Ebay Inc Magento ProStore CP #4 - Filter Validation Bypass Persistent (Payment Information) Vulnerability

2014-08-05 Thread Vulnerability Lab
Document Title: === Ebay Inc Magento ProStore CP #4 - Filter Validation Bypass Persistent (Payment Information) Vulnerability References (Source): http://www.vulnerability-lab.com/get_content.php?id=1265 Ebay Inc ID: EIBBP-28091 Video:

[security bulletin] HPSBMU03083 rev.1 - HP BladeSystem c-Class Virtual Connect Firmware running OpenSSL, Remote Unauthorized Access or Disclosure of Information

2014-08-05 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04392919 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04392919 Version: 1 HPSBMU03083

Re: ownCloud Unencrypted Private Key Exposure

2014-08-05 Thread Frank Stanek
Hi, thank you for this announcement. I have a (very naive) question about this. As a consequence of this vulnerability an attacker with access to the ownCloud server's file system can compromise the encrypted data stored on the server. There does not seem to be a workaround for that and

CVE-2014-2595 - Authentication Bypass in Barracuda Web Application Firewall

2014-08-05 Thread Portcullis Advisories
Vulnerability title: Authentication Bypass in Barracuda Web Application Firewall CVE: CVE-2014-2595 Vendor: Barracuda Product: Web Application Firewall Affected version: Firmware v7.8.1.013 Fixed version: N/A Reported by: Nick Hayes Details: It is possible to re-use a link which includes a

[security bulletin] HPSBMU03037 rev.2 - HP Multimedia Service Environment (MSE), (HP Network Interactive Voice Response (NIVR)), Remote Disclosure of Information

2014-08-05 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 UPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04275280 Version: 2 HPSBMU03037 rev.2 - HP Multimedia Service Environment (MSE), (HP Network Interactive Voice Response (NIVR)), Remote Disclosure of Information NOTICE: The information in this

[CVE- Requested][Vembu Storegrid - Multiple Critical Vulnerabilities]

2014-08-05 Thread Mike Antcliffe
1. Advisory Overview Multiple vulnerabilities exist in the Vembu Storegrid Backup and Disaster Recovery solution affecting both the client and server software (see Additional Information section) include but are not limited to reflected XSS, source code/sensitive information disclosure,

Apache Cordova 3.5.1

2014-08-05 Thread Marcel Kinard
Android Platform Release: 04 Aug 2014 Security issues were discovered in the Android platform of Cordova. We are releasing version 3.5.1 of Cordova Android to address these security issues. We recommend that all Android applications built using Cordova be upgraded to use version 3.5.1 of

SEC Consult SA-20140805-0 :: Multiple vulnerabilities in Readsoft Invoice Processing and Process Director

2014-08-05 Thread SEC Consult Vulnerability Lab
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SEC Consult Vulnerability Lab Security Advisory 20140805-0 === title: Multiple vulnerabilities product: Readsoft Invoice Processing / Process Director

Pro Chat Rooms v8.2.0 - Multiple Vulnerabilities

2014-08-05 Thread mike . manzotti
# Exploit Title: Pro Chat Rooms v8.2.0 - Multiple Vulnerabilities # Google Dork: intitle:Powered by Pro Chat Rooms # Date: 5 August 2014 # Exploit Author: Mike Manzotti @ Dionach Ltd # Vendor Homepage: http://prochatrooms.com # Software Link: http://prochatrooms.com/software.php # Version: