Drupal Revisioning Information Disclosure Security Issue
Application: Drupal
Affected Version: version 7.x-1.7.
Vendor’s URL: Drupal Revisioning
Bug Type: Information Disclosure
Risk Level:
Solution:
Update to version 7.x-1.8.
Application: Drupal
Affected Version: version 7.x-1.7.
Vendor’s URL: Drupal Revisioning
Bug Type: Information Disclosure
Risk Level:
Solution:
Update to version 7.x-1.8.
Application: WordPress
Affected Version: versions prior to 2.9.3.
Vendor’s URL: Jetpack Plugin
Bug Type: Security Bypass
Risk Level: Critical
Solution:
Update to version 2.9.3.
Application: WordPress
Affected Version: versions prior to 3.8.2.
Vendor’s URL: WordPress
Bug Type: Security Bypass, Cross Site Scripting
Risk Level: Critical
Solution:
Update to version 3.8.3.
Application: WordPress
Affected Version: version 1.7.9 and other versions
Vendor’s URL: File Gallery Plugin
Bug Type: System Access
Risk Level: Critical
Solution:
Update to version 1.7.9.2.
Application: WordPress
Affected Version: version 1.2.2 and other versions.
Vendor’s URL: Work The Flow File Upload Plugin
Bug Type: File Upload
Risk Level: Critical
Solution:
No official solution is currently available.
Application: WordPress
Affected Version: version 5.0.5 and prior versions.
Vendor’s URL: Quick Page Post Redirect Plugin
Bug Type: Cross-Site Scripting
Risk Level: Critical
Solution:
Update to version 5.0.6.
Application: WordPress
Affected Version: version 1.2.0 and other versions.
Vendor’s URL: Linenity Theme
Bug Type: File Disclosure
Risk Level: Critical
Solution:
No official solution is currently available.
Application: Ektron CMS
Affected Version: versions prior to 9.00.
Vendor’s URL: Ektron CMS
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Upgrade to version 9.00 or later.
Application: WordPress
Affected Version: version 1.0.6 and other versions.
Vendor’s URL: Business Intelligence Lite Plugin
Bug Type: File Upload
Risk Level: Critical
Solution:
Update to version 1.1.
Application: Netvolution CMS
Affected Version: version 3 and other versions.
Vendor’s URL: Netvolution CMS
Bug Type: SQL Injection
Risk Level: Critical
Solution:
No official solution is currently available.
Application: Jorjweb
Affected Version: -
Vendor’s URL: Jorjweb
Bug Type: SQL Injection
Risk Level: Critical
Solution:
No official solution is currently available.
Application: WordPress
Affected Version: version 1.1.4 and other versions.
Vendor’s URL: The Cotton Theme
Bug Type: File Upload
Risk Level: Critical
Solution:
No official solution is currently available.
Application: Joomla!
Affected Version: version 1.6 and prior versions.
Vendor’s URL: AJAX Shoutbox Component
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 1.7.
Application: LuxCal Web Calendar
Affected Version: version 3.2.2 and other versions.
Vendor’s URL: LuxCal Web Calendar
Bug Type: Cross-Site Request Forgery and SQL Injection
Risk Level: Critical
Solution:
No official solution is currently available.
Application: WordPress
Affected Version: version 3.5.5 and prior versions.
Vendor’s URL: WP SlimStat Plugin
Bug Type: Script Insertion
Risk Level: Critical
Solution:
Update to version 3.5.6.
Application: WordPress
Affected Version: versions prior to 3.3.
Vendor’s URL: Relevanssi Plugin
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 3.3 or later.
Application: Joomla!
Affected Version: versions prior to 1.1.
Vendor’s URL: ODude Dir Component
Bug Type: unknown
Risk Level: Critical
Solution:
Update to version 1.1.
Application: Joomla!
Affected Version: versions 2.5.18, 3.2.1 and 3.2.2
Vendor’s URL: Joomla!
Bug Type: Security Bypass, Cross Site Scripting, SQL Injection
Risk Level: Critical
Solution:
Update to version 2.5.19 or 3.2.3.
Access Bypass, Content Management, Cross Site Scripting, SQL Injection
Application: WordPress
Affected Version: version 7.0.2 and prior versions.
Vendor’s URL: Search Everything Plugin
Bug Type: SQL Injection
Risk Level: Critical
Solution:
Update to version 7.0.3 or later.
Application: Drupal
Affected Version: 7.x-1.x versions prior to 7.x-2.0.
Vendor’s URL: Slickgrid Module
Bug Type: Security Bypass
Risk Level: Critical
Solution:
Update to version 7.x-2.0.