BugTraq Mode:
(Page 1088 of 1748)  < Prev  1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093  Next >
VMSA-2006-0004 Cross site scripting vulnerability and other fixes 2006-08-01
VMware Security Team (security vmware com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------
VMware Security Advisory

Advisory ID: VMSA-2006-0004
Synopsis: Cross site scripting vulnerability and other fixes
Knowledge base URL:http://kb.vmwa

[ more ]  [ reply ]
[ MDKSA-2006:135 ] - Updated freeciv packages fix DoS vulnerabilities 2006-08-01
security mandriva com

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDKSA-2006:135
http://www.mandriva.com/security/
____________________________________________________________________

[ more ]  [ reply ]
[vuln.sg] Lhaplus LHA Extended Header Handling Buffer Overflow Vulnerability 2006-08-01
vulnpost-remove vuln sg
[vuln.sg] Vulnerability Research Advisory

Lhaplus LHA Extended Header Handling Buffer Overflow Vulnerability

by Tan Chew Keong

Release Date: 2006-07-31

Summary

-------

A vulnerability has been found in Lhaplus. When exploited, the vulnerability allows execution of arbitrary code when the

[ more ]  [ reply ]
WoW Roster <= 1.5.x Remote File Include (hsList.php) 2006-08-01
AG Spider (ag-spider hotmail com)
Title : WoW Roster <= 1.5.x Remote File Include (hsList.php)

########################################################################
#######

Discovered By :::: AG-Spider

------------------------------------------------------------------------
-----
Class : Remote file include
Rish : Danger
--

[ more ]  [ reply ]
[SECURITY] [DSA 1130-1] New sitebar packages fix cross-site scripting 2006-08-01
joey infodrom org (Martin Schulze)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
--
Debian Security Advisory DSA 1130-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Martin Schulze
July 30th, 2006

[ more ]  [ reply ]
[Kurdish Security # 21] ShoutBox v4.4 Remote Command Execution 2006-08-01
botan linuxmail org
>>> Kurdish Security

>>> ShoutBox Remote Command Execution

>>> Freedom For Ocalan

>>> Contact : irc.gigachat.net #kurdhack & www.PatrioticHackers.com

>>> Rish : High

>>> Class : Remote

>>> Script : ShoutBox

>>> Site : http://www.knusperleicht.at

Code :

//*************

[ more ]  [ reply ]
[Kurdish Security # 20 ] Quickie Remote Command Execution 2006-08-01
botan linuxmail org
>>> Kurdish Security

>>> Quickie Remote Command Execution

>>> Freedom For Ocalan

>>> Contact : irc.gigachat.net #kurdhack & www.PatrioticHackers.com

>>> Rish : High

>>> Class : Remote

>>> Script : >>> Kurdish Security

>>> FileManager Remote Command Execution

>>> Freedom F

[ more ]  [ reply ]
[Kurdish Security # 19 ] FileManager Remote Command Execution 2006-08-01
botan linuxmail org
>>> Kurdish Security

>>> FileManager Remote Command Execution

>>> Freedom For Ocalan

>>> Contact : irc.gigachat.net #kurdhack & www.PatrioticHackers.com

>>> Rish : High

>>> Class : Remote

>>> Script : FileManager

>>> Site : http://www.knusperleicht.at

Code :

$dwl_down

[ more ]  [ reply ]
[Kurdish Security # 18 ] FAQ Script Remote Command Execution 2006-08-01
botan linuxmail org
>>> Kurdish Security

>>> FAQ Script v1.0 Remote Command Execution

>>> Freedom For Ocalan

>>> Contact : irc.gigachat.net #kurdhack & www.PatrioticHackers.com

>>> Rish : High

>>> Class : Remote

>>> Script : FAQ Script

>>> Site : http://www.knusperleicht.at

Code :

//if

[ more ]  [ reply ]
[Kurdish Security # 17 ] GuestBook 3.5 Remote Command Execution 2006-08-01
botan linuxmail org
>>> Kurdish Security

>>> Guestbook v3.5 Remote Command Execution

>>> Freedom For Ocalan

>>> Contact : irc.gigachat.net #kurdhack & www.PatrioticHackers.com

>>> Rish : High

>>> Class : Remote

>>> Script : MoSpray

>>> Site : http://www.knusperleicht.at

Code :

define('F

[ more ]  [ reply ]
[SECURITY] [DSA 1132-1] New apache2 packages fix buffer overflow 2006-08-01
Steve Kemp (skx debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
--
Debian Security Advisory DSA 1132-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Steve Kemp
Aug 1st, 2005

[ more ]  [ reply ]
[Kurdish Security # 16 ] newsReporter v1.0 Remote Command Execution 2006-08-01
botan linuxmail org
>>> Kurdish Security

>>> newsReporter v1.0 Remote Command Execution

>>> Freedom For Ocalan

>>> Contact : irc.gigachat.net #kurdhack & www.PatrioticHackers.com

>>> Rish : High

>>> Class : Remote

>>> Script : newsReporter

>>> Site : http://www.knusperleicht.at

Code :

r

[ more ]  [ reply ]
NewsLetter v3.5 <= (NL_PATH) Remote File Inclusion Exploit 2006-08-01
tr_zindan wolfsecurity org
#=================================================================

#NewsLetter v3.5 <= (NL_PATH) Remote File Inclusion Exploit

#================================================================

# |

#Critical Level : Dangerous

[ more ]  [ reply ]
[ GLSA 200608-01 ] Apache: Off-by-one flaw in mod_rewrite 2006-08-01
Matthias Geerdsen (vorlon gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200608-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
Re: Do world's famous companies take care of their security? 2006-07-31
Steven M. Christey (coley mitre org)

>There was discussion last week in the Full-Disclosure about XSS
>vulnerabilities in reply to XSS vulns in PayPal and Gadi Evron
>suggested creation of a separate mailing list for just XSS
>vulnerabilities.

This is definitely a growing gap in our current knowledge. I don't
think it's being tracke

[ more ]  [ reply ]
MyNewsGroups <= 0.6b (myng_root) Remote Inclusion Vulnerability 2006-07-31
philipp niedziela gmx de
+--------------------------------------------------------------------

+

+ MyNewsGroups :) v. 0.6b <= Remote File Inclusion

+

+--------------------------------------------------------------------

+

+ Affected Software .: MyNewsGroups :) v. 0.6b

+ Venedor ...........: http://mynewsgroups.source

[ more ]  [ reply ]
Re: Xss in MttKe-php v2.6 2006-07-31
Steven M. Christey (coley mitre org)

>Xss in MttKe-php v2.6

What product or web site is this? A Google search returns mostly
references to the original post.

- Steve

[ more ]  [ reply ]
Multiple vulnerabilities in Open Cubic Player 2.6.0pre6 / 0.1.10_rc5 2006-07-31
Luigi Auriemma (aluigi autistici org)

#######################################################################

Luigi Auriemma

Application: Open Cubic Player
http://www.cubic.org/player/
http://stian.lunafish.org/coding-ocp.php
Versions: DOS/Windows <= 2.6.0pre6

[ more ]  [ reply ]
Corsaire Security Advisory - VMware ESX Server Password Disclosure in Cookie issue 2006-07-31
advisories (advisories corsaire com)

-- Corsaire Security Advisory --

Title: VMware ESX Server Password Disclosure in Cookie issue
Date: 12.05.06
Application: VMware ESX prior to 2.5.2 patch 4
VMware ESX prior to 2.0.2
Environment: VMware ESX
Author: Martin O'Neal [martin.oneal (at) corsaire (dot) com [email concealed]]
Audience: General distributio

[ more ]  [ reply ]
Corsaire Security Advisory - VMware ESX Server Password Disclosure in Log issue 2006-07-31
advisories (advisories corsaire com)

-- Corsaire Security Advisory --

Title: VMware ESX Server Password Disclosure in Log issue
Date: 14.11.05
Application: VMware ESX prior to 2.5.3 upgrade patch 2
VMware ESX prior to 2.1.3 upgrade patch 1
VMware ESX prior to 2.0.2 upgrade patch 1
Environment: VMware ESX
Aut

[ more ]  [ reply ]
Corsaire Security Advisory - VMware ESX Server Password Cross Site Request Forgery issue 2006-07-31
advisories (advisories corsaire com)

-- Corsaire Security Advisory --

Title: VMware ESX Server Password Cross Site Request Forgery issue
Date: 14.11.05
Application: VMware ESX prior to 2.5.3 upgrade patch 2
VMware ESX prior to 2.1.3 upgrade patch 1
VMware ESX prior to 2.0.2 upgrade patch 1
Environment: VMwar

[ more ]  [ reply ]
Oracle and Apache mod_rewrite Vulnerability 2006-07-31
tigerblue puzzleapuma de
Hi,

is the oracle branded httpd also vulnerable ?

Best Regards

tigerblue

systemadministration

[ more ]  [ reply ]
Re: Gdiplus.dll division by 0 2006-07-31
Early Warning Team (ewt telecomitalia it) (1 replies)
We tried the Proof of Concept on our test machines and couldn't reproduce the reported exceptional behavior. The scenarios we tested were:
- Windows XP Service Pack 2, <img> tag in Internet Explorer 6
- Windows XP Service Pack 2, "Insert picture" in Word 2003
- Windows XP Service Pack 2, display

[ more ]  [ reply ]
Re: Gdiplus.dll division by 0 2006-08-01
giacomo collini (gcliste gmail com)
SQL injection Seir Anphin v666 Community Management System 2006-07-30
vulnerabilities mail ru
CR Advisory#1

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

programm: Seir Anphin v666 Community Management System

bug: SQL injection

home page: www.comeplaydying.com

bug found: 27.07.2006

discovered by CR

www.svt.nukleon.us

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~! Details !~

====================

[ more ]  [ reply ]
PHPAuction 2.1 (maybe higher) with phpAdsNew 2.0.5 RFI 2006-07-30
philipp niedziela gmx de
+--------------------------------------------------------------------

+

+ PHPAuction 2.1 with phpAdsNew 2.0.5 Remote File Inclusion

+

+--------------------------------------------------------------------

+

+ Affected Software .: PHPAuction 2.1 (maybe higher) with phpAdsNew,

+

[ more ]  [ reply ]
(Page 1088 of 1748)  < Prev  1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus