CVE-2017-7688
Apache OpenMeetings 1.0.0 updates user password in insecure manner. Date published : 2017-07-14 http://www.securityfocus.com/bid/99586 http://markmail.org/message/ctsiiqtekzsun6fi
Apache OpenMeetings 1.0.0 updates user password in insecure manner. Date published : 2017-07-14 http://www.securityfocus.com/bid/99586 http://markmail.org/message/ctsiiqtekzsun6fi
Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH. Date published : 2017-07-14 http://www.securityfocus.com/bid/99592 http://markmail.org/message/uxk4bpq35svnyjhb
Apache OpenMeetings 1.0.0 doesn’t check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files to the server. Date published : 2017-07-14 http://www.securityfocus.com/bid/99584 http://markmail.org/message/v6dpmrdd6cgg66up
Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure. Date published : 2017-07-14 http://markmail.org/message/hint6fp66lijqdvu
Apache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted areas. Date published : 2017-07-14 http://markmail.org/message/dbrbvf5k343ulivf
Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the...
Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains. Date published : 2017-07-14 http://markmail.org/message/whhibri7ervbjvda
Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection. Date published : 2017-07-14 http://www.securityfocus.com/bid/99587 http://markmail.org/message/3hshl26omwjo6c5i
Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks. Date published : 2017-07-14 http://markmail.org/message/fkesu4e5hhz5xdbg
Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0. Date published : 2017-07-14 http://www.securityfocus.com/bid/99576 http://markmail.org/message/cwr552iapmhukb45
Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0. Date published : 2017-07-14 http://www.securityfocus.com/bid/99577 http://markmail.org/message/aka2z2dq7icfw2p2
Adobe Connect versions 9.6.1 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to a stored cross-site scripting attack. Date published : 2017-07-14 http://www.securityfocus.com/bid/99518 https://helpx.adobe.com/security/products/connect/apsb17-22.html
Adobe Connect versions 9.6.1 and earlier have a reflected cross-site scripting vulnerability. Successful exploitation could lead to a reflected cross-site scripting attack. Date published : 2017-07-14 http://www.securityfocus.com/bid/99517 https://helpx.adobe.com/security/products/connect/apsb17-22.html
Adobe Connect versions 9.6.1 and earlier have a clickjacking vulnerability. Successful exploitation could lead to a clickjacking attack. Date published : 2017-07-14 http://www.securityfocus.com/bid/99521 https://helpx.adobe.com/security/products/connect/apsb17-22.html