Announcements

Drupal Fixes Highly Critical SQL Injection Flaw

  • 17th October 2014
Drupal has patched a critical SQL injection vulnerability in version 7.x of the content management system that can allow arbitrary code execution. The flaw lies in an API that is specifically designed to help prevent against SQL injection attacks. “Drupal 7 includes a database abstraction API to ensure that queries executed against the ...
Continue reading

Joomla Re-Issues Security Update After Patches Glitch

  • 1st October 2014
Users of the Joomla content management system have been on a patching roller coaster the past 24 hours with one set of patches for critical vulnerabilities being pulled last night before being re-issued today. The Joomla update, bringing the CMS up to version 3.3.6, is a security update addressing a high priority remote file inclusion ...
Continue reading

Drupal Patches XSS Vulnerability in Spam Module

  • 19th September 2014
Drupal released an update that patches a cross-site scripting vulnerability in a popular spam and content moderation module used by websites built on the open source CMS. The vulnerability was in a feature of the Mollom module that is installed on at least 60,000 sites, said Drupal security team volunteer Greg Knaddison, director of ...
Continue reading

THREE QUARTERS of Android mobes open to web page spy bug

  • 18th September 2014
A Metasploit module has been developed to easily exploit a dangerous flaw in 75 percent of Android devices that allows attackers to hijack a users' open websites. The exploit targets vulnerability (CVE-2014-6041) in Android versions 4.2.1 and below and was disclosed without fanfare on 1 September, but had since gathered dust, ...
Continue reading