[SECURITY] [DSA 3117-1] php5 security update

2014-12-31 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3117-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso December 31, 2014

[KIS-2014-14] Osclass <= 3.4.2 (Search::setJsonAlert) SQL Injection Vulnerability

2014-12-31 Thread Egidio Romano
--- Osclass <= 3.4.2 (Search::setJsonAlert) SQL Injection Vulnerability --- [-] Software Link: http://osclass.org/ [-] Affected Versions: Version 3.4.2 and prob

[KIS-2014-15] Osclass <= 3.4.2 (ajax.php) Local File Inclusion Vulnerability

2014-12-31 Thread Egidio Romano
-- Osclass <= 3.4.2 (ajax.php) Local File Inclusion Vulnerability -- [-] Software Link: http://osclass.org/ [-] Affected Versions: Version 3.4.2 and probably prior vers

[KIS-2014-16] Osclass <= 3.4.2 (contact.php) Unrestricted File Upload Vulnerability

2014-12-31 Thread Egidio Romano
- Osclass <= 3.4.2 (contact.php) Unrestricted File Upload Vulnerability - [-] Software Link: http://osclass.org/ [-] Affected Versions: Version 3.4.2 an

[KIS-2014-18] Mantis Bug Tracker <= 1.2.17 (ImportXml.php) PHP Code Injection Vulnerability

2014-12-31 Thread Egidio Romano
- Mantis Bug Tracker <= 1.2.17 (ImportXml.php) PHP Code Injection Vulnerability - [-] Software Link: http://www.mantisbt.org/ [-] Affected Ver

[KIS-2014-19] Symantec Web Gateway <= 5.2.1 (restore.php) OS Command Injection Vulnerability

2014-12-31 Thread Egidio Romano
-- Symantec Web Gateway <= 5.2.1 (restore.php) OS Command Injection Vulnerability -- [-] Software Link: http://www.symantec.com/web-gateway/ [