[SECURITY] [DSA 3547-1] imagemagick security update

2016-04-11 Thread Luciano Bello
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 - - Debian Security Advisory DSA-3547-1 secur...@debian.org https://www.debian.org/security/Luciano Bello April 11, 2016

ESA-2016-013: RSA BSAFE® Micro Edition Suite, Crypto-C Micro Edition, Crypto-J, SSL-J and SSL-C Lenstra’s Attack Vulnerability

2016-04-11 Thread Security Alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ESA-2016-013: RSA BSAFE® Micro Edition Suite, Crypto-C Micro Edition, Crypto-J, SSL-J and SSL-C Lenstra’s Attack Vulnerability EMC Identifier: ESA-2016-013 CVE Identifier: CVE-2016-0887 Severity Rating: CVSS v3 Base Score: 5.9

[Multiple CVE]: RCE, info disclosure, HQL injection and stored XSS in Novell Service Desk 7.1.0

2016-04-11 Thread Pedro Ribeiro
Hi, Novell Service Desk (now rebranded as Micro Focus Service Desk) 7.1.0 and below has a number of critical vulnerabilities that allow remote code execution, information disclosure, etc, by authenticated users. Check the full advisory below for details. Novell / Micro Focus have documented these

Directadmin cp ( Delete User ) 1.50.0 Version Xss Vulnerability

2016-04-11 Thread iedb . team
Xss Vulnerability in Directadmin cp ( Delete User ) on 1.50.0 And Old Version # # # @@@@@@@ @@@@@ @@@ # @@@@@@@@@ @@ @@@ @@@@@ # @@@@@@

Directadmin ControlPanel 1.50.0 Version Xss Vulnerability

2016-04-11 Thread iedb . team
Xss Vulnerability In Directadmin ControlPanel 1.50.0 and Old Version 1.4* Pic : http://kkli.ir/VPFl5 # # # @@@@@@@ @@@@@ @@@ # @@@@@@@@@ @@ @@@ @@@@@

OpenCart json_decode function Remote PHP Code Execution

2016-04-11 Thread r3s34rch3r
## # OpenCart json_decode function Remote PHP Code Execution # # Author: Naser Farhadi # Twitter: @naserfarhadi # # Date: 9 April 2016 # Version: 2.1.0.2 to 2.2.0.0 (Latest version) # Vendor Homepage: http://www.opencart.com/ # # Vulnerability: # # /upload/system/helper/json.php #