BugTraq Mode:
(Page 493 of 1747)  < Prev  488 489 490 491 492 493 494 495 496 497 498  Next >
[USN-995-1] libMikMod vulnerabilities 2010-09-29
Marc Deslauriers (marc deslauriers canonical com)
===========================================================
Ubuntu Security Notice USN-995-1 September 29, 2010
libmikmod vulnerabilities
CVE-2007-6720, CVE-2009-0179, CVE-2009-3995, CVE-2009-3996,
CVE-2010-2546, CVE-2010-2971
===========================================================

A se

[ more ]  [ reply ]
[USN-992-1] Avahi vulnerabilities 2010-09-29
Marc Deslauriers (marc deslauriers canonical com)
===========================================================
Ubuntu Security Notice USN-992-1 September 29, 2010
avahi vulnerabilities
CVE-2009-0758, CVE-2010-2244
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 8.04

[ more ]  [ reply ]
XSRF (CSRF) in Zimplit 2010-09-29
advisory htbridge ch
Vulnerability ID: HTB22605
Reference: http://www.htbridge.ch/advisory/xsrf_csrf_in_zimplit.html
Product: Zimplit
Vendor: Zimplit Ltd. ( http://www.zimplit.com/ )
Vulnerable Version: 3.0 and Probably Prior Versions
Vendor Notification: 15 September 2010
Vulnerability Type: CSRF (Cross-Site Request

[ more ]  [ reply ]
Re: XSS vulnerability in Auto CMS 2010-09-28
security curmudgeon (jericho attrition org)

: Vulnerability ID: HTB22564
: Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_auto_cms.html
: Product: Auto CMS
: Vendor: Roberto Aleman ( http://ventics.com/autocms/ )
: Vulnerable Version: 1.6 and Probably Prior Versions

: Vulnerability Type: XSS (Cross Site Scripting)

As an F

[ more ]  [ reply ]
Re: XSS vulnerability in CompuCMS 2010-09-28
security curmudgeon (jericho attrition org)

: Vulnerability ID: HTB22584
: Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_compucms.html
: Product: CompuCMS
: Vendor: CompuSoft A/S ( http://www.compusoft.dk/ )
: Vulnerable Version: Current at 06.08.2010 and Probably Prior Versions

Once again, you assign a "version" based

[ more ]  [ reply ]
Fwd: 2.6.6 <= phpMyFAQ <= 2.6.8 XSS 2010-09-28
Yam Mesicka (yammesicka gmail com)
Hi,

My name is Yam Mesicka, I'm from Israel and this is my first big
disclosure (so help needed is here :-)
I found XSS on phpMyFAQ system, versions 2.6.6 to 2.6.8.

Dork: intitle:"Powered By phpMyFAQ 2.6.8"
XSS: site-location/index.php/"><script>alert("XSS")</script>
Vul: 2.6.6 <= phpMyFAQ <= 2.6.

[ more ]  [ reply ]
[oCERT-2010-004] FFmpeg/libavcodec arbitrary offset dereference 2010-09-28
Andrea Barisani (lcars ocert org)

#2010-004 FFmpeg/libavcodec arbitrary offset dereference

Description:

The libavcodec library, an open source video encoding/decoding library part of
the FFmpeg project, suffers from an arbitrary offset dereference vulnerability.

The vulnerability affects the flic file format parser, insufficient

[ more ]  [ reply ]
XSS in Horde IMP <=4.3.7, fetchmailprefs.php 2010-09-27
Moritz Naumann (security moritz-naumann com)
Hi,

Horde IMP v4.3.7 and lower are subject to a cross site scripting (XSS)
vulnerability:

The fetchmailprefs.php script fails to properly sanitize user supplied
input to the 'fm_id' URL parameter. If exploited, injected code will be
persistent (persistent XSS) and will execute once the user (manua

[ more ]  [ reply ]
SQL injection vulnerability in Entrans 2010-09-27
advisory htbridge ch
Vulnerability ID: HTB22607
Reference: http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_entrans.h
tml
Product: Entrans
Vendor: Khader Abbeb N ( http://sourceforge.net/projects/entrans/ )
Vulnerable Version: 0.3.2 and Probably Prior Versions
Vendor Notification: 13 September 2010
Vulner

[ more ]  [ reply ]
XSS vulnerability in Entrans 2010-09-27
advisory htbridge ch
Vulnerability ID: HTB22606
Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_entrans.html
Product: Entrans
Vendor: Khader Abbeb N ( http://sourceforge.net/projects/entrans/ )
Vulnerable Version: 0.3.2 and Probably Prior Versions
Vendor Notification: 13 September 2010
Vulnerability Ty

[ more ]  [ reply ]
SQL injection vulnerability in e107 2010-09-27
advisory htbridge ch
Vulnerability ID: HTB22604
Reference: http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_e107_2.ht
ml
Product: e107 Website System
Vendor: e107 ( http://www.e107.org/ )
Vulnerable Version: 0.7.23 and Probably Prior Versions
Vendor Notification: 13 September 2010
Vulnerability Type: SQL

[ more ]  [ reply ]
[SECURITY] [DSA-2114-1] New git-core packages fix regression 2010-09-26
Stefan Fritsch (sf debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------

Debian Security Advisory DSA-2114-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Stefan Fritsch
September 26, 2010

[ more ]  [ reply ]
SQL injection vulnerability in Entrans 2010-09-27
advisory htbridge ch
Vulnerability ID: HTB22608
Reference: http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_entrans_1
.html
Product: Entrans
Vendor: Khader Abbeb N ( http://sourceforge.net/projects/entrans/ )
Vulnerable Version: 0.3.2 and Probably Prior Versions
Vendor Notification: 13 September 2010
Vuln

[ more ]  [ reply ]
Web commands injection through FTP Login in Synology Disk Station - CVE-2010-2453 2010-09-26
Rodrigo Branco (rbranco checkpoint com)
Check Point Software Technologies - Vulnerability Discovery Team (VDT)
http://www.checkpoint.com/defense/

Web commands injection through FTP Login in Synology Disk Station
CVE-2010-2453

INTRODUCTION

Synology Inc develops high-performance, reliable, versatile, and environmentally-friendly Network

[ more ]  [ reply ]
Exploit Next Generation(R) Example Codes 2010-09-25
Nelson Brito (nbrito sekure org)
As all of you already know the Exploit Next Generation® Compliance
Methodology is the only methodology able to apply the "Z-Day Attacks"
concepts.

Some examples demonstrated during its very first appearance are now
available at:
- http://code.google.com/p/exploit-ng/

To celebrate one year of its

[ more ]  [ reply ]
Vulnerabilities in CMS MYsite 2010-09-25
MustLive (mustlive websecurity com ua)
Hello Bugtraq!

I want to warn you about Full path disclosure, Cross-Site Scripting and SQL
Injection vulnerabilities in CMS MYsite. It's Ukrainian commercial CMS.

Full path disclosure (WASC-13):

http://site/portal/modules.php?name=Ads

XSS (WASC-08):

http://site/portal/modules.php?name=Web_Links

[ more ]  [ reply ]
[ MDVSA-2010:189-1 ] pcsc-lite 2010-09-24
security mandriva com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2010:189-1
http://www.mandriva.com/security/
______________________________________________________________________

[ more ]  [ reply ]
[ MDVSA-2010:189 ] pcsc-lite 2010-09-24
security mandriva com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2010:189
http://www.mandriva.com/security/
______________________________________________________________________

[ more ]  [ reply ]
Re: Opera Web Browser v10.62 (CSS) Cross Domain Vulnerability 2010-09-24
security opera com
Opera's variation of this vulnerability was fixed back in Opera 10.10. The information on this thread is incorrect. The issue shown here does not affect Opera, and this code would not have produced an exploit in Opera, even in pre-10.10 versions. All it will do is display a message showing that the

[ more ]  [ reply ]
VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues 2010-09-24
VMware Security team (security vmware com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------

VMware Security Advisory

Advisory ID: VMSA-2010-0014
Synopsis: VMware Workstation, Player, and ACE address several
security

[ more ]  [ reply ]
TWSL2010-005: FreePBX recordings interface allows remote code execution 2010-09-23
Trustwave Advisories (trustwaveadvisories trustwave com)
Trustwave's SpiderLabs Security Advisory TWSL2010-005:
FreePBX recordings interface allows remote code execution

https://www.trustwave.com/spiderlabs/advisories/TWSL2010-005.txt

Published: 2010-09-23
Version: 1.0

Vendor: FreePBX (http://www.freepbx.org/)
Product: FreePBX and VOIP solutions (Aster

[ more ]  [ reply ]
Re: Netscape Web Browser (CSS) Cross Domain Vulnerability 2010-09-23
Michal Zalewski (lcamtuf coredump cx)
Not to rain on your parade, but...

> Netscape v9.0.0.6

"AOL formally stopped development of Netscape Navigator on December
28, 2007, but continued supporting the web browser with security
updates until March 1, 2008, when AOL canceled technical support."

If you are using a browser abandoned by th

[ more ]  [ reply ]
Re: Opera Web Browser v10.62 (CSS) Cross Domain Vulnerability 2010-09-23
phara0h (secws phara0h googlemail com)
Works on Opera 10.70. Build 9049 for Linux, too.

On Thu, 23 Sep 2010 04:23:47 -0600
info (at) securitylab (dot) ir [email concealed] wrote:

> Proof Of Concept:
>
> 1.html:
> <body>
> {}body{DOM:
> Cross Domain Vulnerability
>
>
> 2.html:
> <style>
> @import url("1.html");
> </style>
> <script>
> setTimeout(function(){
> va

[ more ]  [ reply ]
Netscape Web Browser (CSS) Cross Domain Vulnerability 2010-09-23
info securitylab ir
PoC:

1.html:
<body>
{}body{DOM:
Cross Domain Vulnerability

2.html:
<style>
@import url("1.html");
</style>
<script>
setTimeout(function(){
var s = document.body.currentStyle.DOM;
alert(s);
},0);
</script>

Vulnerable:
Netscape v9.0.0.6

By: Securitylab.ir
Original Advisory: http://Securitylab.ir/A

[ more ]  [ reply ]
[security bulletin] HPSBMA02578 SSRT100069 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Information Disclosure 2010-09-23
security-alert hp com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c02514929
Version: 1

HPSBMA02578 SSRT100069 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Information Disclosure

NOTICE: The information in this Security Bulletin shou

[ more ]  [ reply ]
[security bulletin] HPSBMA02583 SSRT100070 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote URL Redirection 2010-09-23
security-alert hp com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c02518794
Version: 1

HPSBMA02583 SSRT100070 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote URL Redirection

NOTICE: The information in this Security Bulletin should be a

[ more ]  [ reply ]
[security bulletin] HPSBMA02584 SSRT100230 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote URL Redirection 2010-09-23
security-alert hp com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c02514953
Version: 1

HPSBMA02584 SSRT100230 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote URL Redirection

NOTICE: The information in this Security Bulletin should be a

[ more ]  [ reply ]
[security bulletin] HPSBMA02585 SSRT100256 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Denial of Service (DoS) 2010-09-23
security-alert hp com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c02521481
Version: 1

HPSBMA02585 SSRT100256 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Denial of Service (DoS)

NOTICE: The information in this Security Bulletin should be acted upo

[ more ]  [ reply ]
Opera Web Browser v10.62 (CSS) Cross Domain Vulnerability 2010-09-23
info securitylab ir
Proof Of Concept:

1.html:
<body>
{}body{DOM:
Cross Domain Vulnerability

2.html:
<style>
@import url("1.html");
</style>
<script>
setTimeout(function(){
var s = document.body.currentStyle.DOM;
alert(s);
},0);
</script>

Vulnerable:
Opera 10.62

By: Securitylab.ir
Original Advisory: http://Secur

[ more ]  [ reply ]
[ISecAuditors Security Advisories] SQL Injection and XSS in Motorito < v2.0 Ni 483 2010-09-23
ISecAuditors Security Advisories (advisories isecauditors com)
=============================================
INTERNET SECURITY AUDITORS ALERT 2010-005
- Original release date: March 30th, 2010
- Last revised: September 23th, 2010
- Discovered by: Mario Diaz Caldera
- Severity: 5.5/10 (CVSS Base Score)
=============================================

I. VULNERABIL

[ more ]  [ reply ]
(Page 493 of 1747)  < Prev  488 489 490 491 492 493 494 495 496 497 498  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus