|
Prev week |
Colapse all |
Post message
[USN-992-1] Avahi vulnerabilities 2010-09-29 Marc Deslauriers (marc deslauriers canonical com) =========================================================== Ubuntu Security Notice USN-992-1 September 29, 2010 avahi vulnerabilities CVE-2009-0758, CVE-2010-2244 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 [ more ] [ reply ] XSRF (CSRF) in Zimplit 2010-09-29 advisory htbridge ch Vulnerability ID: HTB22605 Reference: http://www.htbridge.ch/advisory/xsrf_csrf_in_zimplit.html Product: Zimplit Vendor: Zimplit Ltd. ( http://www.zimplit.com/ ) Vulnerable Version: 3.0 and Probably Prior Versions Vendor Notification: 15 September 2010 Vulnerability Type: CSRF (Cross-Site Request [ more ] [ reply ] Re: XSS vulnerability in Auto CMS 2010-09-28 security curmudgeon (jericho attrition org) : Vulnerability ID: HTB22564 : Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_auto_cms.html : Product: Auto CMS : Vendor: Roberto Aleman ( http://ventics.com/autocms/ ) : Vulnerable Version: 1.6 and Probably Prior Versions : Vulnerability Type: XSS (Cross Site Scripting) As an F [ more ] [ reply ] Re: XSS vulnerability in CompuCMS 2010-09-28 security curmudgeon (jericho attrition org) : Vulnerability ID: HTB22584 : Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_compucms.html : Product: CompuCMS : Vendor: CompuSoft A/S ( http://www.compusoft.dk/ ) : Vulnerable Version: Current at 06.08.2010 and Probably Prior Versions Once again, you assign a "version" based [ more ] [ reply ] Fwd: 2.6.6 <= phpMyFAQ <= 2.6.8 XSS 2010-09-28 Yam Mesicka (yammesicka gmail com) Hi, My name is Yam Mesicka, I'm from Israel and this is my first big disclosure (so help needed is here :-) I found XSS on phpMyFAQ system, versions 2.6.6 to 2.6.8. Dork: intitle:"Powered By phpMyFAQ 2.6.8" XSS: site-location/index.php/"><script>alert("XSS")</script> Vul: 2.6.6 <= phpMyFAQ <= 2.6. [ more ] [ reply ] [oCERT-2010-004] FFmpeg/libavcodec arbitrary offset dereference 2010-09-28 Andrea Barisani (lcars ocert org) #2010-004 FFmpeg/libavcodec arbitrary offset dereference Description: The libavcodec library, an open source video encoding/decoding library part of the FFmpeg project, suffers from an arbitrary offset dereference vulnerability. The vulnerability affects the flic file format parser, insufficient [ more ] [ reply ] XSS in Horde IMP <=4.3.7, fetchmailprefs.php 2010-09-27 Moritz Naumann (security moritz-naumann com) Hi, Horde IMP v4.3.7 and lower are subject to a cross site scripting (XSS) vulnerability: The fetchmailprefs.php script fails to properly sanitize user supplied input to the 'fm_id' URL parameter. If exploited, injected code will be persistent (persistent XSS) and will execute once the user (manua [ more ] [ reply ] SQL injection vulnerability in Entrans 2010-09-27 advisory htbridge ch Vulnerability ID: HTB22607 Reference: http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_entrans.h tml Product: Entrans Vendor: Khader Abbeb N ( http://sourceforge.net/projects/entrans/ ) Vulnerable Version: 0.3.2 and Probably Prior Versions Vendor Notification: 13 September 2010 Vulner [ more ] [ reply ] XSS vulnerability in Entrans 2010-09-27 advisory htbridge ch Vulnerability ID: HTB22606 Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_entrans.html Product: Entrans Vendor: Khader Abbeb N ( http://sourceforge.net/projects/entrans/ ) Vulnerable Version: 0.3.2 and Probably Prior Versions Vendor Notification: 13 September 2010 Vulnerability Ty [ more ] [ reply ] SQL injection vulnerability in e107 2010-09-27 advisory htbridge ch Vulnerability ID: HTB22604 Reference: http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_e107_2.ht ml Product: e107 Website System Vendor: e107 ( http://www.e107.org/ ) Vulnerable Version: 0.7.23 and Probably Prior Versions Vendor Notification: 13 September 2010 Vulnerability Type: SQL [ more ] [ reply ] [SECURITY] [DSA-2114-1] New git-core packages fix regression 2010-09-26 Stefan Fritsch (sf debian org) SQL injection vulnerability in Entrans 2010-09-27 advisory htbridge ch Vulnerability ID: HTB22608 Reference: http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_entrans_1 .html Product: Entrans Vendor: Khader Abbeb N ( http://sourceforge.net/projects/entrans/ ) Vulnerable Version: 0.3.2 and Probably Prior Versions Vendor Notification: 13 September 2010 Vuln [ more ] [ reply ] Web commands injection through FTP Login in Synology Disk Station - CVE-2010-2453 2010-09-26 Rodrigo Branco (rbranco checkpoint com) Check Point Software Technologies - Vulnerability Discovery Team (VDT) http://www.checkpoint.com/defense/ Web commands injection through FTP Login in Synology Disk Station CVE-2010-2453 INTRODUCTION Synology Inc develops high-performance, reliable, versatile, and environmentally-friendly Network [ more ] [ reply ] Exploit Next Generation(R) Example Codes 2010-09-25 Nelson Brito (nbrito sekure org) As all of you already know the Exploit Next Generation® Compliance Methodology is the only methodology able to apply the "Z-Day Attacks" concepts. Some examples demonstrated during its very first appearance are now available at: - http://code.google.com/p/exploit-ng/ To celebrate one year of its [ more ] [ reply ] Vulnerabilities in CMS MYsite 2010-09-25 MustLive (mustlive websecurity com ua) Hello Bugtraq! I want to warn you about Full path disclosure, Cross-Site Scripting and SQL Injection vulnerabilities in CMS MYsite. It's Ukrainian commercial CMS. Full path disclosure (WASC-13): http://site/portal/modules.php?name=Ads XSS (WASC-08): http://site/portal/modules.php?name=Web_Links [ more ] [ reply ] Re: Opera Web Browser v10.62 (CSS) Cross Domain Vulnerability 2010-09-24 security opera com Opera's variation of this vulnerability was fixed back in Opera 10.10. The information on this thread is incorrect. The issue shown here does not affect Opera, and this code would not have produced an exploit in Opera, even in pre-10.10 versions. All it will do is display a message showing that the [ more ] [ reply ] VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues 2010-09-24 VMware Security team (security vmware com) TWSL2010-005: FreePBX recordings interface allows remote code execution 2010-09-23 Trustwave Advisories (trustwaveadvisories trustwave com) Trustwave's SpiderLabs Security Advisory TWSL2010-005: FreePBX recordings interface allows remote code execution https://www.trustwave.com/spiderlabs/advisories/TWSL2010-005.txt Published: 2010-09-23 Version: 1.0 Vendor: FreePBX (http://www.freepbx.org/) Product: FreePBX and VOIP solutions (Aster [ more ] [ reply ] Re: Netscape Web Browser (CSS) Cross Domain Vulnerability 2010-09-23 Michal Zalewski (lcamtuf coredump cx) Not to rain on your parade, but... > Netscape v9.0.0.6 "AOL formally stopped development of Netscape Navigator on December 28, 2007, but continued supporting the web browser with security updates until March 1, 2008, when AOL canceled technical support." If you are using a browser abandoned by th [ more ] [ reply ] Re: Opera Web Browser v10.62 (CSS) Cross Domain Vulnerability 2010-09-23 phara0h (secws phara0h googlemail com) Works on Opera 10.70. Build 9049 for Linux, too. On Thu, 23 Sep 2010 04:23:47 -0600 info (at) securitylab (dot) ir [email concealed] wrote: > Proof Of Concept: > > 1.html: > <body> > {}body{DOM: > Cross Domain Vulnerability > > > 2.html: > <style> > @import url("1.html"); > </style> > <script> > setTimeout(function(){ > va [ more ] [ reply ] Netscape Web Browser (CSS) Cross Domain Vulnerability 2010-09-23 info securitylab ir PoC: 1.html: <body> {}body{DOM: Cross Domain Vulnerability 2.html: <style> @import url("1.html"); </style> <script> setTimeout(function(){ var s = document.body.currentStyle.DOM; alert(s); },0); </script> Vulnerable: Netscape v9.0.0.6 By: Securitylab.ir Original Advisory: http://Securitylab.ir/A [ more ] [ reply ] [security bulletin] HPSBMA02578 SSRT100069 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Information Disclosure 2010-09-23 security-alert hp com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c02514929 Version: 1 HPSBMA02578 SSRT100069 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Information Disclosure NOTICE: The information in this Security Bulletin shou [ more ] [ reply ] [security bulletin] HPSBMA02583 SSRT100070 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote URL Redirection 2010-09-23 security-alert hp com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c02518794 Version: 1 HPSBMA02583 SSRT100070 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote URL Redirection NOTICE: The information in this Security Bulletin should be a [ more ] [ reply ] [security bulletin] HPSBMA02584 SSRT100230 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote URL Redirection 2010-09-23 security-alert hp com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c02514953 Version: 1 HPSBMA02584 SSRT100230 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote URL Redirection NOTICE: The information in this Security Bulletin should be a [ more ] [ reply ] [security bulletin] HPSBMA02585 SSRT100256 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Denial of Service (DoS) 2010-09-23 security-alert hp com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c02521481 Version: 1 HPSBMA02585 SSRT100256 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Denial of Service (DoS) NOTICE: The information in this Security Bulletin should be acted upo [ more ] [ reply ] Opera Web Browser v10.62 (CSS) Cross Domain Vulnerability 2010-09-23 info securitylab ir Proof Of Concept: 1.html: <body> {}body{DOM: Cross Domain Vulnerability 2.html: <style> @import url("1.html"); </style> <script> setTimeout(function(){ var s = document.body.currentStyle.DOM; alert(s); },0); </script> Vulnerable: Opera 10.62 By: Securitylab.ir Original Advisory: http://Secur [ more ] [ reply ] [ISecAuditors Security Advisories] SQL Injection and XSS in Motorito < v2.0 Ni 483 2010-09-23 ISecAuditors Security Advisories (advisories isecauditors com) ============================================= INTERNET SECURITY AUDITORS ALERT 2010-005 - Original release date: March 30th, 2010 - Last revised: September 23th, 2010 - Discovered by: Mario Diaz Caldera - Severity: 5.5/10 (CVSS Base Score) ============================================= I. VULNERABIL [ more ] [ reply ] |
|
Privacy Statement |
Ubuntu Security Notice USN-995-1 September 29, 2010
libmikmod vulnerabilities
CVE-2007-6720, CVE-2009-0179, CVE-2009-3995, CVE-2009-3996,
CVE-2010-2546, CVE-2010-2971
===========================================================
A se
[ more ] [ reply ]