Hackers are targeting the Rio Olympics, so watch out for these cyberthreats – CSO
Monthly Archives: July 2016
Oracle Patches 27 Vulnerabilities
A total of 27 vulnerabilities have been patched by Oracle. These affect eBusiness Suite R12.x and 11.5, Apex, Primavera, OBIEE, and Agile DB components. These issues include SQL injection, cross site scripting, XXE injection, SSRF, failed access controls, and more.
Amazon Isn't Saying If Echo Has Been Wiretapped
Brazilian Judge Orders Another WhatsApp Block Over Message Encryption
Hackers Claim Credit For Crashing Pokemon Go
BlackBerry Chief: We Don't Have To Make Phones To Make Phones
Wowza Streaming Engine 4.5.0 Cross Site Scripting
Wowza Streaming Engine suffers from multiple reflected cross site scripting vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site. Version 4.5.0 build 18676 is affected.
Wowza Streaming Engine 4.5.0 Cleartext Sensitive Information Storage
Wowza Streaming Engine version 4.5.0 build 18676 stores sensitive information in cleartext within a resource that might be accessible to another control sphere. When the file is modified it is automatically applied into the application with newly created user account. Wowza stores sensitive information such as username and password in cleartext in admin.password file, which is readable by local users.
Wowza Streaming Engine 4.5.0 Cross Site Request Forgery
Wowza Streaming Engine version 4.5.0 build 18676 suffers from a cross site request forgery vulnerability.
Wowza Streaming Engine 4.5.0 Remote Privilege Escalation
The Wowza Streaming Engine application suffers from a privilege escalation issue. Normal user (read-only) can elevate his/her privileges by sending a POST request setting the parameter ‘accessLevel’ to ‘admin’ gaining admin rights and/or setting the parameter ‘advUser’ to ‘true’ and ‘_advUser’ to ‘on’ gaining advanced admin rights. Version 4.5.0 build 18676 is affected.