|
Colapse all |
Post message
[ MDKSA-2006:092 ] - Updated mpg123 packages fix DoS vulnerability. 2006-05-26 security mandriva com Re: RE: A Nasty Security Bug that affect PGP Virtual Disks & PGP SDA , PGP 8.x & 9.x and Truecrypt. 2006-05-26 ahariri balamand edu lb We appreciate your comments, Did you check truecrypt video ? http://www.safehack.com/Advisory/truecrypt/truecrypt.html We are not saying maybe it is documented feature. We did not see that and the objective was not to test truecrypt but it was to test pgp. It was a trial on truecrypt and we report [ more ] [ reply ] Morris Guestbook v1 2006-05-26 luny youfucktard com Homepage: http://www.tuttophp.altervista.org/morrisguest-ing.htm Description: Morris Guestbook is a text-based guestbook with the following features: Data storing on text file, paging of messages on screen, words crypting, counting of inserted messages, blockage of messages with both html tag [ more ] [ reply ] Smile Guestbook v1 2006-05-26 luny youfucktard com Homepage: http://www.tuttophp.altervista.org/smileguest-ing.htm Description: Smile Guestbook is a cool text-based guestbook with smilies inserting and other features below Effected files: view.php An XSS attack is possible due to no filtering of pagina variable: http://www.example.com [ more ] [ reply ] Pretty Guestbook v1 2006-05-26 luny youfucktard com Homepage: http://www.tuttophp.altervista.org/main.php Description: Text-based guestbook with the following features: - Data storing on text file - Paging of messages on screen - Blockage of messages with words too long into - Blockage of messages with both html tags(<>) - Validity-checking of e [ more ] [ reply ] Re: Microsoft Internet Explorer - Crash on mouse button click 2006-05-25 unknown user (mac68k gmail com) I've successfully tested in english version of Windows XP pro SP2 with IE 6. it's very strange... 2006/5/25, r0xes <r0xes.ratm (at) gmail (dot) com [email concealed]>: > Nope. Also, doesn't work on WinXP Home Sp2 with IE 6. > => Maybe it is only Windows ___yourlanguage__ ? > > > On 5/24/06, unknown user < mac68k (at) gmail (dot) com [email concealed]> [ more ] [ reply ] Vacation Retal Script v1.0 2006-05-25 luny youfucktard com Vacation Retal Script v1.0 Homepage: http://www.vacationrentalscript.com/ Description: Vacation Rentals is the best solution for your vacation rental online business. It?s easy to install, easy to use, provides lots of features and option details. Just check the online demo and convince your [ more ] [ reply ] Super Link Exchange Script v1.0 2006-05-25 luny youfucktard com Super Link Exchange Script v1.0 Homepage: http://www.ebizunion.com/guidetosuper.php Description: Main Features: 1. Add unlimited nested category/sub-category, 2. Can check reciprocal link back, 3. Can hide and delete no link back sites. 4. Template can be edited and suitable to fit your curr [ more ] [ reply ] PHPSimple Choose v0.3 2006-05-24 luny youfucktard com PHPSimple Choose v0.3 Homepage: http://phpsimplechoose.sourceforge.net Description: Do you need to add some fun to your site? Look no further. With PHPSimpleChoose you can let your users input terms and have one randomly choosen. Every bit of text is changeable, and we are working on al [ more ] [ reply ] iBoutique.MALL - Directory Traversal 2006-05-24 luny youfucktard com iBoutique.MALL Homepage: http://www.netartmedia.net/mall/ Description: Based on iBoutique 4.0, iBoutique.MALL is a powerful multi user mall software solution. It makes possible for the new vendors to signup and create their own customized online stores with ease. Effected files: index.php [ more ] [ reply ] XSS Vulnerability on Vodafone 2006-05-24 try_og hotmail com Some link on the website Vodafone.de contains a little vulnerability that could be used for illegal purposes. It could be used for phishing or other purposes. hxxp:// website /simlock/servlets/sim?IMEI=[XSS-Code Here] hxxps:// website /simlock/servlets/sim?IMEI=[XSS-Code Here] Actual [ more ] [ reply ] rPSA-2006-0080-1 postgresql postgresql-server 2006-05-24 Justin M. Forbes (jmforbes rpath com) rPath Security Advisory: 2006-0080-1 Published: 2006-05-24 Products: rPath Linux 1 Rating: Severe Exposure Level Classification: Local System User Deterministic Vulnerability Updated Versions: postgresql=/conary.rpath.com@rpl:devel//1/8.1.4-1-0.1 postgresql-server=/conary.rpath.com@rpl:d [ more ] [ reply ] Re: Microsoft Internet Explorer - Crash on mouse button click 2006-05-24 unknown user (mac68k gmail com) i disable my all of IE plugins and restart IE and test again. but, exploit worked. how about refresh the exploit page, and retry click on exploit page? p.s do you using any antivirus program? if you do, how about disable antivirus program, and retry click on exploit page? 2006/5/25, s89df987 s9f8 [ more ] [ reply ] On the Recent PGP and Truecrypt Posting 2006-05-26 jon pgp com Here is some information about the issue with PGP and Truecrypt. We cannot speak for the Truecrypt people, but much of the explanation applies to their software as well as ours. We are disappointed that the people who developed this report released it in a web site and on bugtraq before contactin [ more ] [ reply ] Re: Microsoft Internet Explorer - Crash on mouse button click 2006-05-24 unknown user (mac68k gmail com) do you click on the exploit page? if you don't, you must click on the exploit page. also, if you run this exploit in local, must activate active content. but if you do(and doesn't crashed), how about refresh the exploit page, and retry click on exploit page? i think it will be work. 2006/5/25, r [ more ] [ reply ] Re: PhpListPro 2.01 Remote File Include Vulnerability 2006-05-24 not available com This bug was not discovered by SnoB[http://www.cyber-security.org] !!!!!!!!! It was posted long before yours and has the same description and input examples. Seems like you have stolen it. That's really lame! Here are the original issues: (Take a look on the release date) http://www.secur [ more ] [ reply ] ByteHoard <= 2.1 multiple vulnerabilities 2006-05-23 zerogue gmail com ByteHoard <= 2.1 multiple vulnerabilities Discovered by: Nomenumbra Date: 23/5/2006 impact:high (file manipulation,privilege escalation,possible defacement) ByteHoard versions up to 2.1 are prone to multiple vulnerabilities, including directory traversal. [0x00] Directory traversal: Us [ more ] [ reply ] PHP AGTC-Membership system <= v1.1a XSS 2006-05-23 zerogue gmail com PHP AGTC-Membership system <= v1.1a XSS Discovered by: Nomenumbra Date: 23/5/2006 impact:moderate (privilege escalation,possible defacement) Ordinary users can add users to the user management system as well, or change their own email address, which isn't properly sanitized, thus allowing [ more ] [ reply ] PHPResidence <= 0.6 XSS 2006-05-23 zerogue gmail com PHPResidence <= 0.6 XSS Discovered by: Nomenumbra Date: 23/5/2006 impact:moderate (privilege escalation,possible defacement) PHP Residence software doesn't sanitize any of it's input, allowing a malicious attacker (providing he/she has an account) to inject arbitrary HTML or javascript cod [ more ] [ reply ] |
|
Privacy Statement |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDKSA-2006:092
http://www.mandriva.com/security/
____________________________________________________________________
[ more ] [ reply ]