Dell OpenManager Server Administrator version 8.3 XML external entity exploit. Dell has contacted Packet Storm and has provided the following additional information: The Dell OpenManage Server Administrator (OMSA) product Linux installations has basic dependencies on the open source library libxml2. Customers using OMSA should upgrade to the latest libxml2 version 2.9.x as per the prerequisites mentioned in the installation guide on page 14 available here: http://topics-cdn.dell.com/pdf/dell-openmanage-server-administrator-v8.3_Install Guide_en-us.pdf. In general, users should use the most up-to-date versions as part of prudent computing practices.
d17fcc47a263830d3f8c7e93e9e5be745c51f553e740a9a88a4f51ea999dea0d
Mobiketa version 1.0 suffers from a cross site request forgery vulnerability.
3b8fa3723320cc3e1eb493e140404d57d7be05e61f32fa1d395eeaf72a4e1609
Fire Soft Board version 2.1 suffers from a cross site scripting vulnerability.
8ecc7d921eea8ece1c3aa8c25c4d25c1e494475dbda0b45a301c106933ac6000
Matrix42 Remote Control Host version 3.20.0031 suffers from an unquoted path privilege escalation vulnerability.
e928e0e77d5e3a73daa82ca9ccb8820d2bfefd76c5b214745cb8b14e5e842764
WordPress CM Ad Changer plugin version 1.7.7 suffers from a cross site scripting vulnerability.
c0be27eebca044470644e7a969b0287dff5a39a5a9e9b7408c2acf09861d5431
simplesamlphp versions prior to 1.14.4 suffers from a link injection / open redirection vulnerability.
efacbdf485bccc9a9b19bb5c86514b7a32b679c29eac99a314978a2372a299d8
swconfig, when run against the OpenWRT kernel, is able to change a switch chip's settings without CAP_NET_ADMIN permission. Patch for fix included.
66c9d8b673f993ecdd6813e69fcd1ab7678aee6d0a8a54505556d584264265e4
Split-Flap suffers from multiple cross site scripting vulnerabilities.
35c87e7e31c52cc94bef39ea7d12efe0eecaeb3b982e3cdc718846226d8c1a2f
Joomla Maqma Helpdesk component version 4.2.3 suffers from a cross site scripting vulnerability.
037463b72588a0f7112f5fedf275a5b38c414ee601d80605952e49f95fd72490