je.st
news
Tag: vulnerability
Joomla receives patches for zero-day SQL injection vulnerability
2014-03-10 19:12:52| InfoWorld: Top News
Recently released security updates for the popular Joomla CMS (content management system) address a SQL injection vulnerability that poses a high risk and can be exploited to extract information from the databases of Joomla-based sites. The Joomla Project released versions 3.2.3 and 2.5.19 of the open-source CMS Thursday. Both updates address two cross-site scripting (XSS) vulnerabilities in core components, but version 3.2.3 also patches a SQL injection flaw, publicly disclosed in early February, and an unauthorized log-in flaw in the Gmail-based authentication plug-in.
Tags: sql
receives
injection
patches
Apple's SSL iPhone vulnerability: How did it happen, and what next?
2014-02-25 19:19:48| Wireless - Topix.net
Apple has issued an urgent fix for a vulnerability in its SSL code, used to create secure connections to websites over Wi-Fi or other connections, for its iPhone, iPad and iPod Touch devices.
Exploit released for vulnerability targeted by Linksys router worm
2014-02-18 13:21:31| InfoWorld: Top News
Technical details about a vulnerability in Linksys routers that's being exploited by a new worm were released Sunday along with a proof-of-concept exploit and a larger than earlier expected list of potentially vulnerable device models. Last week, security researchers from the SANS Institute's Internet Storm Center identified a self-replicating malware program that exploits an authentication bypass vulnerability to infect Linksys routers. The worm has been named TheMoon.
Tags: released
targeted
router
exploit
Denial-of-service vulnerability puts Apache Tomcat servers at risk
2014-02-12 23:30:24| InfoWorld: Top News
Security researchers published a proof-of-concept exploit for a recently disclosed vulnerability that allows attackers to launch denial-of-service attacks against websites hosted on Apache Tomcat servers. Apache Tomcat is a widely used Web server for hosting applications developed with the Java Servlet and the JSP (JavaServer Pages) technologies.
Tags: risk
servers
puts
apache
Snapchat vulnerability can be exploited to crash iPhones, researcher says
2014-02-10 18:07:33| InfoWorld: Top News
A vulnerability in Snapchat allows attackers to launch denial-of-service attacks against users of the popular photo messaging app, causing their phones to become unresponsive and even crash. According to Jaime Sanchez, the security researcher who discovered the issue, authorization tokens accompanying Snapchat requests from authenticated users don't expire.
Tags: says
crash
researcher
vulnerability
Sites : [7] [8] [9] [10] [11] [12] [13] [14] [15] [16] [17] [18] [19] [20] [21] [22] [23] [24] [25] [26] next »