|
Colapse all |
Post message
Input Validation/Output Encoding Vulnerabilities in Cisco CallManager Allow Script Injection Attacks 2006-06-19 Reynolds, Jake (Jake Reynolds fishnetsecurity com) I. SYNOPSIS Release Date: 07/19/2006 Affected Application: Cisco CallManager 3.1 and up (versions prior to 3.1 were not tested but may still be vulnerable) Severity If Exploited: High Impact: Arbitrary configuration of phone system/Theft of individual phone users' credentials Mitigating Factors [ more ] [ reply ] Vm ware 0day dos exploit by n00b. 2006-06-18 co296 aol com Credit's : n00b email : co296 (at) aol (dot) com [email concealed] Erm was wondering if you could take a close look at this it is a 0day dos exploit by me i found tonight in vmware i have even debug for you guy's to take a look at.I hope you guy's will put it up after checking through it.Ok the first thing is vmware us [ more ] [ reply ] Re: PHP Live Helper <=([abs_path]) Remote File Include Vulnerabilities 2006-06-19 stormhacker hotmail com [ GLSA 200606-21 ] Mozilla Thunderbird: Multiple vulnerabilities 2006-06-19 Sune Kloppenborg Jeppesen (jaervosz gentoo org) [ GLSA 200606-20 ] Typespeed: Remote execution of arbitrary code 2006-06-19 Sune Kloppenborg Jeppesen (jaervosz gentoo org) SaphpLesson<<--1.1 "misc.php" SQL injection 2006-06-19 CrAzY CrAcKeR hotmail com ============================================= Discovered By: CrAzY CrAcKeR Site:www.alshmokh.com I want to thank my friend:- nono225-mHOn-rageh-Lover Hacker-Breeeeh BoNy_m-Rootshill-LiNuX_rOOt-Sw33t h4ck3r ============================================= Example:- /misc.php?action=[SQL] [ more ] [ reply ] VBZooM <<--V1.00 "lng.php" SQL injection 2006-06-19 CrAzY CrAcKeR hotmail com ============================================= Discovered By: CrAzY CrAcKeR Site:www.alshmokh.com I want to thank my friend:- nono225-mHOn-rageh-Lover Hacker-Breeeeh BoNy_m-Rootshill-LiNuX_rOOt-Sw33t h4ck3r ============================================= Example:- /lng.php?QuranID=[SQL] [ more ] [ reply ] vuBB <= 0.2.1 [BFA] SQL Injection Exploit + Advisory link 2006-06-18 gmdarkfig gmail com #!/usr/bin/perl # # by DarkFig -- acid-root.new.fr # French Advisory (vuBB <= 0.2.1 [BFA] SQL Injection, XSS, CRLF Injection, Full Path Disclosure): http://www.acid-root.new.fr/advisories/vubb021b.txt # use IO::Socket; use LWP::Simple; # Header print "\r\n+------------------------------- [ more ] [ reply ] VBZooM <<--V1.11 "message.php" SQL injection 2006-06-19 CrAzY CrAcKeR hotmail com ============================================= Discovered By: CrAzY CrAcKeR Site:www.alshmokh.com I want to thank my friend:- nono225-mHOn-rageh-Lover Hacker-Breeeeh BoNy_m-Rootshill-LiNuX_rOOt-Sw33t h4ck3r ============================================= Example:- /message. php?UserID=[SQ [ more ] [ reply ] VBZooM <<--V1.00 "rank.php" SQL injection 2006-06-19 CrAzY CrAcKeR hotmail com ============================================= Discovered By: CrAzY CrAcKeR Site: www.alshmokh.com I want to thank my friend:- nono225-mHOn-rageh-Lover Hacker-Breeeeh BoNy_m-Rootshill-LiNuX_rOOt-Sw33t h4ck3r ============================================= Example:- /rank.php?MemberID=[SQL [ more ] [ reply ] e107 v0.7.5 XSS 2006-06-18 securityconnection gmail com http://target.xx/search.php?q=&r=0&s=Search&in=1&ex=1&ep= %27%3E%3Cscript%3Ealert%28%2FXSS%2F%29%3C%2Fscript% 3E&be=1&t=1&adv=1&type=all&on=new&time=any&author= ------------------ Submit comment Subject: '><script>alert(/XSS/)</script> Click Reply to this you comment. Ellipsis Security http [ more ] [ reply ] PHP Live Helper <=([abs_path]) Remote File Include Vulnerabilities 2006-06-19 selfar2002 hotmail com ------------------------------------------------------------------------ --- PHP Live Helper <=([abs_path]) Remote File Include Vulnerabilities ------------------------------------------------------------------------ --- Discovered By SnIpEr_SA Author : SnIpEr_SA Remote : Yes Local : No Criti [ more ] [ reply ] Re: [MajorSecurity #17] SixCMS <= 6 - Multiple XSS and directory traversal vulnerabilities 2006-06-19 ellinger six de [security bulletin] HPSBTU02116 SSRT061135 rev.2 - HP Tru64 UNIX and HP Internet Express for Tru64 UNIX Running sendmail, Remote Execution of Arbitrary Code or Denial of Service (DoS) 2006-06-19 security-alert hp com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c00692635 Version: 2 HPSBTU02116 SSRT061135 rev.2 - HP Tru64 UNIX and HP Internet Express for Tru64 UNIX Running sendmail, Remote Execution of Arbitrary Code or Denial of Service (DoS) NOTICE: Th [ more ] [ reply ] Microsoft Excel 0-day Vulnerability FAQ document written 2006-06-18 Juha-Matti Laurio (juha-matti laurio netti fi) I have written FAQ document including 23 items about the new Excel 0-day vulnerability exploited by Trojan. The document entitled as Microsoft Excel 0-day Vulnerability FAQ is located at http://blogs.securiteam.com/index.php/archives/451 Permalink-type URL to the FAQ is http://blogs.securiteam.com [ more ] [ reply ] MPCS v0.2 - XSS 2006-06-17 luny youfucktard com MPCS v0.2 Homepage: http://tpvgames.co.uk/mpcs Affected files: comment.php XSS vuln with cookie & full path disclosure: Direct html injection doesnt seem to work, however, if you navigate to the code below in your browser, and then post a comment on the same page, our XSS example w [ more ] [ reply ] XSS in http://www.newscientist.com/ - Search 2006-06-16 viz security gmail com We from Black Box Magazine - Underground Inet-Security Research -- http://bboxnet.mine.nu found Cross Site Scripting Vuln in http://www.newscientist.com/ Write this example in Search: "><img src=javascript:a=/Defaced%20by%20Black%20Box%20Magazine/><img src=javascript:alert(a.source)> [ more ] [ reply ] mp3.com - Cross site scripting vulnerability 2006-06-16 admin majorsecurity de mp3.com - Cross site scripting vulnerability ---------------------------------------------- Type: Cross site scripting Date: June, 15th 2006 ---------------------------------------------- Credits: ---------------------------------------------- Discovered by: David "Aesthetico" Vieira-Kurz [ more ] [ reply ] vbzoom V1.11 forum.php SQL Injection Vulnerabilities 2006-06-16 KARKOR23 hotmail com Discovered By CrAsh_oVeR_rIdE Vbzoom SQL Injection site:www.vbzoom.com Vulnerable: vbzoom V1.11 vulnerable files:forum.php exploit: http://www.sitname.com/vz/forum.php?UserID=1&MainID=[sql]&Page=1 -------------------------------------------------- Discovered By CrAsh_oVeR_rIdE E-mail:KARKOR [ more ] [ reply ] |
|
Privacy Statement |
[ more ] [ reply ]