MyBB Prior to 1.8.7 Multiple Security Vulnerabilities
Monthly Archives: November 2016
Vuln: MyBB Prior to 1.8.6 Multiple Security Vulnerabilities
MyBB Prior to 1.8.6 Multiple Security Vulnerabilities
Vuln: MyBB Versions Prior To 1.8.8 Multiple Security Vulnerabilities
MyBB Versions Prior To 1.8.8 Multiple Security Vulnerabilities
DCFM Blog 0.9.7 Cross Site Scripting
DCFM Blog version 0.9.7 suffers from a cross site scripting vulnerability.
DCFM Blog 0.9.7 Blind SQL Injection
DCFM Blog version 0.9.7 suffers from a remote blind SQL injection vulnerability.
Ubuntu Security Notice USN-3130-1
Ubuntu Security Notice 3130-1 – It was discovered that OpenJDK did not restrict the set of algorithms used for Jar integrity verification. An attacker could use this to modify without detection the content of a JAR file, affecting system integrity. It was discovered that the JMX component of OpenJDK did not sufficiently perform classloader consistency checks. An attacker could use this to bypass Java sandbox restrictions. Various other issues were also addressed.
Red Hat Security Advisory 2016-2802-01
Red Hat Security Advisory 2016-2802-01 – OpenSSL is a toolkit that implements the Secure Sockets Layer and Transport Layer Security protocols, as well as a full-strength general-purpose cryptography library. Security Fix: A memory leak flaw was found in the way OpenSSL handled TLS status request extension data during session renegotiation. A remote attacker could cause a TLS server using OpenSSL to consume an excessive amount of memory and, possibly, exit unexpectedly after exhausting all available memory, if it enabled OCSP stapling support.
Red Hat Security Advisory 2016-2808-01
Red Hat Security Advisory 2016-2808-01 – This release of Red Hat JBoss Web Server 2.1.2 serves as a replacement for Red Hat JBoss Web Server 2.1.1. It contains security fixes for the Tomcat 7 component. Only users of the Tomcat 7 component in JBoss Web Server need to apply the fixes delivered in this release. Security Fix: A CSRF flaw was found in Tomcat’s the index pages for the Manager and Host Manager applications. These applications included a valid CSRF token when issuing a redirect as a result of an unauthenticated request to the root of the web application. This token could then be used by an attacker to perform a CSRF attack.
Red Hat Security Advisory 2016-2807-01
Red Hat Security Advisory 2016-2807-01 – Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages technologies. This release of Red Hat JBoss Web Server 2.1.2 serves as a replacement for Red Hat JBoss Web Server 2.1.1. It contains security fixes for the Tomcat 7 component. Only users of the Tomcat 7 component in JBoss Web Server need to apply the fixes delivered in this release. Security Fix: A CSRF flaw was found in Tomcat’s the index pages for the Manager and Host Manager applications. These applications included a valid CSRF token when issuing a redirect as a result of an unauthenticated request to the root of the web application. This token could then be used by an attacker to perform a CSRF attack.
WordPress Answer My Question 1.3 SQL Injection
WordPress Answer My Question plugin version 1.3 suffers from a remote SQL injection vulnerability.