BugTraq Mode:
(Page 555 of 1748)  < Prev  550 551 552 553 554 555 556 557 558 559 560  Next >
Secunia Research: Employee Timeclock Software Backup Information Disclosure 2010-03-10
Secunia Research (remove-vuln secunia com)
======================================================================

Secunia Research 10/03/2010

- Employee Timeclock Software Backup Information Disclosure -

======================================================================
Table of Contents

Affected Software...

[ more ]  [ reply ]
[xss] a xss on "threadid" parameter in BBSMAX 2010-03-10
lis cker (liscker hotmail com)

i found a xss on "threadid" parameter in "post.aspx" in BBSMAX , it's "post.aspx?action=reply&threadid="

Vulnerable: BBSMAX 4.2 BBSMAX 4.1 BBSMAX 3.0

For example:
http://bbs.example.com/forum1/post.aspx?action=reply&threadid="><script>
alert(/liscker/);</script>


BBSMAX Home Page : h

[ more ]  [ reply ]
[SECURITY] [DSA 2009-1] New tdiary packages fix cross-site scripting 2010-03-09
white debian org (Steffen Joeris)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------

Debian Security Advisory DSA-2009-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Steffen Joeris
March 09, 2010

[ more ]  [ reply ]
Friendly-Tech FriendlyTR69 CPE Remote Management V2.8.9 SQL Injection Vulnerability 2010-03-10
lament ilhack org
=========================================

Yaniv Miron aka "Lament" Advisory March 7, 2010

Friendly-Tech FriendlyTR69 CPE Remote Management V2.8.9 SQL Injection Vulnerability

=========================================

=====================

I. BACKGROUND

=====================

Based on the comp

[ more ]  [ reply ]
CORE-2009-0813: Windows Movie Maker and Microsoft Producer IsValidWMToolsStream() Heap Overflow 2010-03-09
CORE Security Technologies Advisories (advisories coresecurity com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Core Security Technologies - CoreLabs Advisory
http://www.coresecurity.com/corelabs/

Windows Movie Maker and Microsoft Producer IsValidWMToolsStream() Heap
Overflow

1. *Advisory Information*

Title: Windows Movie Maker and Microsoft

[ more ]  [ reply ]
[ MDVSA-2010:058 ] php 2010-03-09
security mandriva com

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2010:058
http://www.mandriva.com/security/
_____________________________________________________________________

[ more ]  [ reply ]
ZDI-10-026: Hewlett-Packard OVPI helpmanager Servlet Remote Code Execution Vulnerability 2010-03-09
ZDI Disclosures (zdi-disclosures tippingpoint com)
ZDI-10-026: Hewlett-Packard OVPI helpmanager Servlet Remote Code Execution Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-10-026
March 9, 2010

-- CVE ID:
CVE-2010-0447

-- Affected Vendors:
Hewlett-Packard

-- Affected Products:
Hewlett-Packard OpenView Performance Insight

-- Tippin

[ more ]  [ reply ]
ZDI-10-025: Microsoft Office Excel XLSX File Parsing Remote Code Execution Vulnerability 2010-03-09
ZDI Disclosures (zdi-disclosures tippingpoint com)
ZDI-10-025: Microsoft Office Excel XLSX File Parsing Remote Code Execution Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-10-025
March 9, 2010

-- CVE ID:
CVE-2010-0263

-- Affected Vendors:
Microsoft

-- Affected Products:
Microsoft Office Excel

-- Vulnerability Details:
This vulner

[ more ]  [ reply ]
[security bulletin] HPSBMA02489 SSRT090065 rev.1 - HP Performance Insight , Remote Execution of Arbitrary Commands 2010-03-09
security-alert hp com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c02033170
Version: 1

HPSBMA02489 SSRT090065 rev.1 - HP Performance Insight , Remote Execution of Arbitrary Commands

NOTICE: The information in this Security Bulletin should be acted upon as soon

[ more ]  [ reply ]
IBM ENOVIA SmarTeam v5 Cross Site Scripting Vulnerability 2010-03-09
lament ilhack org
=========================================
Yaniv Miron aka "Lament" Advisory March 7, 2010
IBM ENOVIA SmarTeam v5 Cross Site Scripting Vulnerability
=========================================

=====================
I. BACKGROUND
=====================
ENOVIA SmarTeam provides highly flexible product da

[ more ]  [ reply ]
SQL injection vulnerability in wILD CMS 2010-03-09
Maciej Gojny (vuln ariko-security com)

# Title: [SQL injection vulnerability in wILD CMS]
# Date: [09.03.2010]
# Author: [Ariko-Security]
# Software Link: [http://www.wildcms.com/]
# Version: [ALL]

============ { Ariko-Security - Advisory #4/3/2010 } =============

SQL injection vulnerability in wILD CMS

Vendor's Descriptio

[ more ]  [ reply ]
Croogo CMS 1.2 Cross Site Scripting Vulnerabilities 2010-03-09
Paulino Calderon (calderon webvuln com)
Croogo CMS 1.2 Cross Site Scripting Vulnerabilities
==========================================

Vulnerable Software: 1.2 and prior
Release Date: 2010-03-06
Last Update: 2010-02-01
Critical: Low
Impact: Session hijack
Denial of service
Code execution

Solution Status:

[ more ]  [ reply ]
[SECURITY] [DSA 2008-1] New typo3-src packages fix several vulnerabilities 2010-03-08
Moritz Muehlenhoff (jmm debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------

Debian Security Advisory DSA-2008-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Moritz Muehlenhoff
March 08, 2010

[ more ]  [ reply ]
rPSA-2010-0014-1 mysql mysql-bench mysql-server 2010-03-07
rPath Update Announcements (announce-noreply rpath com)
rPath Security Advisory: 2010-0014-1
Published: 2010-03-07
Products:
rPath Appliance Platform Linux Service 1
rPath Appliance Platform Linux Service 2
rPath Linux 1
rPath Linux 2

Rating: Severe
Exposure Level Classification:
Remote System User Deterministic Privilege Escalation

[ more ]  [ reply ]
rPSA-2010-0013-1 gzip 2010-03-07
rPath Update Announcements (announce-noreply rpath com)
rPath Security Advisory: 2010-0013-1
Published: 2010-03-07
Products:
rPath Appliance Platform Linux Service 1
rPath Appliance Platform Linux Service 2
rPath Linux 1
rPath Linux 2

Rating: Major
Exposure Level Classification:
Local System User Non-deterministic Vulnerability
Updat

[ more ]  [ reply ]
rPSA-2010-0012-1 postgresql postgresql-contrib postgresql-server 2010-03-07
rPath Update Announcements (announce-noreply rpath com)
rPath Security Advisory: 2010-0012-1
Published: 2010-03-07
Products:
rPath Appliance Platform Linux Service 1
rPath Appliance Platform Linux Service 2
rPath Linux 1
rPath Linux 2

Rating: Severe
Exposure Level Classification:
Remote System User Deterministic Privilege Escalation

[ more ]  [ reply ]
[USN-907-1] gnome-screensaver vulnerabilities 2010-03-08
Marc Deslauriers (marc deslauriers canonical com)
===========================================================
Ubuntu Security Notice USN-907-1 March 08, 2010
gnome-screensaver vulnerabilities
CVE-2010-0285, CVE-2010-0422
===========================================================

A security issue affects the following Ubuntu releases:

[ more ]  [ reply ]
rPSA-2010-0011-1 gnome-ssh-askpass openssh openssh-client openssh-server 2010-03-07
rPath Update Announcements (announce-noreply rpath com)
rPath Security Advisory: 2010-0011-1
Published: 2010-03-07
Products:
rPath Appliance Platform Linux Service 1
rPath Appliance Platform Linux Service 2
rPath Linux 1
rPath Linux 2

Rating: Minor
Exposure Level Classification:
Remote User Non-deterministic Information Exposure
Upda

[ more ]  [ reply ]
[ MDVSA-2010:057 ] apache 2010-03-06
security mandriva com

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2010:057
http://www.mandriva.com/security/
_____________________________________________________________________

[ more ]  [ reply ]
"Writing JIT-Spray Shellcode for fun and profit" by DSecRG 2010-03-06
DSecRG (research dsecrg com)
"Writing JIT-Spray Shellcode for fun and profit"

by Alexey Sintsov from DSecRG (dsecrg.com)

Attacks on clients? browsers have always been the real threat for everyone.
And here vulnerabilities have been not only in the browser but also in plug-ins.
Bank-clients, business software, antivirus softwa

[ more ]  [ reply ]
ZoneAlarm Security Circumvention 2010-03-08
Andrew Barkley (barkley usa net)
Hi,

During my (in)security research, I've discovered what appears initially to be
a design oversight and not necessarily a vulnerability, affecting ZoneAlarm
and various other security vendors. I've tested this on various XP platforms
successfully, please feel free to notify the vendor as you wish

[ more ]  [ reply ]
[XSS] i found a xss on "page" parameter in "eccredit.php" in Dvbbs < 8.3.0 2010-03-06
lis cker (liscker hotmail com)

Home Page : http://www.dvbbs.net/

Dvbbs is prone to an cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affec

[ more ]  [ reply ]
phpinfo() XSS Vulnerability 2010-03-06
info securitylab ir (1 replies)
###################################################################

# Securitylab.ir

#################################################################

# Note: The above code in php 5.2.6 and lower test is successful

#################################################################

Vulnerability

[ more ]  [ reply ]
Re: phpinfo() XSS Vulnerability 2010-03-08
Salvatore Fresta aka Drosophila (drosophilaxxx gmail com)
Re: Apple Airport Wireless Products: Promiscuous FTP PORT Allowed in FTP Proxy Provides Security Bypass 2010-03-06
drstrangep0rk hushmail com (1 replies)
Do you have firmware information on which products it affects.

Thanks

[ more ]  [ reply ]
[xss] a xss on "action" parameter in BBSMAX 2010-03-06
lis cker (liscker hotmail com)

i found a xss on "action" parameter in "post.aspx" in BBSMAX , it's "post.aspx?action="

Vulnerable: BBSMAX 4.2 BBSMAX 4.1 BBSMAX 3.0

For example:
http://bbs.example.com/forum1/post.aspx?action=newthread"><script>alert(
/liscker/)</script>

BBSMAX Home Page : http://www.bbsmax.com/

[ more ]  [ reply ]
Apache mod_isapi Dangling Pointer Vulnerability - Security Advisory - SOS-10-002 2010-03-05
Lists (lists senseofsecurity com au)
Apache mod_isapi Dangling Pointer Vulnerability - Security Advisory -
SOS-10-002

Release Date. 5-Mar-2010
Last Update. -
Vendor Notification Date. 9-Feb-2010
Product. Apache HTTP Server
Platform. Microsoft Windows
A

[ more ]  [ reply ]
[ MDVSA-2010:056 ] openoffice.org 2010-03-05
security mandriva com

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2010:056
http://www.mandriva.com/security/
_____________________________________________________________________

[ more ]  [ reply ]
Re: ncpfs, Multiple Vulnerabilities 2010-03-05
dan j rosenberg gmail com
Apparently Bugtraq doesn't like attachments. The patches are available as attachments to the archived Full-Disclosure posting, at:

http://seclists.org/fulldisclosure/2010/Mar/122

[ more ]  [ reply ]
(Page 555 of 1748)  < Prev  550 551 552 553 554 555 556 557 558 559 560  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus