Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.
Monthly Archives: July 2016
Vuln: Oracle Java SE CVE-2016-0636 Remote Security Bypass Vulnerability
Oracle Java SE CVE-2016-0636 Remote Security Bypass Vulnerability
Vuln: phpMyAdmin Security Bypass Vulnerability
phpMyAdmin Security Bypass Vulnerability
Vuln: Oracle Java SE and JRockit CVE-2016-3427 Remote Security Vulnerability
Oracle Java SE and JRockit CVE-2016-3427 Remote Security Vulnerability
Vuln: Oracle Java SE CVE-2016-3426 Remote Security Vulnerability
Oracle Java SE CVE-2016-3426 Remote Security Vulnerability
CVE-2015-0899
The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.
CVE-2016-1181
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899.
CVE-2016-1182
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899.
CVE-2016-3092
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
CVE-2016-4430
Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.