New User, Welcome!     Login

<< Previous

web content

DynPG CMS v4.1.0 Multiple Remote File Inclusion Vulnerability

########################################################

Description:

DynPG is used to upload and manage dynamic web content similar to other content management systems.
DynPG however differs from other CMS, because it is embedded directly into websites.
The software was originally developed to realize designs that are created with Adobe Photoshop, Adobe Fireworks, Adobe Illustrator or any other graphics software.
The layout is created with an editor like Adobe Dreamweaver or Adobe GoLive or even as simple code.
After that, code snippets are placed at those points, where dynamically generated content (like articles, galleries, blogs or other dynamic content) shall be generated.
It provides a convenient way to extend existing websites with dynamic content. DynPG provides a template engine, but also supports existing CSS layouts.

[ MDVSA-2009:290-1 ] firefox

 incorrect file when opening it. Since this attack requires local
 access to the victim's machine, the severity of this vulnerability
 was determined to be low (CVE-2009-3274).
 
 Security researcher Paul Stone reported that a user's form history,
 both from web content as well as the smart location bar, was vulnerable
 to theft. A malicious web page could synthesize events such as mouse
 focus and key presses on behalf of the victim and trick the browser
 into auto-filling the form fields with history entries and then
 reading the entries (CVE-2009-3370).
 

[ MDVSA-2009:294 ] firefox

 incorrect file when opening it. Since this attack requires local
 access to the victim's machine, the severity of this vulnerability
 was determined to be low (CVE-2009-3274).
 
 Security researcher Paul Stone reported that a user's form history,
 both from web content as well as the smart location bar, was vulnerable
 to theft. A malicious web page could synthesize events such as mouse
 focus and key presses on behalf of the victim and trick the browser
 into auto-filling the form fields with history entries and then
 reading the entries (CVE-2009-3370).
 

[SECURITY] [DSA 1535-1] New iceweasel packages fix several vulnerabilities

    Authentication credentials with empty usernames, resulting
    in potential Cross-Site Request Forgery attacks.

CVE-2008-1240

    Gregory Fleischer discovered that web content fetched through
    the jar: protocol can use Java to connect to arbitrary ports.
    This is only an issue in combination with the non-free Java
    plugin.

CVE-2008-1241

eLineStudio Site Composer (ESC) <=2.6 Multiple Vulnerabilities

###################################################################################

####################
1. Description:
####################
        eLineStudio Site Composer is a 100% browser-based database-driven content management system that helps companies to better manage, update & share web content. eLineStudio Site Composer provides affordable & flexible licensing for end users & web developers.
####################
2. Vulnerabilities:
####################
        2.1. Injection Flaws, Cross Site Scripting (XSS). SQL Injection in "/ansFAQ.asp" in "id" parameter. Reflected XSS attack in "/ansFAQ.asp" in "topic" and "button" parameters.
                2.1.1. Exploit:

AR Web Content Manager (AWCM) Cross-Site scripting Vulnerability

Hi,

SecPod Research Team Member Antu Sanadi has found a XSS vulnerability in 
AR Web Content Manager (AWCM)

Advisory details has been attached to this mail.


Regards,
SecPod Research Team

[ GLSA 200804-20 ] Sun JDK/JRE: Multiple vulnerabilities

* Chris Evans of the Google Security Team discovered multiple
  unspecified vulnerabilities within the Java Runtime Environment Image
  Parsing Library (CVE-2008-1193, CVE-2008-1194).

* Gregory Fleischer reported that web content fetched via the "jar:"
  protocol was not subject to network access restrictions
  (CVE-2008-1195).

* Chris Evans and Johannes Henkel of the Google Security Team
  reported that the XML parsing code retrieves external entities even

PR08-02: Plone CMS Security Research - the Art of Plowning

Product description:

Plone is a ready-to-run content management system built on the powerful,
and free, Zope application server. Plone is easy to set up, extremely
flexible, and provides you with a system for managing web content that
is ideal for project groups, communities, web sites, extranets and
intranets.

Plone is designed with security in mind by addressing the 10 most common
security vulnerabilities in web applications (OWASP Top 10).

TransLucid 1.75 (fckeditor) Remote Arbitrary File Upload

####################
- Description:
####################

transLucid is the simple website publishing system with which anyone  
can create and maintain web content, in multiple languages and based  
on a
growing list of ready-made, professional layouts.

####################
- Vulnerability:

VUPEN Security Research - Adobe Shockwave 3D Two Remote Code Execution Vulnerabilities (CVE-2010-1284)

"Over 450 million Internet-enabled desktops have installed Adobe Shockwave
Player. These people now have access to some of the best the Web has to 
offer
including dazzling 3D games and entertainment, interactive product
demonstrations, and online learning applications. Shockwave Player displays
Web content that has been created by Adobe Director." from Adobe.com


II. DESCRIPTION
---------------------


eLineStudio Site Composer (ESC) <=2.6 Multiple Vulnerabilities

###################################################################################

####################
1. Description:
####################
        eLineStudio Site Composer is a 100% browser-based database-driven content management system that helps companies to better manage, update & share web content. eLineStudio Site Composer provides affordable & flexible licensing for end users & web developers.
####################
2. Vulnerabilities:
####################
        2.1. Injection Flaws, Cross Site Scripting (XSS). SQL Injection in "/ansFAQ.asp" in "id" parameter. Reflected XSS attack in "/ansFAQ.asp" in "topic" and "button" parameters.
                2.1.1. Exploit:

<<Previous

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!