SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php.
Monthly Archives: February 2015
CVE-2015-1448
The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allows remote attackers to bypass authentication and perform administrative actions via unspecified vectors.
CVE-2015-1449
Buffer overflow in the integrated web server on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2015-1450
SQL injection vulnerability in Restaurant Biller allows remote attackers to execute arbitrary SQL commands via the cid parameter in a category action to index.php.
B-Sides Knoxville 2015 Call For Papers
The B-Sides Knoxville 2015 Call For Papers has been announced. It will take place May 15th, 2015 at Scruffy City Hall.
Female Skype Avatar Sinks Syria Opposition Fighters
A cyberespionage campaign pulled off by pro-Syrian hackers against Assad opposition fighters used social engineering to steal military planning documents.
Google announces ‘Vulnerability Research Grants’
Google has announced it is to pay out research grants to security researchers seeking out potential bugs, even if they turn up empty-handed, reports ZDNet.
The post Google announces ‘Vulnerability Research Grants’ appeared first on We Live Security.
Fedora 21 Security Update: patch-2.7.4-1.fc21
Landesk Management Suite 9.5 Cross Site Scripting
Landesk Management Suite version 9.5 suffers from a cross site scripting vulnerability.
OptimalSite CMS 1 / 2.4 Cross Site Scripting
OptimalSite CMS versions 1 and 2.4 suffer from a cross site scripting vulnerability.