Информационная безопасность
[RU] switch to English


Cводка уязвимостей безопасности в Web-приложениях (PHP, ASP, JSP, CGI, Perl)
Опубликовано:21 июня 2015 г.
Источник:
SecurityVulns ID:14550
Тип:удаленная
Уровень опасности:
5/10
Описание:Инъекции PHP, инъекции SQL, обратный путь в каталогах, межсайтовый скриптинг, модификация файлов, утечка информации и т.д.
Затронутые продукты:SEARCHBLOX : SearchBlox 8.2
 DRUPAL : drupal 7.38
 VESTACP : Vesta Control Panel 0.9
 TYPO3 : Akronymmanager 0.5
 BLACKCATCMS : BlackCat CMS 1.1
CVE:CVE-2015-4117
 CVE-2015-3422 (Cross-site scripting (XSS) vulnerability in SearchBlox before 8.2.1 allows remote attackers to inject arbitrary web script or HTML via the menu2 parameter to admin/main.jsp.)
 CVE-2015-3234 (The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.)
 CVE-2015-3233 (Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.)
 CVE-2015-3232 (Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter.)
 CVE-2015-3231 (The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.)
 CVE-2015-2803 (SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3 allows remote authenticated users with permission to maintain acronyms to execute arbitrary SQL commands via the id parameter.)
Оригинальный текстdocumentDEBIAN, [SECURITY] [DSA 3291-1] drupal7 security update (21.06.2015)
 documentHigh-Tech Bridge Security Research, OS Command Injection in Vesta Control Panel (21.06.2015)
 documentHigh-Tech Bridge Security Research, Reflected Cross-Site Scripting (XSS) in SearchBlox (21.06.2015)
 documentd4rkr0id_(at)_gmail.com, BlackCat CMS v1.1.1 Arbitrary File Download Vulnerability (21.06.2015)
 documentRedTeam Pentesting, [RT-SA-2015-002] SQL Injection in TYPO3 Extension Akronymmanager (21.06.2015)
 documentiedb.team_(at)_gmail.com, Productsurf Cms Sql Injection Vulnerability (21.06.2015)
 documentiedb.team_(at)_gmail.com, WebdesignJiNi Cms Sql Injection Vulnerability (21.06.2015)

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород