Path traversal vulnerability in EMC MR (Watch4net) Device Discovery

2015-03-19 Thread Securify B.V.
Path traversal vulnerability in EMC MR (Watch4net) Device Discovery Han Sahin, November 2014

Cross-Site Scripting vulnerability in EMC MR (Watch4net) Web Portal Report Favorites

2015-03-19 Thread Securify B.V.
Cross-Site Scripting vulnerability in EMC MR (Watch4net) Web Portal Report Favorites Han Sahin, November 2014

Command injection vulnerability in EMC Secure Remote Services Virtual Edition

2015-03-19 Thread Securify B.V.
Command injection vulnerability in EMC Secure Remote Services Virtual Edition Han Sahin, November 2014

EMC MR (Watch4net) data storage collector credentials are not properly protected

2015-03-19 Thread Securify B.V.
EMC MR (Watch4net) data storage collector credentials are not properly protected Han Sahin, November 2014

Cross-Site Scripting vulnerability in EMC MR (Watch4net) Centralized Management Console

2015-03-19 Thread Securify B.V.
Cross-Site Scripting vulnerability in EMC MR (Watch4net) Centralized Management Console Han Sahin, November 2014

Path traversal vulnerability in EMC MR (Watch4net) MIB Browser

2015-03-19 Thread Securify B.V.
Path traversal vulnerability in EMC MR (Watch4net) MIB Browser Han Sahin, November 2014

EMC Secure Remote Services Virtual Edition Provisioning component is affected by SQL injection

2015-03-19 Thread Securify B.V.
EMC Secure Remote Services Virtual Edition Provisioning component is affected by SQL injection Han Sahin, November 2014

Cross-Site Scripting vulnerability in EMC MR (Watch4net) Alerting Frontend

2015-03-19 Thread Securify B.V.
Cross-Site Scripting vulnerability in EMC MR (Watch4net) Alerting Frontend Han Sahin, November 2014

Google Analytics by Yoast stored XSS

2015-03-19 Thread Jouko Pynnonen
OVERVIEW == Google Analytics by Yoast is a WordPress plug-in for monitoring website traffic. With approximately seven million downloads it’s one of the most popular WordPress plug-ins. A security vulnerability in the plug-in allows an unauthenticated attacker to store arbitrary HTML,

FreeBSD Security Advisory FreeBSD-SA-15:06.openssl

2015-03-19 Thread FreeBSD Security Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 = FreeBSD-SA-15:06.opensslSecurity Advisory The FreeBSD Project Topic:

cve-assign delays

2015-03-19 Thread Steven M. Christey
We recognize that some requesters have experienced delays, and sometimes lengthy delays, in getting CVE IDs assigned. We apologize for those delays. The number of cve-assign requests has been growing dramatically, as has the number of unique and new requesters. Our goal is always to provide

Advent JMX Servlet of Citrx Command Center is accessible to unauthenticated users

2015-03-19 Thread Securify B.V.
Advent JMX Servlet of Citrx Command Center is accessible to unauthenticated users Han Sahin, August 2014

Citrix NetScaler VPX help pages are vulnerable to Cross-Site Scripting

2015-03-19 Thread Securify B.V.
Citrix NetScaler VPX help pages are vulnerable to Cross-Site Scripting Han Sahin, August 2014

[SECURITY] [DSA 3197-1] openssl security update

2015-03-19 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-3197-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff March 19, 2015

Citrix NITRO SDK xen_hotfix page is vulnerable to Cross-Site Scripting

2015-03-19 Thread Securify B.V.
Citrix NITRO SDK xen_hotfix page is vulnerable to Cross-Site Scripting Han Sahin, August 2014

Command injection vulnerability in Citrix NITRO SDK xen_hotfix page

2015-03-19 Thread Securify B.V.
Command injection vulnerability in Citrix NITRO SDK xen_hotfix page Han Sahin, August 2014