Databáze Hot News 2015 March - 2015 January February March April May June July August September October November December


7.3.2015

Bugtraq

Last Call - Workhsops of CISTI'2015: 10th Iberian Conference on Information Systems and Technologies 2015-03-05
ML (marialemos72 gmail com)

Ultimate PHP Board (UPB) 2.2.7 Cross Site Scripting Vulnerability 2015-03-05
prathan ptr gmail com

[ MDVSA-2015:054 ] bind 2015-03-04
security mandriva com

WeBid 1.1.1 Unrestricted File Upload Exploit 2015-03-04
prathan ptr gmail com

[ MDVSA-2015:055 ] freetype2 2015-03-04
security mandriva com

Malware

RDN/Generic.grp!hy

Generic PUP.x!47D5B92EC2DE

Generic Downloader.x!C3BE171842B5

RDN/Generic BackDoor!bbv!681E8DE9F748

Generic.bfr!6EABCAE20244

RDN/Generic.bfr!id!89DA4F0B9AFE

RDN/Generic BackDoor!bbv!63D0D36E010A

Generic.dx!9DA85BB0FFAB

Generic FakeAlert!E35608C04D28

RDN/Generic.tfr!ei!40A74770E65E

RDN/Generic.tfr!ei!57CF1966A13B

RDN/Generic.bfr!id!744B66331525

W32/Spybot.bfr!0391BECB1EFF

RDN/Generic.dx!64703124682A

RDN/Generic PUP.x!C3C9518B2E91

Generic.bfr!AC16DBD5D6E8

RDN/Generic.bfr!id!3A6E60A6E410

RDN/Generic.tfr!ei!2DD5F2DB4CCF

RDN/Generic PWS.y!FA849BA90082

Generic Downloader.x!3F5003F05153

RDN/Generic.dx!djn!3316DFE3E56C

RDN/Generic.dx!djn!3104020682F0

RDN/Generic BackDoor!bbv!3B3C64828E7B

RDN/Generic BackDoor!bbv!4882A71A6585

RDN/Generic PUP.x!0AF6343C4EAB

RDN/Generic.bfr!id!26DB9531DF97

RDN/Generic.dx!djn!3BAFE3140147

Generic PUP.x!DDE5C72A8342

Generic PUP.z!F996094B0BA4

RDN/Generic.bfr!1A1B5134B133

Phishing

TV Stream

7th March 2015

Watch TV!

David

6th March 2015

POST FREE CLASSIFIED ADS ON
ADSROAD

Paypal

6th March 2015

YOUR PAYPAL ACCOUNT HAS BEEN
LIMITED

Wells Fargo

6th March 2015

[ WELLS FARGO ] IMPORTANT
NOTIFICATION

PayPal

6th March 2015

PayPal: View your recent
activity

Security Centre

5th March 2015

UPDATE YOUR INFORMATION

Barclays

4th March 2015

Barclays - Important
Notification.

PayPal

4th March 2015

Issue PP-001-487-280-335

Vulnerebility

Drupal Global Redirect Module Open Redirection Vulnerability
2015-02-28
http://www.securityfocus.com/bid/54002

Bitweaver 'rankings.php' Local File Include Vulnerability
2015-02-28
http://www.securityfocus.com/bid/52176

IBM DB2 Administration Server (DAS) 'validateUser()' Stack Buffer Overflow Vulnerability
2015-02-28
http://www.securityfocus.com/bid/46077

IBM WebSphere Application Server for z/OS Multiple Unspecified Cross Site Scripting Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43874

ENOVIA Unspecified Security Vulnerability
2015-02-28
http://www.securityfocus.com/bid/44509

SilverStripe Unspecified Cross Site Request Forgery Vulnerability
2015-02-28
http://www.securityfocus.com/bid/44768

IBM Systems Director Agent 'reset_diragent_keys' Insecure File Permissions Vulnerability
2015-02-28
http://www.securityfocus.com/bid/44839

SilverStripe Multiple Remote Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/45367

TYPO3 Core TYPO3-SA-2010-022 Multiple Remote Security Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/45470

webConductor 'default.asp' SQL Injection Vulnerability
2015-02-28
http://www.securityfocus.com/bid/41042

IBM Tivoli Directory Server 'DIGEST-MD5' Denial of Service Vulnerability
2015-02-28
http://www.securityfocus.com/bid/42093

IBM WebSphere Service Registry and Repository Multiple Cross Site Scripting Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/42281

IBM Tivoli Storage Manager FastBack Remote Code Execution and Denial of Service Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/42549

IBM Records Manager Multiple Unspecified Remote Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43136

IBM AIX Local Privilege Escalation and Security Bypass Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43207

IBM DB2 prior to 9.7 Fix Pack 3 Multiple Security Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43291

Blue Coat ProxySG Unspecified Cross Site Scripting Vulnerability
2015-02-28
http://www.securityfocus.com/bid/43675

IBM Tivoli Access Manager for e-business Multiple Cross Site Scripting Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/44382

IBM Tivoli Directory Server Multiple Denial of Service Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/44604

Apple Safari 'setInterval()' Address Bar Spoofing Vulnerability
2015-02-28
http://www.securityfocus.com/bid/52323

eGroupware Multiple Input Validation Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/52770

IBM WebSphere ILOG JRules Cross Site Scripting Vulnerability
2015-02-28
http://www.securityfocus.com/bid/41030

IBM Rational ClearQuest Unspecified Security Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/41205

IBM FileNet Application Engine Multiple Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43271

MyBB Multiple Security Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/50816

XChat Remote Denial of Service Vulnerability
2015-02-28
http://www.securityfocus.com/bid/50820

AnGuanJia Remote Unauthorized Access Vulnerability
2015-02-28
http://www.securityfocus.com/bid/51695

Apple Mac OS X Apple Type Services '.dfont' Font File Memory Corruption Vulnerability
2015-02-28
http://www.securityfocus.com/bid/51832

WordPress s2Member Pro Plugin 'Coupon Code' Field HTML Injection Vulnerability
2015-02-28
http://www.securityfocus.com/bid/51997

Dotclear 'swfupload.swf' Remote Arbitrary File Upload Vulnerability
2015-02-28
http://www.securityfocus.com/bid/52173

Exploit

  HP Data Protector 8.10 Remote Command Execution

  ProjectSend r561 - SQL Injection Vulnerability

4.3.2015

Bugtraq

[ MDVSA-2015:054 ] bind 2015-03-04
security mandriva com

WeBid 1.1.1 Unrestricted File Upload Exploit 2015-03-04
prathan ptr gmail com

[ MDVSA-2015:055 ] freetype2 2015-03-04
security mandriva com

[CVE-2015-2102] Clipbucket 2.7 RC3 0.9 - Blind SQL Injection 2015-03-04
prathan ptr gmail com

[SECURITY] [DSA 3179-1] icedove security update 2015-03-03
Moritz Muehlenhoff (jmm debian org)

[security bulletin] HPSBST03265 rev.1 - HP VMA SAN Gateway running Bash Shell and OpenSSL, Remote Denial of Service (DoS), Unauthorized Access, and Disclosure of Information 2015-03-03
security-alert hp com

[ MDVSA-2015:052 ] tomcat 2015-03-03
security mandriva com

Malware

RDN/Generic.grp!hy

Generic PUP.x!47D5B92EC2DE

Generic Downloader.x!C3BE171842B5

RDN/Generic BackDoor!bbv!681E8DE9F748

Generic.bfr!6EABCAE20244

RDN/Generic.bfr!id!89DA4F0B9AFE

RDN/Generic BackDoor!bbv!63D0D36E010A

Generic.dx!9DA85BB0FFAB

Generic FakeAlert!E35608C04D28

RDN/Generic.tfr!ei!40A74770E65E

RDN/Generic.tfr!ei!57CF1966A13B

RDN/Generic.bfr!id!744B66331525

W32/Spybot.bfr!0391BECB1EFF

RDN/Generic.dx!64703124682A

RDN/Generic PUP.x!C3C9518B2E91

Generic.bfr!AC16DBD5D6E8

RDN/Generic.bfr!id!3A6E60A6E410

RDN/Generic.tfr!ei!2DD5F2DB4CCF

RDN/Generic PWS.y!FA849BA90082

Generic Downloader.x!3F5003F05153

RDN/Generic.dx!djn!3316DFE3E56C

RDN/Generic.dx!djn!3104020682F0

RDN/Generic BackDoor!bbv!3B3C64828E7B

RDN/Generic BackDoor!bbv!4882A71A6585

RDN/Generic PUP.x!0AF6343C4EAB

RDN/Generic.bfr!id!26DB9531DF97

RDN/Generic.dx!djn!3BAFE3140147

Generic PUP.x!DDE5C72A8342

Generic PUP.z!F996094B0BA4

RDN/Generic.bfr!1A1B5134B133

Phishing

Barclays

4th March 2015

Barclays - Important
Notification.

PayPal

4th March 2015

Issue PP-001-487-280-335

Vulnerebility

Drupal Global Redirect Module Open Redirection Vulnerability
2015-02-28
http://www.securityfocus.com/bid/54002

Bitweaver 'rankings.php' Local File Include Vulnerability
2015-02-28
http://www.securityfocus.com/bid/52176

IBM DB2 Administration Server (DAS) 'validateUser()' Stack Buffer Overflow Vulnerability
2015-02-28
http://www.securityfocus.com/bid/46077

IBM WebSphere Application Server for z/OS Multiple Unspecified Cross Site Scripting Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43874

ENOVIA Unspecified Security Vulnerability
2015-02-28
http://www.securityfocus.com/bid/44509

SilverStripe Unspecified Cross Site Request Forgery Vulnerability
2015-02-28
http://www.securityfocus.com/bid/44768

IBM Systems Director Agent 'reset_diragent_keys' Insecure File Permissions Vulnerability
2015-02-28
http://www.securityfocus.com/bid/44839

SilverStripe Multiple Remote Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/45367

TYPO3 Core TYPO3-SA-2010-022 Multiple Remote Security Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/45470

webConductor 'default.asp' SQL Injection Vulnerability
2015-02-28
http://www.securityfocus.com/bid/41042

IBM Tivoli Directory Server 'DIGEST-MD5' Denial of Service Vulnerability
2015-02-28
http://www.securityfocus.com/bid/42093

IBM WebSphere Service Registry and Repository Multiple Cross Site Scripting Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/42281

IBM Tivoli Storage Manager FastBack Remote Code Execution and Denial of Service Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/42549

IBM Records Manager Multiple Unspecified Remote Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43136

IBM AIX Local Privilege Escalation and Security Bypass Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43207

IBM DB2 prior to 9.7 Fix Pack 3 Multiple Security Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43291

Blue Coat ProxySG Unspecified Cross Site Scripting Vulnerability
2015-02-28
http://www.securityfocus.com/bid/43675

IBM Tivoli Access Manager for e-business Multiple Cross Site Scripting Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/44382

IBM Tivoli Directory Server Multiple Denial of Service Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/44604

Apple Safari 'setInterval()' Address Bar Spoofing Vulnerability
2015-02-28
http://www.securityfocus.com/bid/52323

eGroupware Multiple Input Validation Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/52770

IBM WebSphere ILOG JRules Cross Site Scripting Vulnerability
2015-02-28
http://www.securityfocus.com/bid/41030

IBM Rational ClearQuest Unspecified Security Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/41205

IBM FileNet Application Engine Multiple Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43271

MyBB Multiple Security Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/50816

XChat Remote Denial of Service Vulnerability
2015-02-28
http://www.securityfocus.com/bid/50820

AnGuanJia Remote Unauthorized Access Vulnerability
2015-02-28
http://www.securityfocus.com/bid/51695

Apple Mac OS X Apple Type Services '.dfont' Font File Memory Corruption Vulnerability
2015-02-28
http://www.securityfocus.com/bid/51832

WordPress s2Member Pro Plugin 'Coupon Code' Field HTML Injection Vulnerability
2015-02-28
http://www.securityfocus.com/bid/51997

Dotclear 'swfupload.swf' Remote Arbitrary File Upload Vulnerability
2015-02-28
http://www.securityfocus.com/bid/52173

Exploit

  Symantec Web Gateway 5 restore.php Post Authentication Command Injection

  Seagate Business NAS Unauthenticated Remote Command Execution

  Solarwinds Orion Service - SQL Injection Vulnerabilities

  BEdita CMS 3.5.0 - Multiple Vulnerabilities

  PHPMoAdmin Unauthorized Remote Code Execution (0-Day)

  Linux Kernel IRET Instruction #SS Fault Handling - Crash PoC

  Linux Kernel PPP-over-L2TP Socket Level Handling - Crash PoC

  Linux Kernel Associative Array Garbage Collection - Crash PoC

2.3.2015

Bugtraq

[ MDVSA-2015:049 ] cups 2015-03-02
security mandriva com

[CVE-2015-1583] ATutor LCMS - CSRF Vulnerability in Version 2.2 2015-02-28
edricteo outlook sg

BEdita CMS - XSS & CSRF Vulnerability in Version 3.5.0 2015-02-28
edricteo outlook sg

SEC Consult SA-20150227-0 :: Multiple vulnerabilities in Loxone Smart Home 2015-02-27
SEC Consult Vulnerability Lab (research sec-consult com)

Wordpress Media Cleaner Plugin - XSS Vulnerability 2015-02-27
iletisim ismailsaygili com tr

[SECURITY] CVE-2015-0254 XXE and RCE via XSL extension in JSTL XML tags 2015-02-27
Jeremy Boynes (jboynes apache org)

Malware

Generic PUP.x!47D5B92EC2DE

Generic Downloader.x!C3BE171842B5

RDN/Generic BackDoor!bbv!681E8DE9F748

Generic.bfr!6EABCAE20244

RDN/Generic.bfr!id!89DA4F0B9AFE

RDN/Generic BackDoor!bbv!63D0D36E010A

Generic.dx!9DA85BB0FFAB

Generic FakeAlert!E35608C04D28

RDN/Generic.tfr!ei!40A74770E65E

RDN/Generic.tfr!ei!57CF1966A13B

RDN/Generic.bfr!id!744B66331525

W32/Spybot.bfr!0391BECB1EFF

RDN/Generic.dx!64703124682A

RDN/Generic PUP.x!C3C9518B2E91

Generic.bfr!AC16DBD5D6E8

RDN/Generic.bfr!id!3A6E60A6E410

RDN/Generic.tfr!ei!2DD5F2DB4CCF

RDN/Generic PWS.y!FA849BA90082

Generic Downloader.x!3F5003F05153

RDN/Generic.dx!djn!3316DFE3E56C

RDN/Generic.dx!djn!3104020682F0

RDN/Generic BackDoor!bbv!3B3C64828E7B

RDN/Generic BackDoor!bbv!4882A71A6585

RDN/Generic PUP.x!0AF6343C4EAB

RDN/Generic.bfr!id!26DB9531DF97

RDN/Generic.dx!djn!3BAFE3140147

Generic PUP.x!DDE5C72A8342

Generic PUP.z!F996094B0BA4

RDN/Generic.bfr!1A1B5134B133

Generic.dx!E87F1C1B381E

Phishing

Satya Vathi

2nd March 2015

BANCA IMI SECURITIES CORP.

Satya Vathi

2nd March 2015

BANK ASIA LTD

PayPal

2nd March 2015

[PayPal] your account
information appears to be
missing

PayPal

2nd March 2015

IMPORTANT: Please re-update
your account information.

EARTH LINK RDP

1st March 2015

WE RE-SELL GENUINE EARTHLINK
RDPS( CHANGE OF WEBSITE)

Santander UK

1st March 2015

Santander Bank Important
Notification

Halifax

1st March 2015

Update Your Online Account

Payments

1st March 2015

YOUR PENDING PURCHASE

Marilynn Johengen

1st March 2015

Now you can take control over
every situation, Deb S!!

service@paypal.co.uk

28th February 2015

YOUR ACCOUNT PAYPAL HAS BEEN
LIMITED.

Service PayPal

27th February 2015

Your account is currently
restricted.

Alert

27th February 2015

3гԁ NotіcÐľ | PаymÐľnt
DeclіnÐľÔ

Apple Team

27th February 2015

VERIFY YOUR APPLE ID

Vulnerebility

Drupal Global Redirect Module Open Redirection Vulnerability
2015-02-28
http://www.securityfocus.com/bid/54002

Bitweaver 'rankings.php' Local File Include Vulnerability
2015-02-28
http://www.securityfocus.com/bid/52176

IBM DB2 Administration Server (DAS) 'validateUser()' Stack Buffer Overflow Vulnerability
2015-02-28
http://www.securityfocus.com/bid/46077

IBM WebSphere Application Server for z/OS Multiple Unspecified Cross Site Scripting Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43874

ENOVIA Unspecified Security Vulnerability
2015-02-28
http://www.securityfocus.com/bid/44509

SilverStripe Unspecified Cross Site Request Forgery Vulnerability
2015-02-28
http://www.securityfocus.com/bid/44768

IBM Systems Director Agent 'reset_diragent_keys' Insecure File Permissions Vulnerability
2015-02-28
http://www.securityfocus.com/bid/44839

SilverStripe Multiple Remote Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/45367

TYPO3 Core TYPO3-SA-2010-022 Multiple Remote Security Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/45470

webConductor 'default.asp' SQL Injection Vulnerability
2015-02-28
http://www.securityfocus.com/bid/41042

IBM Tivoli Directory Server 'DIGEST-MD5' Denial of Service Vulnerability
2015-02-28
http://www.securityfocus.com/bid/42093

IBM WebSphere Service Registry and Repository Multiple Cross Site Scripting Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/42281

IBM Tivoli Storage Manager FastBack Remote Code Execution and Denial of Service Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/42549

IBM Records Manager Multiple Unspecified Remote Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43136

IBM AIX Local Privilege Escalation and Security Bypass Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43207

IBM DB2 prior to 9.7 Fix Pack 3 Multiple Security Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43291

Blue Coat ProxySG Unspecified Cross Site Scripting Vulnerability
2015-02-28
http://www.securityfocus.com/bid/43675

IBM Tivoli Access Manager for e-business Multiple Cross Site Scripting Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/44382

IBM Tivoli Directory Server Multiple Denial of Service Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/44604

Apple Safari 'setInterval()' Address Bar Spoofing Vulnerability
2015-02-28
http://www.securityfocus.com/bid/52323

eGroupware Multiple Input Validation Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/52770

IBM WebSphere ILOG JRules Cross Site Scripting Vulnerability
2015-02-28
http://www.securityfocus.com/bid/41030

IBM Rational ClearQuest Unspecified Security Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/41205

IBM FileNet Application Engine Multiple Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/43271

MyBB Multiple Security Vulnerabilities
2015-02-28
http://www.securityfocus.com/bid/50816

XChat Remote Denial of Service Vulnerability
2015-02-28
http://www.securityfocus.com/bid/50820

AnGuanJia Remote Unauthorized Access Vulnerability
2015-02-28
http://www.securityfocus.com/bid/51695

Apple Mac OS X Apple Type Services '.dfont' Font File Memory Corruption Vulnerability
2015-02-28
http://www.securityfocus.com/bid/51832

WordPress s2Member Pro Plugin 'Coupon Code' Field HTML Injection Vulnerability
2015-02-28
http://www.securityfocus.com/bid/51997

Dotclear 'swfupload.swf' Remote Arbitrary File Upload Vulnerability
2015-02-28
http://www.securityfocus.com/bid/52173

Exploit

Seagate Business NAS <= 2014.00319 - Pre-Authentication Remote Code Execution (0day)