Рейтинг
0.00
avatar

IT outsourcing Kemerovo

Подробнее ↓

IT outsourcing Kemerovo CVE-2014-4701 (nagios)

    The check_dhcp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4702.
      Теги:
    • нет
    • 0
    • 0
    • 0 комментариев

    IT outsourcing Kemerovo CVE-2014-3997 (it360, password_manager_pro)

      SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.
        Теги:
      • нет
      • 0
      • 0
      • 0 комментариев

      IT outsourcing Kemerovo CVE-2014-3996 (desktop_central, it360, password_manager_pro)

        SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to LinkViewFetchServlet.dat.
          Теги:
        • нет
        • 0
        • 0
        • 0 комментариев

        IT outsourcing Kemerovo CVE-2014-3627 (hadoop)

          The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive, which is not properly handled during localization, related to distributed cache.
            Теги:
          • нет
          • 0
          • 0
          • 0 комментариев

          IT outsourcing Kemerovo CVE-2014-3561 (enterprise_virtualization)

            The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.
              Теги:
            • нет
            • 0
            • 0
            • 0 комментариев

            IT outsourcing Kemerovo CVE-2012-6656 (glibc)

              iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of «0xffff» to the iconv function when converting IBM930 encoded data to UTF-8.
                Теги:
              • нет
              • 0
              • 0
              • 0 комментариев

              IT outsourcing Kemerovo CVE-2014-7868 (manageengine_it_plus, manageengine_it360, manageengine_opmanager)

                Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the (1) OPM_BVNAME parameter in a Delete operation to the APMBVHandler servlet or (2) query parameter in a compare operation to the DataComparisonServlet servlet.
                  Теги:
                • нет
                • 0
                • 0
                • 0 комментариев

                IT outsourcing Kemerovo CVE-2014-7867 (manageengine_it_plus, manageengine_it360, manageengine_opmanager)

                  SQL injection vulnerability in the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the probeName parameter.
                    Теги:
                  • нет
                  • 0
                  • 0
                  • 0 комментариев