In its response to a Hardened-PHP Project advisory issued last November warning of a PHP HTML entity encoder heap overflow vulnerability, Cisco has described which products are affected and mitigations that can be deployed. Cisco’s response is here.
In a separate advisory, Cisco is warning that attackers could take advantage of default passwords in NetFlow Collection Engine.




