Kunena Forum Extension for Joomla Multiple SQL Injection Vulnerabilities

2014-07-30 Thread vulns
Kunena forum extension for Joomla multiple SQL injection vulnerabilities Class: Input Validation Error CVE:N/A Remote: Yes Local: No Published: 02/07/2014 Credit: Raymond Rizk of Dionach

Kunena Forum Extension for Joomla Multiple Reflected Cross-Site Scripting Vulnerabilities

2014-07-30 Thread vulns
Kunena forum extension for Joomla multiple reflected cross-site scripting vulnerabilities Class: Input Validation Error CVE N/A Remote Yes Local No Published 02/07/2014 Credit Raymond Rizk of

Re: [FD] Beginner's error: import function of Windows Mail executes rogue program C:\Program.exe with credentials of other account

2014-07-30 Thread Stefan Kanthak
Michael Cramer mike.cra...@outlook.com wrote: sudo make-me-a-sandwich.py How is this different from any other temporary, per-process elevation system? 0. neither sudo nor make-me-a-sandwich.py nor the OS where these programs typically run have a CreateProcess*() system call which

Re: [FD] Beginner's error: import function of Windows Mail executes rogue program C:\Program.exe with credentials of other account

2014-07-30 Thread Stefan Kanthak
Michael Cramer mike.cra...@outlook.com wrote: I think you're arguing semantics here. Of course. Of course the specifics of how a particular program is executed will be different between command line and GUI-based OS'. Really? Is there any need for this difference you state? BTW: what is the

[SECURITY] [DSA 2992-1] linux security update

2014-07-30 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2992-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso July 29, 2014

WiFi HD v7.3.0 iOS - Multiple Web Vulnerabilities

2014-07-30 Thread Vulnerability Lab
Document Title: === WiFi HD v7.3.0 iOS - Multiple Web Vulnerabilities References (Source): http://www.vulnerability-lab.com/get_content.php?id=1283 Release Date: = 2014-07-29 Vulnerability Laboratory ID (VL-ID):

Barracuda Networks Web Application Firewall v6.1.5 LoadBalancer v4.2.2 #37 - Filter Bypass Multiple Vulnerabilities

2014-07-30 Thread Vulnerability Lab
Document Title: === Barracuda Networks Web Application Firewall v6.1.5 LoadBalancer v4.2.2 #37 - Filter Bypass Multiple Vulnerabilities References (Source): http://www.vulnerability-lab.com/get_content.php?id=1103 Barracuda Networks Security ID (BNSEC):

[Onapsis Security Advisory 2014-021] SAP HANA XS Missing encryption in form-based authentication

2014-07-30 Thread Onapsis Research Labs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Onapsis Security Advisory 2014-021: SAP HANA XS Missing encryption in form-based authentication This advisory can be downloaded in PDF format from http://www.onapsis.com/. By downloading this advisory from the Onapsis Resource Center, you will gain

[Onapsis Security Advisory 2014-025] Multiple Cross Site Scripting Vulnerabilities in SAP HANA XS Administration Tool

2014-07-30 Thread Onapsis Research Labs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Onapsis Security Advisory 2014-025: Multiple Cross Site Scripting Vulnerabilities in SAP HANA XS Administration Tool This advisory can be downloaded in PDF format from http://www.onapsis.com/. By downloading this advisory from the Onapsis Resource

[Onapsis Security Advisory 2014-026] Missing authorization check in function modules of BW-SYS-DB-DB4

2014-07-30 Thread Onapsis Research Labs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Onapsis Security Advisory 2014-026: Missing authorization check in function modules of BW-SYS-DB-DB4 This advisory can be downloaded in PDF format from http://www.onapsis.com/. By downloading this advisory from the Onapsis Resource Center, you will

[ MDVSA-2014:139 ] nss

2014-07-30 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2014:139 http://www.mandriva.com/en/support/security/

[Onapsis Security Advisory 2014-022] SAP HANA IU5 SDK Authentication Bypass

2014-07-30 Thread Onapsis Research Labs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Onapsis Security Advisory2014-022: SAP HANA IU5 SDK Authentication Bypass This advisory can be downloaded in PDF format from http://www.onapsis.com/. By downloading this advisory from the Onapsis Resource Center, you will gain access to beforehand

[Onapsis Security Advisory 2014-024] Hard-coded Username in SAP FI Manager Self-Service

2014-07-30 Thread Onapsis Research Labs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Onapsis Security Advisory 2014-024: Hard-coded Username in SAP FI Manager Self-Service This advisory can be downloaded in PDF format from http://www.onapsis.com/. By downloading this advisory from the Onapsis Resource Center, you will gain access

[Onapsis Security Advisory 2014-023] HTTP verb tampering issue in SAP_JTECHS

2014-07-30 Thread Onapsis Research Labs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Onapsis Security Advisory2014-023: HTTP verb tampering issue in SAP_JTECHS This advisory can be downloaded in PDF format from http://www.onapsis.com/. By downloading this advisory from the Onapsis Resource Center, you will gain access to beforehand

[ MDVSA-2014:141 ] java-1.7.0-openjdk

2014-07-30 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2014:141 http://www.mandriva.com/en/support/security/

[security bulletin] HPSBMU03078 rev.1 - HP CloudSystem Foundation and HP CloudSystem Enterprise Software running OpenSSL, Remote Unauthorized Access or Disclosure of Information

2014-07-30 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04385138 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04385138 Version: 1 HPSBMU03078

[ MDVSA-2014:140 ] owncloud

2014-07-30 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2014:140 http://www.mandriva.com/en/support/security/

Vulnerabilities in Facebook and Facebook Messenger for Android [STIC-2014-0529]

2014-07-30 Thread Programa STIC
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Security advisory of Programa STIC at FundaciĆ³n Dr. Manuel Sadosky www.fundacionsadosky.org.ar Vulnerabilities in Facebook and Facebook Messenger for Android 1. *Advisory Information* Title: Vulnerabilities in Facebook and