BugTraq Mode:
(Page 1125 of 1748)  < Prev  1120 1121 1122 1123 1124 1125 1126 1127 1128 1129 1130  Next >
CORE-2006-0327: IAXclient truncated frames vulnerabilities 2006-06-09
Core Security Technologies advisories (advisories coresecurity com)
Core Security Technologies - Corelabs Advisory
http://www.coresecurity.com/corelabs/

IAXclient truncated frames vulnerabilities

Date Published: 2006-06-09

Last Update: 2006-06-09

Advisory ID: CORE-2006-0327

Bugtraq ID: 18307

CVE Name: N/A

Title: IAXclient truncated frames vulnerabilities

[ more ]  [ reply ]
Secunia Research: SelectaPix Cross-Site Scripting and SQLInjection Vulnerabilities 2006-06-09
Secunia Research (remove-vuln secunia com)
======================================================================

Secunia Research 09/06/2006

- SelectaPix Cross-Site Scripting and SQL Injection Vulnerabilities -

======================================================================
Table of Contents

Affected Softwar

[ more ]  [ reply ]
Re: SSL VPNs and security 2006-06-09
Michal Zalewski (lcamtuf dione ids pl)
On Fri, 9 Jun 2006, E Mintz wrote:

> How about some real-world, application specific exploits?

There's an example of a XSS that can be used to compromise Cisco Web VPN
session in the text.

> So, please show me an example of an actual compromise and I'll listen.
> Otherwise, put up, or shut up!

Y

[ more ]  [ reply ]
[ GLSA 200606-08 ] WordPress: Arbitrary command execution 2006-06-09
Sune Kloppenborg Jeppesen (jaervosz gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200606-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
Re: SSL VPNs and security 2006-06-09
E Mintz (net4n6 gmail com)
How about some real-world, application specific exploits?

SSL VPN is hardly a 'novelty' or 'recent' technology. I implemented my
first SSL VPN in '99 at a large financial, and it is still in
production, and secure

So, please show me an example of an actual compromise and I'll listen.
Otherwise, pu

[ more ]  [ reply ]
Docebo Lms 3.0.3, Remote command execution 2006-06-09
Federico Fazzi (federico autistici org)
-----------------------------------------------------
Advisory id: FSA:010

Author: Federico Fazzi
Date: 09/06/2006, 7:24
Sinthesis: Docebo Lms 3.0.3, Remote command execution
Type: high
Product: http://www.docebolms.org/
Patch: unavailable
---------------------------------------------

[ more ]  [ reply ]
MobeSpace v2.0 - XSS 2006-06-09
luny youfucktard com
MobeSpace v2.0

Homepage:

http://mobescripts.com/

Effected files:

index.php

The input forms of:

- Profile

- Comments

- Uploading a file to your locker

- Posting in your blog

- Creating a caption for your pic

- Sending PM's

The input boxes of the above do not sanatize user input

[ more ]  [ reply ]
[USN-288-3] PostgreSQL client vulnerabilities 2006-06-09
Martin Pitt (martin pitt canonical com)
===========================================================
Ubuntu Security Notice USN-288-3 June 09, 2006
dovecot, exim4, postfix vulnerabilities
CVE-2006-2314, CVE-2006-2753
===========================================================

A security issue affects the following Ubuntu rel

[ more ]  [ reply ]
Docebo Kms 3.0.3, Remote command execution 2006-06-09
Federico Fazzi (federico autistici org)
-----------------------------------------------------
Advisory id: FSA:009

Author: Federico Fazzi
Date: 09/06/2006, 7:09
Sinthesis: Docebo Kms 3.0.3, Remote command execution
Type: high
Product: http://www.docebolms.org/
Patch: unavailable
---------------------------------------------

[ more ]  [ reply ]
mole.com.ua Ticket Booking Script - XSS 2006-06-09
luny youfucktard com
Ticket Booking Script

Homepage:

http://www.mole.com.ua

Effected files:

input boxes on booking2.php

XSS Vulnerabilities:

The input boxes on booking2.php do not sanatize userinput before geenrating it and then submitting it to a MySQL db. This can causes XSS examples as well as possible

[ more ]  [ reply ]
Re: DGbook v1.0 - XSS 2006-06-09
diangemilang gmail com
Thanks for the bugtraq,

We'll fix that bug(s) in the next version

Dian Gemilang Team

[ more ]  [ reply ]
mole.com.ua Booking Script 2006-06-09
luny youfucktard com
Booking Script.

Homepage:

http://www.mole.com.ua

PError with full path disclosure and possible buffer overflow?:

http://www.example.com/week.php?year=2006&month=06&day=0'

Warning: checkdate() expects parameter 2 to be long, string given in /home/httpd/vhosts/domain/subdomains/booking/ht

[ more ]  [ reply ]
Docebo Core 3.0.3, Remote command execution 2006-06-09
Federico Fazzi (federico autistici org)
-----------------------------------------------------
Advisory id: FSA:008

Author: Federico Fazzi
Date: 09/06/2006, 6:44
Sinthesis: Docebo Core 3.0.3, Remote command execution
Type: high
Product: http://www.docebolms.org/
Patch: unavailable
--------------------------------------------

[ more ]  [ reply ]
Docebo CMS 3.0.3, Remote command execution 2006-06-09
Federico Fazzi (federico autistici org)
-----------------------------------------------------
Advisory id: FSA:007

Author: Federico Fazzi
Date: 09/06/2006, 6:10
Sinthesis: Docebo CMS 3.0.3, Remote command execution
Type: high
Product: http://www.docebolms.org/
Patch: unavailable
---------------------------------------------

[ more ]  [ reply ]
Re: PHP-Nuke <= 7.9 Search XSS Vulnerability 2006-06-09
try_og hotmail com
"><iframe src="http://[site]/

will become:

<iframe src="http://[site]/">

"><"

will become:

<"">

This way, you can put html (maybe even more) on the page you are searching from...

[ more ]  [ reply ]
[USN-293-1] gdm vulnerability 2006-06-09
Martin Pitt (martin pitt canonical com)
===========================================================
Ubuntu Security Notice USN-293-1 June 09, 2006
gdm vulnerability
CVE-2006-2452
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 5.10
Ubuntu 6.06 LTS

[ more ]  [ reply ]
phazizGuestbook v2.0 - XSS 2006-06-08
luny youfucktard com
phazizGuestbook v2.0

Homepage:

http://www.devhome.de/#english_version

Effected files:

input boxes of name, email, url, text.

XSS Vulnerability:

None of these input boxes sanatize user input before generating it. for PoC put <IMG SRC=javascript:alert(�XSS')> in any of the above bo

[ more ]  [ reply ]
iFoto v0.20-06/06/06 2006-06-08
luny youfucktard com
iFoto v0.20-06/06/06

Homepage:

http://ifoto.ireans.com/

Effected files:

XSS Vulnerability:

The dir path to show the image is base 64 encoded, so to attempt this XSS example we encode our codein base64.

The code we'll be using is javascript in an iframe tag. [IFRAME SRC="javascript:al

[ more ]  [ reply ]
Dell Openmanage CD Vulnerability 2006-06-08
wiz561 gmail com
When you boot up using the Dell PowerEdge Installation and Server Management Disc (P/N: WG126 Rev. A00, October 2005), there are two major vulnerabilities on the machine. If you use this disc to boot up and you are connected to a DHCP network, there is an SSH server running that does not require a

[ more ]  [ reply ]
[SECURITY] [DSA 1094-1] New gforge packages fix cross-site scripting 2006-06-08
Moritz Muehlenhoff (jmm debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
--
Debian Security Advisory DSA 1094-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Moritz Muehlenhoff
June 8th, 2006

[ more ]  [ reply ]
[USN-294-1] courier vulnerability 2006-06-09
Martin Pitt (martin pitt canonical com)
===========================================================
Ubuntu Security Notice USN-294-1 June 09, 2006
courier vulnerability
CVE-2006-2659
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 5.04
Ubuntu 5.10
U

[ more ]  [ reply ]
[ GLSA 200606-07 ] Vixie Cron: Privilege Escalation 2006-06-09
Sune Kloppenborg Jeppesen (jaervosz gentoo org)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200606-07
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -

[ more ]  [ reply ]
okscripts.com - XSS Vulns 2006-06-08
luny youfucktard com
OkMall v1.0

Homepage:

http://www.okscripts.com/

Effected files:

search.php

XSS Vulnerabilities:

The search inputbox doesn?t properally filter using input before generating it. Backslashes areadded but we can easily

evade this.

ForPoC try putting a [imgsrc=lol.jpg]in the search

[ more ]  [ reply ]
[USN-295-1] xine-lib vulnerability 2006-06-09
Martin Pitt (martin pitt canonical com)
===========================================================
Ubuntu Security Notice USN-295-1 June 09, 2006
xine-lib vulnerability
CVE-2006-2802
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 5.04
Ubuntu 5.10

[ more ]  [ reply ]
[USN-292-1] binutils vulnerability 2006-06-09
Martin Pitt (martin pitt canonical com)
===========================================================
Ubuntu Security Notice USN-292-1 June 09, 2006
binutils vulnerability
CVE-2006-2362
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 5.04
Ubuntu 5.10

[ more ]  [ reply ]
SSL VPNs and security 2006-06-08
Michal Zalewski (lcamtuf dione ids pl) (1 replies)
"Web VPN" or "SSL VPN" is a term used to denote methods for accessing
company's internal applications with a bare WWW browser, with the use of
browser-based SSO authentication and SSL tunneling. As opposed to IPSec,
no additional software or configuration is required, and hence, corporate
users can

[ more ]  [ reply ]
Re: SSL VPNs and security 2006-06-09
Amit Klein (AKsecurity) (aksecurity hotpop com)
[security bulletin] HPSBUX02090 SSRT051058 rev.2 - HP-UX Secure Shell Remote Denial of Service (DoS) 2006-06-08
security-alert hp com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c00589050
Version: 2

HPSBUX02090 SSRT051058 rev.2 - HP-UX Secure Shell Remote Denial of Service (DoS)

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

[ more ]  [ reply ]
[security bulletin] HPSBMA02121 SSRT061157 rev.2 - HP OpenView Storage Data Protector Remote Arbitrary Command Execution 2006-06-08
security-alert hp com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c00671912
Version: 2

HPSBMA02121 SSRT061157 rev.2 - HP OpenView Storage Data Protector
Remote Arbitrary Command Execution

NOTICE: The information in this Security Bulletin should be acted upon

[ more ]  [ reply ]
(Page 1125 of 1748)  < Prev  1120 1121 1122 1123 1124 1125 1126 1127 1128 1129 1130  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus