[Full-disclosure] Vulnerabilities in Contact Form 7 for WordPress

2014-01-31 Thread MustLive
Hello list! I want to inform you about vulnerabilities in Contact Form 7 plugin for WordPress. These are Code Execution via Arbitrary File Uploading vulnerabilities (two attack vectors). This is addition to previous Code Execution vulnerability in Contact Form 7 (http://seclists.org/fulldisclosu

[Full-disclosure] [SECURITY] [DSA 2850-1] libyaml security update

2014-01-31 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2850-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso January 31, 2014

[Full-disclosure] [SE-2013-01] Security vulnerabilities in Oracle Java Cloud Service

2014-01-31 Thread Security Explorations
Hello All, Those concerned about security of Java PaaS (Platform as a Service) or cloud services in general might find the following information interesting. Security Explorations discovered multiple security vulnerabilities in the environment of Oracle [1] Java Cloud Service [2]. Among a tota