[Canvas] Agora pack 2.71 is out

Yuriy Gurkin audit at gleg.net
Mon Nov 27 10:27:28 UTC 2017


Hi, List,

2.71 ver. of Agora contains 5 modules. List:

- Cogent Datahub Blind SQL injection [0-Day]
- Oracle Java SE - Web Start jnlp XML External Entity Processing
Information Disclosure [CVE-2017-10309]
- Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution
[CVE-2017-9805]
- Wordpress Simple Events Calendar 1.3.5 – Authenticated SQL Injection
- WordPress Events 2.3.4 - Authenticated SQL Injection

Happy pentesting,
Gleg`s Security team <http://gleg.net/>
Follow us on Twitter: GlegExploitPack <https://twitter.com/GlegExploitPack>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.immunityinc.com/pipermail/canvas/attachments/20171127/208de02c/attachment.html>


More information about the Canvas mailing list