The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote authenticated users with certain permissions to bypass intended access restrictions and possibly obtain sensitive information by inserting a token, which embeds a rendered entity in the main node.
Monthly Archives: December 2015
Critical Flaws Found in Network Management Systems
Rapid7 has reported and disclosed a half-dozen XSS and SQL injection flaws in popular network management systems, all of which can be reached via SNMP.
Juniper Releases Out-of-band Security Advisory for ScreenOS
Original release date: December 17, 2015
Juniper has discovered unauthorized code in ScreenOS which could allow an attacker to take control of NetScreen devices and to decrypt VPN connections.
US-CERT recommends that users and administrators review Juniper Security Bulletin 2015-12 and update all affected ScreenOS versions.
This product is provided subject to this Notification and this Privacy & Use policy.
PyAMF 0.7.2 XXE Injection
PyAMF suffers from insufficient AMF input payload sanitization which results in the XML parser not preventing the processing of XML external entities (XXE). A specially crafted AMF payload, containing malicious references to XML external entities, can be used to trigger denial of service (DoS) conditions or arbitrarily return the contents of files that are accessible with the running application privileges. Versions 0.7.2 and below are affected.
Easy File Sharing Web Server 7.2 GET SEH Buffer Overflow
Easy File Sharing web server version 7.2 GET HTTP request SEH buffer overflow exploit.
Easy File Sharing Web Server 7.2 HEAD SEH Buffer Overflow
Easy File Sharing web server version 7.2 HEAD HTTP request SEH buffer overflow exploit.
Libnsbmp 0.1.2 Heap Overflow / Out-Of-Bounds Read
Libnsbmp version 0.1.2 suffers from heap overflow and out-of-bounds read vulnerabilities.
Zen Cart 1.5.4 Local File Inclusion
Zen Cart version 1.5.4 suffers from a local file inclusion vulnerability.
orion.extfeedbackform Bitrix Module 2.1.2 CSRF / SQL Injection
orion.extfeedbackform Bitrix module version 2.1.2 suffers from cross site request forgery and remote SQL injection vulnerabilities.
Libnsgif 0.1.2 Stack Overflow / Out-Of-Bounds Read
Libnsgif version 0.1.2 suffers from stack overflow and out-of-bounds read vulnerabilities.