[ MDVSA-2015:056 ] rpm

2015-03-09 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2015:056 http://www.mandriva.com/en/support/security/ __

ocPortal 9.0.16 Multiply XSS Vulnerabilities

2015-03-09 Thread dennis . veninga
# Exploit Title: ocPortal 9.0.16 Multiply XSS Vulnerabilities # Google Dork: "Copyright (c) ocPortal 2011 " # Date: 26-2-2015 # Exploit Author: Dennis Veninga # Vendor Homepage: http://ocportal.com/ # Vendor contacted: 22-2-2015 # Fix: http://ocportal.com/site/news/view/security_issues/xss-vulnera

[security bulletin] HPSBGN03277 rev.1 - HP Virtualization Performance Viewer, Remote Execution of Code, Denial of Service (DoS) and Other Vulnerabilities

2015-03-09 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04582466 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04582466 Version: 1 HPSBGN03277 r

MongoDB BSON Handling Remote Denial of Service Vulnerability

2015-03-09 Thread noreply-secresearch
MongoDB BSON Handling Remote Denial of Service Vulnerability March 06, 2015 Summary: Fortinet's FortiGuard Labs has discovered a remote denial of service vulnerability in MongoDB. It allows remote attackers to launch a denial of service attack without providing any authentication credent

[security bulletin] HPSBUX03235 SSRT101750 rev.3 - HP-UX Running BIND, Remote Denial of Service (DoS)

2015-03-09 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04550240 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04550240 Version: 3 HPSBUX03235 S

H2HC 12th Edition - Call for Papers

2015-03-09 Thread Rodrigo Rubira Branco (BSDaemon)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CALL FOR PAPERS - Hackers 2 Hackers Conference 12th edition The call for papers for H2HC 12th edition is now open. H2HC is a hacker conference taking place in Sao Paulo, Brazil, from 22 to 27 October 2015. [ - Introduction - ] For the twelveth cons

Betster (PHP Betoffice) Authentication Bypass and SQL Injection

2015-03-09 Thread prathan . ptr
http://betster.sourceforge.net/ Software Link : http://downloads.sourceforge.net/project/betster/betster-1.0.4.zip Version : 1.0.4 Tested on : Linux, PHP 5.3.9 SOFTWARE DESCRIPTION Betster is a Software to create a online bet-off

[security bulletin] HPSBPI03107 rev.2 - Certain HP LaserJet Printers, MFPs and Certain HP OfficeJet Enterprise Printers using OpenSSL, Remote Unauthorized Access

2015-03-09 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04451722 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04451722 Version: 2 HPSBPI03107 r

[security bulletin] HPSBHF03279 rev.1 - HP Point of Sale PCs Running Windows with OPOS Drivers, Remote Execution of Code

2015-03-09 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04583185 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04583185 Version: 1 HPSBHF03279 r

[slackware-security] samba (SSA:2015-064-01)

2015-03-09 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] samba (SSA:2015-064-01) New samba packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +--+ patches/packages/samba-4.1.1

[SECURITY] [DSA 3180-1] libarchive security update

2015-03-09 Thread Alessandro Ghedini
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-3180-1 secur...@debian.org http://www.debian.org/security/Alessandro Ghedini March 05, 2015

Stored XSS Vulnerability in Google Analytics by Yoast Wordpress Plugin

2015-03-09 Thread kingkaustubh
Stored XSS Vulnerability in Google Analytics by Yoast Wordpress Plugin . contents:: Table Of Content Overview Title :Stored XSS Vulnerability in Google Analytics by Yoast Wordpress Plugin Author: Kaustubh G. Padwad, Rohit Kumar. Plugin Homepage: https://yoast.com/wordpress/plugins/google-analyti