WordPress Image Export plugin version 1.1 suffers from an arbitrary file download vulnerability.
Monthly Archives: July 2015
Kaspersky Lab Partners with 20th Century Fox to Launch the Ultimate Fantastic Four Sweepstakes
Joomla Docman Path Disclosure / Local File Inclusion
Joomla Docman suffers from full path disclosure and local file inclusion vulnerabilities.
Kaseya Virtual System Administrator File Download / Open Redirect
Kaseya Virtual System Administrator suffers from arbitrary file download open redirection vulnerabilities.
PFSense 2.2.2 Cross Site Scripting
PFSense version 2.2.2 suffers from a cross site scripting vulnerability.
ArticleFR 3.0.6 Cross Site Request Forgery
ArticleFR version 3.0.6 allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
ArticleFR 3.0.6 Cross Site Scripting
ArticleFR suffers from multiple stored cross site scripting vulnerabilities. The issues are triggered when input passed via the POST parameter ‘name’ in Categories, POST parameters ‘title’ and ‘rel’ in Links and GET parameter ‘url’ in PingServers module is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site. Version 3.0.6 is affected.
Panda Security 1.0.0.13 Arbitrary Code Execution
Panda Kernel Memory Access Driver does not validate the size of data to be copied to both an allocated kernel paged pool buffer and to an allocated non-paged pool buffer. Furthermore, the attacker has control over the start-to-copy index regarding the non-paged pool buffer which allows an attacker to corrupt a kernel object with more precision, and control the EIP via a hijacked function pointer.
SAP Afaria XeService.exe 7.0.6398.0 Weak File Permissions
The SAP Afaria Windows client software installs with weak default permissions that grant read and write permissions to the Everyone group to the install folder. Versions 7.0.6398.0 is affected.
Flash Player Update Patches Two Hacking Team Zero Days
Adobe today patched two zero day vulnerabilities discovered in data from the Hacking Team breach. It also released updated versions of Acrobat, Reader and Shockwave.