.
CWMP is a protocol widely used by ISPs worldwide for remote provisioning
and troubleshooting their subscribers’ equipment. However editing the
CWMP configuration (more specifically sending the POST request)…
WebsiteBaker <=2.8.3 – Multiple Vulnerabilities
Posted by Manuel Garcia Cardenas on Nov 17
=============================================
MGC ALERT 2014-004
– Original release date: March 11, 2014
– Last revised: November 18, 2014
– Discovered by: Manuel Garcia Cardenas
– Severity: 10/10 (CVSS Base Score)
=============================================
I. VULNERABILITY
————————-
Multiple Vulnerabilities in WebsiteBaker 2.8.3
II. BACKGROUND
————————-
WebsiteBaker helps you to create the website you want:…
Zoph <= 0.9.1 – Multiple Vulnerabilities
Posted by Manuel Garcia Cardenas on Nov 17
=============================================
MGC ALERT 2014-005
– Original release date: March 5, 2014
– Last revised: November 18, 2014
– Discovered by: Manuel Garcia Cardenas
– Severity: 10/10 (CVSS Base Score)
=============================================
I. VULNERABILITY
————————-
Multiple Vulnerabilities in Zoph <= 0.9.1
II. BACKGROUND
————————-
Zoph (Zoph Organizes Photos) is a web based digital image…
ABRT for CentOS Linux is now live
ABRT is a collection of scripts that makes it easier to report bugs and crashes in various components of the distribution to a central server. Metadata from this allows developers and upstream projects to evaluate their priority chain, and also get crucial information on why their software might not be performing as expected on CentOS Linux. This information is sent to the server in a json format text file, the contents of which will never contain private date. The entire specification for this report format is available at : https://github.com/abrt/faf/wiki/uReport and I encourage everyone to read it once, so as to build confidence in the process. -------- You can enable ABRT reporting by running: /usr/sbin/abrt-auto-reporting enabled this script is provided by the 'abrt' rpm package. -------- More details on ABRT on CentOS are available on the CentOS wiki at http://wiki.centos.org/TipsAndTricks/ABRT ; The entire ABRT documentation is available online at : http://abrt.readthedocs.org/en/latest/ - this includes both user and developer information. For those looking to get started with hacking on ABRT, start by reading through the advanced usage examples at : http://abrt.readthedocs.org/en/latest/examples.html -------- The reports posted by CentOS machines will currently land at the Fedora Project hosted retrace server at : https://retrace.fedoraproject.org/ -------- For any problems or issues with the abrt code included in CentOS Linux, or for any problems associated with abrt user experience on CentOS Linux : please post reports at http://bugs.centos.org/ by selecting the right Distribution version and component as 'abrt'. All other conversations around abrt on CentOS Linux should goto the CentOS-devel mailing list ( http://lists.centos.org/ ). regards,
Privacy and security post-Snowden: Pew Research parallels ESET findings
Privacy and security online are hot button topics in America today, as a new survey by the Pew Research Center confirms, mirroring similar results from two different privacy and security surveys conducted by ESET.
The post Privacy and security post-Snowden: Pew Research parallels ESET findings appeared first on We Live Security.
![]()
Openkm Document Management System 6.4.17 Cross Site Scripting
Openkm Document Management System versions 6.4.17 and below suffer from a cross site scripting vulnerability.
Videos Tube 2.0 SQL Injection / XSS / Shell Upload
Videos Tube version 2.0 suffers from cross site scripting, remote shell upload, and remote SQL injection vulnerabilities.
Malware Spreading Via Steam Chat
Joomla HD FLV 2.1.0.1 Arbitrary File Download
Joomla HD FLV version 2.1.0.1 suffers from an arbitrary file download vulnerability.