Red Hat Security Advisory 2016-0308-01

Red Hat Security Advisory 2016-0308-01 – RabbitMQ is an implementation of AMQP, the emerging standard for high performance enterprise messaging. The RabbitMQ server is a robust and scalable implementation of an AMQP broker. A cross-site scripting vulnerability was discovered in RabbitMQ, which allowed using api/ path info to inject and receive data. A remote attacker could use this flaw to create an “/api/…” URL, forcing a server error that resulted in the server returning an HTML page with embedded text from the URL. A response-splitting vulnerability was discovered in RabbitMQ. An /api/definitions URL could be specified, which then caused an arbitrary additional header to be returned. A remote attacker could use this flaw to inject arbitrary HTTP headers and possibly gain access to secure data.

Debian Security Advisory 3494-1

Debian Linux Security Advisory 3494-1 – Two SQL injection vulnerabilities were discovered in cacti, a web interface for graphing of monitoring systems. Specially crafted input can be used by an attacker in parameters of the graphs_new.php script to execute arbitrary SQL commands on the database.

Fing v3.3.0 iOS – Persistent Mail Encoding Vulnerability

Posted by Vulnerability Lab on Feb 29

Document Title:
===============
Fing v3.3.0 iOS – Persistent Mail Encoding Vulnerability

References (Source):
====================
http://www.vulnerability-lab.com/get_content.php?id=1772

Release Date:
=============
2016-02-29

Vulnerability Laboratory ID (VL-ID):
====================================
1772

Common Vulnerability Scoring System:
====================================
3.5

Product & Service Introduction:…