|
Colapse all |
Post message
Internet Explorer drag&drop 0day 2006-02-13 Gadi Evron (ge linuxbox org) (1 replies) Matthew Murphy has just disclosed a vulnerability in Internet Explorer. He will send his advisory later today, but as he is unable to right now, he asked me to email this for him. [I didn't want to email the advisory itself as ALL CREDIT BELONGS TO HIM and I didn't want to take the credit away fr [ more ] [ reply ] Re: [Full-disclosure] Internet Explorer drag&drop 0day 2006-02-13 Thierry Zoller (Thierry Zoller lu) [SECURITY] [DSA 969-1] New scponly packages fix potential root vulnerability 2006-02-13 joey infodrom org (Martin Schulze) Folder Guard password protection bypass 2006-02-13 ShadowBeast underdevelop com tested on Folder Guard v4.11 bypassing the Folder Guard password is done by renaming(or moving) the password file. the file is FGuard.FGP, after we rename it the Folder Guard will run and wont ask for a password for questions or currections please contact me at ShadowBeast (at) underdevelop (dot) com [email concealed] or Shado [ more ] [ reply ] [SECURITY] [DSA 968-1] New noweb packages fix insecure temporary file creation 2006-02-13 joey infodrom org (Martin Schulze) Everyone's loginName variable Cross Site Scripting Vulnerability 2006-02-13 simo morx org Title: Everyone's loginName variable Cross Site Scripting Author: Simo Ben youssef aka _6mO_HaCk <simo_at_morx_org> Published: 12 february 2006 MorX Security Research Team http://www.morx.org Service: Webmail Vendor: everyone / www.everyone.net Vulnerability: Cross Site Scripting Exploit included: [ more ] [ reply ] Invision Power Board Army System Mod <= 2.1 SQL Injection Exploit 2006-02-12 unsecure writeme com VULNERABLE PRODUCT ----------------------------------- Invision Power Board Army System Mod Version: 2.1 and priors. Url: http://supersmashbrothers.2ya.com Vulnerability: Remote SQL Injection ----------------------------------------------------- BACKGROUND ---------------------------- Army Syste [ more ] [ reply ] Siteframe Beaumont 5.0.1a <== Cross-Site Scripting Vulnerability 2006-02-12 federico alice tiscali it Hi, I'm Kiki and I would signal you a XSS in the CMS Siteframe Beaumont 5.0.1a I enclose the advisory and the origina is here: http://kiki91.altervista.org/exploit/siteframe5.0.1a_xss.txt Bye bye Kiki p.s: sorry for my bad English but I'm Italian ;) Advisory: Siteframe Beaumont 5.0.1a <== Cros [ more ] [ reply ] Re: Zen-Cart <= 1.2.6d blind SQL injection / remote commands execution: 2006-02-13 please-use-the-support-forum zen-cart com [eVuln] phpstatus Authentication Bypass 2006-02-12 alex evuln com New eVuln Advisory: phpstatus Authentication Bypass http://evuln.com/vulns/61/summary.html --------------------Summary---------------- eVuln ID: EV0061 CVE: CVE-2006-0570 CVE-2006-0571 CVE-2006-0572 Vendor: Hinton Design Vendor's Web Site: http://www.hintondesign.org Software: phpstatus Sowtware's [ more ] [ reply ] [eVuln] Clever Copy 'Referer' & 'X-Forwarded-For' XSS Vulnerabilities 2006-02-12 alex evuln com New eVuln Advisory: Clever Copy 'Referer' & 'X-Forwarded-For' XSS Vulnerabilities http://evuln.com/vulns/64/summary.html --------------------Summary---------------- eVuln ID: EV0064 CVE: CVE-2006-0627 Vendor: 3.0 2.0 2.0a Software: Clever Copy V3 Sowtware's Web Site: http://clevercopy.bestdirectbuy [ more ] [ reply ] [eVuln] phphd Multiple Vulnerabilities 2006-02-12 alex evuln com New eVuln Advisory: phphd Multiple Vulnerabilities http://evuln.com/vulns/60/summary.html --------------------Summary---------------- eVuln ID: EV0060 CVE: CVE-2006-0607 CVE-2006-0608 CVE-2006-0609 Vendor: Hinton Design Vendor's Web Site: http://www.hintondesign.org Software: phphd Sowtware's Web S [ more ] [ reply ] DB_eSession deleteSession() SQL injection 2006-02-11 GulfTech Security Research (security gulftech org) ########################################################## # GulfTech Security Research February 11, 2006 ########################################################## # Vendor : Lawrence Osiris # URL : http://www.phpclasses.org/browse/package/1624.html # Version : DB_eSession 1.0.2 # Risk : [ more ] [ reply ] DocMGR <= 0.54.2 arbitrary remote inclusion 2006-02-12 rgod autistici org --------------- DocMGR <= 0.54.2 arbitrary remote inclusion -------------------- software: site: http://www.docmgr.org/ description: "DocMGR is a complete, web-based Document Management System (DMS). It allows for the storage of any file type, and supports full-text indexing of the most popular [ more ] [ reply ] imageVue16.1 upload vulnerability 2006-02-11 zjieb hotmail com ImageVue is an online Flash gallery for viewing images. For more information about ImageVue visit http://www.imagevuex.com Credits: me Vulnerable Systems: imageVue16.1 In ImageVue one can upload images to the Gallery. The upload-script however isn't checking credentials nor does it check file ext [ more ] [ reply ] [USN-247-1] Heimdal vulnerability 2006-02-11 Martin Pitt (martin pitt canonical com) =========================================================== Ubuntu Security Notice USN-247-1 February 10, 2006 heimdal vulnerability CVE-2006-0582 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 4.10 (Warty Warthog) Ubunt [ more ] [ reply ] [eVuln] phpht Topsites Multiple Vulnerabilities 2006-02-11 alex evuln com New eVuln Advisory: phpht Topsites Multiple Vulnerabilities http://evuln.com/vulns/59/summary.html --------------------Summary---------------- eVuln ID: EV0059 Vendor: Hinton Design Vendor's Web Site: http://www.hintondesign.org Software: phpht Topsites Sowtware's Web Site: http://www.hintondesign. [ more ] [ reply ] [eVuln] phphg Guestbook Multiple Vulnerabilities 2006-02-11 alex evuln com New eVuln Advisory: phphg Guestbook Multiple Vulnerabilities http://evuln.com/vulns/58/summary.html --------------------Summary---------------- eVuln ID: EV0058 CVE: CVE-2006-0602 CVE-2006-0603 CVE-2006-0604 Vendor: Hinton Design Vendor's Web Site: http://www.hintondesign.org Software: phphg Guestb [ more ] [ reply ] Linpha <= 1.0 multiple arbitrary local inclusion 2006-02-11 rgod autistici org ------------- Linpha <= 1.0 multiple arbitrary local inclusion ----------------- software: site: http://linpha.sourceforge.net/nuke/ description: " LinPHA is an easy to use, multilingual, flexible photo / image archive / album / gallery written in PHP. It uses a SQL database to store info [ more ] [ reply ] Corrupt Word file may cause buffer overflow in the Blackberry Attachment Service 2006-02-11 lukew sktbcs com From Research in Motion's KB-04791 (sorry, long link): http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/ 8021/8149/8052/Support_-_Corrupt_Word_file_may_cause_buffer_overflow_in_ the_BlackBerry_Attachment_Service.html?nodeid=1181753&vernum=2 Applies to: BlackBerry Enterprise Ser [ more ] [ reply ] HiveMail <= 1.3 Multiple Vulnerabilities 2006-02-11 GulfTech Security Research (security gulftech org) ########################################################## # GulfTech Security Research February 10, 2006 ########################################################## # Vendor : HiveMail # URL : http://www.hivemail.com/ # Version : HiveMail <= 1.3 # Risk : Multiple Vulnerabilities ######### [ more ] [ reply ] FarsiNews 2.5 Multiple Vulnerabilities 2006-02-10 h e (het_ebadi yahoo com) FarsiNews 2.5 Multiple Vulnerabilities FarsiNews is a News Publishing System That uses Flat files to store it`s Datas... Farsinews is a persian and improved translation of CuteNews, AjFork, CuteHack and CuteSQL... for more information about FarsiNews Publishing System visit http://www.farsinewsteam [ more ] [ reply ] [security bulletin] SSRT061108 rev.2 - HP Systems Insight Manager Remote Unauthorized Access - Directory Traversal 2006-02-09 security-alert hp com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c00597967 Version: 2 HPSBMA02096 SSRT061108 rev.2 - HP Systems Insight Manager Remote Unauthorized Access - Directory Traversal NOTICE: The information in this Security Bulletin should be acted u [ more ] [ reply ] |
|
Privacy Statement |
Hash: SHA1
- -------------------------------------------------------------------
SySS-Advisory: XSS-vulnerability in guestbook-php-script
- -------------------------------------------------------------------
Problem discovered: February 3d 2006
Vendor contact
[ more ] [ reply ]