|
Colapse all |
Post message
linksys router + irc DoS 2006-03-03 Cade Cairns (cairnsc gmail com) Bug: Certain Linksys (and possibly Netgear) routers will reset an IRC connection when a malformed DCC request is received. In fact, it doesn't even have to be a proper DCC request, the flaw can be triggered simply by sending the following string such that it is received by the user in some way. DC [ more ] [ reply ] [eVuln] Easy Forum XSS Vulnerability 2006-03-04 alex evuln com New eVuln Advisory: Easy Forum XSS Vulnerability http://evuln.com/vulns/85/summary.html --------------------Summary---------------- eVuln ID: EV0085 CVE: CVE-2006-0877 Software: Easy Forum Sowtware's Web Site: http://hot-things.net/?q=eforum Versions: 2.5 Critical Level: Harmless Type: Cross-Site S [ more ] [ reply ] [KAPDA::#30] - CuteNews1.4.1 Cross_Site_Scripting Vulnerability 2006-03-04 roozbeh_afrasiabi yahoo com [KAPDA::#30] - CuteNews1.4.1 Cross_Site_Scripting Vulnerability KAPDA New advisory Vulnerable products : CuteNews1.4.1 Vendor: www.cutephp.com Risk: Low Vulnerabilities: Cross_Site_Scripting Discoverd by Roozbeh Afrasiabi and imei addmimistrator roozbeh_afrasiabi[at]yahoo[dot]com www.kapda.ir www. [ more ] [ reply ] AVG 7 granting Everyone Full Control to updated files... even its drivers 2006-03-04 redxii1234 hotmail com There is more here: http://www.dslreports.com/forum/remark,15601404 Basically, a first time install of AVG 7 will have default permissions. \Program Files\Grisoft\AVG Free has inherited permissions from \Program Files. This is preferred, because lower privileged accounts can't damage it. Once any [ more ] [ reply ] Various router DoS 2006-03-04 ryanmeyer14 netscape net It appears that various routers are prone to an IRC-only DoS attack. Particularly Netgear and Linksys routers have been shown vulnerable. If a client behind one of the vulnerable routers connects to an IRC server on port 6667 (and only 6667, does not DoS with other ports) and a user posts the follo [ more ] [ reply ] phpArcadeScript XSS Injections 2006-03-04 retard 30gigs com ???summary software: phpArcadeScript vendors website: http://www.phparcadescript.com/ versions: <= 2.0 class: remote status: unpatched exploit: available solution: not available discovered by: retard and jim risk level: medium ??? description due to phpArcadeScript excessive use of global [ more ] [ reply ] [ GLSA 200603-02 ] teTeX, pTeX, CSTeX: Multiple overflows in included XPdf code 2006-03-04 Thierry Carrez (koon gentoo org) [ GLSA 200603-01 ] WordPress: SQL injection vulnerability 2006-03-04 Thierry Carrez (koon gentoo org) Kaspersky Memory/CPU Usage Leak by design 2006-03-03 Michael Lang jackal-net at Hi, i've recently discovered a design problem in Kaspersky AV Scanner. Original seen on FileScanner for Unix 5.0.5 the Problematic files are also screewing up the latest 5.5.3 Version. AS i didnt find an offical way to deploy this at Kaspersky i hope someone from them will read this and contact m [ more ] [ reply ] Re: Mozilla Thunderbird : Multiple Information Disclosure Vulnerabilities 2006-03-02 David Rasch (d rasch broadwick com) > > ------------------------------------------------------------------------ > > Subject: > Re: Mozilla Thunderbird : Multiple Information Disclosure Vulnerabilities > From: > Steve Shockley <steve.shockley (at) shockley (dot) net [email concealed]> > Date: > Tue, 28 Feb 2006 18:57:57 -0500 > To: > Renaud Lifchitz <r.lifchitz@s [ more ] [ reply ] XST-Strikes-Back vulnerability in Netcache 2006-03-03 Nite Sprite (nitespritewalla yahoo com) :: NiteSprite Security advisory NSSA-06-001 :: :: by NiteSprite :: :: XST-Strikes-Back vulnerability in Netcache :: :: Date 2006-03-02 :: :: Product Netapp Netcache 5.6 :: :: Detail :: XST-Strikes-back is in http://www.securityfocus.com/archive/1/423028 If you try it on Netcache 5.6, you succ [ more ] [ reply ] [eVuln] Skate Board Multimple Vulnerabilities 2006-03-03 alex evuln com New eVuln Advisory: Skate Board Multimple Vulnerabilities http://evuln.com/vulns/84/summary.html --------------------Summary---------------- eVuln ID: EV0084 CVE: CVE-2006-0809 CVE-2006-0810 CVE-2006-0811 Software: Skate Board Sowtware's Web Site: http://bb.jiraiya.se/main.php?content=start Version [ more ] [ reply ] Gregarius 0.5.2 XSS and SQL Injection Vulnerabilities 2006-03-03 tzitaroth gmail com http://gregarius.net/ Gregarius is a web-based RSS/RDF/ATOM feed aggregator, designed to run on your web server, allowing you to access your news sources from wherever you want. XSS in search.php: search.php?rss_query=<script>alert(1)</script>&rss_query_match=exact XSS in tags.php: tags.php?tag=< [ more ] [ reply ] Gallery 2 Multiple Vulnerabilities 2006-03-03 GulfTech Security Research (security gulftech org) ########################################################## # GulfTech Security Research March 02, 2006 ########################################################## # Vendor : Bharat Mediratta # URL : http://gallery.menalto.com/ # Version : Gallery2 <= 2.0.2 # Risk : Multiple Vulnerabilit [ more ] [ reply ] MyBB 1.04 Perl Exploit 2006-03-03 o y 6 hotmail com #!/usr/bin/perl -w # MyBB <= 1.04 (misc.php COMMA) Remote SQL Injection Exploit 2 , Perl C0d3 # # Milw0rm ID :- # http://www.milw0rm.com/auth.php?id=1539 # D3vil-0x1 | Devil-00 < BlackHat > :) # # DONT FORGET TO DO YOUR CONFIG !! # DONT FORGET TO DO YOUR CONFIG !! # DONT FORGET TO DO YOUR CONFIG [ more ] [ reply ] iDefense Security Advisory 03.02.06: EMC Dantz Retrospect 7 Backup client DoS Vulnerability 2006-03-02 labs-no-reply (at) idefense (dot) com [email concealed] (labs-no-reply idefense com) EMC Dantz Retrospect 7 Backup client DoS Vulnerability iDefense Security Advisory 03.02.06 http://www.idefense.com/application/poi/display?type=vulnerabilities March 02, 2006 I. BACKGROUND EMC Dantz Retrospect is a network backup client designed for small to mid-sized businesses. Dantz protects m [ more ] [ reply ] iDefense Security Advisory 03.02.06: Apple Mac OS X passwd Arbitrary Binary File Creation/Modification 2006-03-02 labs-no-reply (at) idefense (dot) com [email concealed] (labs-no-reply idefense com) Apple Mac OS X passwd Arbitrary Binary File Creation/Modification iDefense Security Advisory 03.02.06 http://www.idefense.com/application/poi/display?type=vulnerabilities March 02, 2006 I. BACKGROUND Mac OS X is an operating system for the Apple family of microcomputers. More information is avail [ more ] [ reply ] AZTEK forums 4.0 multiple vulnerabilities (PoC) 2006-03-02 billy hotmail com /*==========================================*/ // AZTEK forums 4.0 multiple vulnerabilities (PoC) // Product: AZTEK forums // URL: http://www.forum-aztek.com/ // RISK: high /*==========================================*/ [PoC] 1- XSS - Post a message including the following line: </textarea>'"><sc [ more ] [ reply ] RE: [Full-disclosure] Mozilla Thunderbird : Multiple Information Disclosure Vulnerabilities 2006-03-02 Jay Stapleton (jay stapleton computershare com) Or perhaps cache the images along with the message, to be deleted when the message is. That way one can open an email many times without accessing a web resource each time. It would also allow someone to forward a message, and include the content as it is currently, as opposed to how it may be in [ more ] [ reply ] vBulletin3.0.12&3.5.3~is_valid_email()~XSS Attack 2006-03-02 addmimistrator gmail com ???Summary??? Software: vBulletin Sowtware?s Web Site: http://www.vBulletin.com Versions: 3.0.12-3.5.3 Class: Remote Status: Unpatched Exploit: Available Solution: Available Discovered by: imei addmimistrator Risk Level: Mediume ??-Description??- There is a security bug in most powerfull & common fo [ more ] [ reply ] iDefense Security Advisory 03.02.06: Apple MacOS X BOMArchiveHelper Directory Traversal Vulnerability 2006-03-02 labs-no-reply (at) idefense (dot) com [email concealed] (labs-no-reply idefense com) Apple MacOS X BOMArchiveHelper Directory Traversal Vulnerability iDefense Security Advisory 03.02.06 http://www.idefense.com/intelligence/vulnerabilities/display.php?id=399 March 02, 2006 I. BACKGROUND Mac OS X is an operating system for the Apple family of microcomputers. More information is ava [ more ] [ reply ] [ MDKSA-2006:052 ] - Updated mozilla-thunderbird packages fix vulnerability 2006-03-02 security mandriva com Woltlab Burning Board 2.x (Datenbank MOD fileid) MultipleVulnerabilities. 2006-03-01 nukedx nukedx com --Security Report-- Advisory: Woltlab Burning Board 2.x (Datenbank MOD fileid) Multiple Vulnerabilities. --- Author: Mustafa Can Bjorn "nukedx a.k.a nuker" IPEKCI --- Date: 01/03/06 01:33 AM --- Contacts:{ ICQ: 10072 MSN/Email: nukedx (at) nukedx (dot) com [email concealed] Web: http://www.nukedx.com } --- Vendor: WbbCoderForum [ more ] [ reply ] [eVuln] E-Blah Platinum 'Referer' XSS Vulnerability 2006-03-02 alex evuln com New eVuln Advisory: E-Blah Platinum 'Referer' XSS Vulnerability http://evuln.com/vulns/83/summary.html --------------------Summary---------------- eVuln ID: EV0083 CVE: CVE-2006-0829 Software: E-Blah Platinum Sowtware's Web Site: http://www.eblah.com Versions: 9.7 Critical Level: Moderate Type: Cro [ more ] [ reply ] |
|
Privacy Statement |
software:
site: http://www.phpstats.net/
description: Open source statistical package for PHP enabled web sites
------------------------------------------------------------------------
--------
i) vulnerable code in adm
[ more ] [ reply ]