BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the ‘User-Agent’ field using a Time-based blind SLEEP payload.
Daily Archives: April 3, 2023
CVE-2022-38922
BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the ‘users-cookie-settings’ token using a Time-based blind SLEEP payload.
skopeo-1.11.2-1.fc37
FEDORA-2023-28c182b657
Packages in this update:
skopeo-1.11.2-1.fc37
Update description:
Security fix for CVE-2022-41723
skopeo-1.11.2-1.fc38
FEDORA-2023-ccaf5538dd
Packages in this update:
skopeo-1.11.2-1.fc38
Update description:
Security fix for CVE-2022-41723
CVE-2022-27665
Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. This can lead to execution of malicious code and commands on the client due to improper handling of user-provided input. By inputting malicious payloads in the subdirectory searchbar or Add folder filename boxes, it is possible to execute client-side commands. For example, there is Client-Side Template Injection via subFolderPath to the ThinClient/WtmApiService.asmx/GetFileSubTree URI.
Israeli cybersecurity firm launches managed services offering for MSPs
Israel-based managed cybersecurity provider Guardz has announced the general availability of its first cybersecurity offering for managed service providers (MSP) and IT professionals.
“The launch of this dedicated MSP platform brings Guardz one step closer to our goal of democratizing enterprise-grade level cybersecurity technologies,” said Dor Eisner, co-founder and CEO of Guardz. “MSPs will be able to give their clients the confidence that their business is secure from the inside out and gain complete visibility into their users’ cyber posture.”
Guardz’ namesake offering comes shortly after the company exited stealth in January with $10 million in seed funding. Company co-founder Eisner previously worked at the Israeli Military Intelligence as a cybersecurity team lead, while the other co-founder Alon Lavi was a staff sergeant at Israel Defense Forces before starting Guardz.
USN-5994-1: HAProxy vulnerability
It was discovered that HAProxy incorrectly initialized certain connection
buffers. A remote attacker could possibly use this issue to obtain
sensitive information.
USN-5993-1: Samba vulnerabilities
Demi Marie Obenour discovered that the Samba LDAP server incorrectly
handled certain confidential attribute values. A remote authenticated
attacker could possibly use this issue to obtain certain sensitive
information. (CVE-2023-0614)
Andrew Bartlett discovered that the Samba AD DC admin tool incorrectly
sent passwords in cleartext. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2023-0922)
USN-5992-1: ldb vulnerability
Demi Marie Obenour discovered that ldb, when used with Samba, incorrectly
handled certain confidential attribute values. A remote authenticated
attacker could possibly use this issue to obtain certain sensitive
information.
Hit the Road and Implement Your Cybersecurity Roadmap
When it’s time to put your cybersecurity roadmap into action, you might be wondering how to get started. Tony Sager has the answers.