RSS   Vulnerabilities for
'Malware information sharing platform'
   RSS

2016-09-03
 
CVE-2015-5721

 

 
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.

 
 
CVE-2015-5720

 

 
Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) add.ctp, (2) edit.ctp, and (3) ajaxification.js.

 
 
CVE-2015-5719

 

 
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.

 

 >>> Vendor: Misp-project 2 Products
Malware information sharing platform
MISP


Copyright 2024, cxsecurity.com

 

Back to Top