European Central Bank Website Hit by Malware Attack

European Central Bank Website Hit by Malware Attack
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database CVE-2019-14923PUBLISHED: 2019-08-16

EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field.

CVE-2019-15091PUBLISHED: 2019-08-16

filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload.

CVE-2019-15108PUBLISHED: 2019-08-16

An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filename to the file-upload feature of the event simulator component.

CVE-2018-20969PUBLISHED: 2019-08-16

do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter.

CVE-2016-10894PUBLISHED: 2019-08-16

xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (and thus control) various programs such as Chromium via events such as pan scrolling, "pinch and zoom" gestures, or even regular mouse clicks (by depressing the touchpad o...