PEAR HTTP_Upload v1.0.0b3 Arbitrary File Upload

2017-01-25 Thread hyp3rlinx
[+] [+] Credits: John Page AKA Hyp3rlinx [+] Website: hyp3rlinx.altervista.org [+] Source: http://hyp3rlinx.altervista.org/advisories/PEAR-HTTP_UPLOAD-ARBITRARY-FILE-UPLOAD.txt [+] ISR: ApparitionSEC

[SECURITY] [DSA 3771-1] firefox-esr security update

2017-01-25 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 - - Debian Security Advisory DSA-3771-1 secur...@debian.org https://www.debian.org/security/ Moritz Muehlenhoff January 25, 2017

Google Forms WordPress Plugin unauthenticated PHP Object injection vulnerability

2017-01-25 Thread Summer of Pwnage
Google Forms WordPress Plugin unauthenticated PHP Object injection vulnerability Yorick Koster, June 2016

Cisco Security Advisory: Cisco TelePresence Multipoint Control Unit Remote Code Execution Vulnerability

2017-01-25 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco TelePresence Multipoint Control Unit Remote Code Execution Vulnerability Advisory ID: cisco-sa-20170125-telepresence Revision 1.0 For Public Release 2017 January 25 16:00 UTC (GMT

Cisco Security Advisory: Cisco Expressway Series and TelePresence VCS Denial of Service Vulnerability

2017-01-25 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco Expressway Series and TelePresence VCS Denial of Service Vulnerability Advisory ID: cisco-sa-20170125-expressway Revision 1.0 For Public Release 2017 January 25 16:00 UTC (GMT

Cisco Security Advisory: Cisco Adaptive Security Appliance CX Context-Aware Security Denial of Service Vulnerability

2017-01-25 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco Adaptive Security Appliance CX Context-Aware Security Denial of Service Vulnerability Advisory ID: cisco-sa-20170125-cas Revision 1.0 For Public Release 2017 January 25 16:00 UTC (GMT

ESA-2016-166: EMC Isilon OneFS Privilege Escalation Vulnerability

2017-01-25 Thread EMC Product Security Response Center
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 ESA-2016-166: EMC Isilon OneFS Privilege Escalation Vulnerability EMC Identifier: ESA-2016-166 CVE Identifier: CVE-2016-9871 Severity Rating: CVSS v3 Base Score: 7.2 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected products: • EMC Isilon

OpenCart 2.3.0.2 CSRF - User Account Takeover

2017-01-25 Thread Open Security
===[ Introduction ]=== OpenCart is a free open source ecommerce platform for online merchants. OpenCart provides a professional and reliable foundation from which to build a successful online store. ===[ Description ]=== There is a security vulnerability in OpenCart 2.3.0.2 which allows a