Tags › Security Advisory
Armorlogic Profense WAF: multiple vulnerabilities
Published on May 13, 2009 in CVE-2009-1594, CVE-2009-1593, profense, cross-site scripting, security advisory
An advisory by EnableSecurity. Trustwave published a joint advisory named TWSL2009-001.
- ID: ES-20090500
- Affected Versions: versions prior to 2.4.4 and 2.2.22
- Fixed versions: 2.4.4, 2.2.22 and later
- Enable Security Advisory: https://www.enablesecurity.com/advisories/ES2009-02-armorlogic-profense-multiple-vulnerabilities/
Description
Armorlogic Profense is a Web Application Firewall and load balancing solution.
From their website (armorlogic.com):
“Protecting and securing websites and web applications can be a complicated business. Profense web application firewall simplifies protection with an affordable and easy to use, feature rich, solution that gives you full PCI DSS 1.1 and 1.2 section 6.6 compliance.”
…
OpenX: multiple vulnerabilities
Published on Apr 1, 2009 in openx, cross-site scripting, sql injection, security advisory
An advisory by EnableSecurity in collaboration with Acunetix.
- Affected versions: OpenX 2.6.4 and older versions
- Enable Security Advisory: https://www.enablesecurity.com/advisories/ES2009-01-openx-multiple-vulnerabilities/
Description
OpenX is an online advertising web application written in PHP that supports popular sites such as TechCrunch, SUN Microsystems and Metacafe.
From their website (openx.org):
“OpenX is a free, open source ad server that manages the selling and delivery of your online advertising inventory. You can get OpenX as a hosted service or as downloaded software.”
…
Apple Mail.app: S/MIME encrypted emails stored in clear text
Published on Oct 3, 2008 in apple, security advisory
- Affected version: 3.5 (929.4/929.2)
- Unaffected version: Unknown
Summary
Apple Mail.app does not store S/MIME encrypted emails securely in the Drafts directory on server.
Impact
The assumption that the server does not have access to the email content is violated.
Description
Apple’s Mail.app is the default email application that comes with Mac OS X machines. It supports S/MIME as standard for encryption and authentication of emails. However by default Mail.app also has an option called “Store draft messages on the server” when you are making use of an IMAP or Exchange server.
…