Log Analyzer 3.6.0 - Cross Site Scripting Vulnerability

2012-12-28 Thread Vulnerability Lab
Title: == Log Analyzer 3.6.0 - Cross Site Scripting Vulnerability Date: = 2012-12-20 References: === http://www.vulnerability-lab.com/get_content.php?id=792 Vendor:

SonicWall Email Security 7.4.1.x - Persistent Web Vulnerability

2012-12-28 Thread Vulnerability Lab
Title: == SonicWall Email Security 7.4.1.x - Persistent Web Vulnerability Date: = 2012-12-21 References: === http://www.vulnerability-lab.com/get_content.php?id=768 VL-ID: = 768 Common Vulnerability Scoring System: 4.1

[SECURITY] [DSA 2591-1] mahara security update

2012-12-28 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2591-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff December 27, 2012

[SECURITY] [DSA 2592-1] elinks security update

2012-12-28 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2592-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff December 28, 2012

CubeCart 5.0.7 and lower versions | Insecure Backup File Handling

2012-12-28 Thread YGN Ethical Hacker Group
1. OVERVIEW CubeCart 5.0.7 and lower versions are vulnerable to Insecure Backup File Handling which leads to the disclosure of the application configuration file. 2. BACKGROUND CubeCart is an out of the box ecommerce shopping cart software solution which has been written to run on servers that