[KIS-2014-09] X2Engine = 4.1.7 (SiteController.php) PHP Object Injection Vulnerability

2014-09-24 Thread Egidio Romano
- X2Engine = 4.1.7 (SiteController.php) PHP Object Injection Vulnerability - [-] Software Link: http://www.x2engine.com/ [-] Affected Versions: All

[KIS-2014-10] X2Engine = 4.1.7 (FileUploadsFilter.php) Unrestricted File Upload Vulnerability

2014-09-24 Thread Egidio Romano
X2Engine = 4.1.7 (FileUploadsFilter.php) Unrestricted File Upload Vulnerability [-] Software Link: http://www.x2engine.com/ [-]

CVE-2014-6603 suricata 2.0.3 Out-of-bounds access in SSH parser

2014-09-24 Thread Steffen Bauch
CVE-2014-6603 suricata 2.0.3 Out-of-bounds access in SSH application parser 1. Background Suricata is a high performance Network IDS, IPS and Network Security Monitoring engine developed by the Open Information Security Foundation (OISF). 2. Summary Information It was found out that the

[SECURITY] [DSA 3031-1] apt security update

2014-09-24 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3031-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso September 23, 2014