BugTraq Mode:
(Page 1212 of 1748)  < Prev  1207 1208 1209 1210 1211 1212 1213 1214 1215 1216 1217  Next >
Easily exploitable Pseudo Random Number generator in phpbb version 2.0.19 and under. 2006-02-05
chinchilla gmail com
I. DESCRIPTION

Easily exploitable Pseudo Random Number generator in phpbb version 2.0.19 and under.

II. DETAILS

Due to poor design the gen_rand_string() can only generate upto 1 million hashes or random strings. This allow an attacker to reset any account through the lost password request form b

[ more ]  [ reply ]
ProtoVer LDAP vs CommuniGate Pro 5.0.7 2006-02-04
Evgeny Legerov (research gleg net)
I. DESCRIPTION

CommuniGate Pro Core Server from CommuniGate Systems provides robust cross-platform
groupware applications, enabling a cost effective, easy to manage communications platform.

For more info visit http://www.stalker.com

II. DETAILS

ProtoVer LDAP testsuite v1.5 uncovered critical D

[ more ]  [ reply ]
cleartext passwords get into log files 2006-02-03
innate gmx de
author: l0om
page: www.excluded.org
date: 03.02.2006

cleartext passwords get into log files
(this was first noted from a sshd [SSH-1.99-OpenSSH_3.7.1p2])

once on a linux box i have noticed cleartext passwords in the
"/var/log/messages" logfile. how this happens and how to prevent
is the aim of th

[ more ]  [ reply ]
mwcollect Alliance Launch 2006-02-03
Georg Wicherski (georg-wicherski pixel-house net)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

The mwcollect Alliance has been launched today. The mwcollect Alliance
is a non-profit community effort to collect autonomously spreading
malware and share with anti-virus and vulnerability researchers. Malware
is collected with the mwcollect Malware Co

[ more ]  [ reply ]
[eVuln] Vanilla Guestbook Multiple XSS & SQL Injection Vulnerabilities 2006-02-01
alex evuln com
New eVuln Advisory:
Vanilla Guestbook Multiple XSS & SQL Injection Vulnerabilities
http://evuln.com/vulns/54/summary.html

--------------------Summary----------------

Software: Vanilla Guestbook
Sowtware's Web Site: http://tachyondecay.net/
Versions: 1.0 Beta
Critical Level: Moderate
Type: Multiple

[ more ]  [ reply ]
Issues with security software: orbicule.com "Undercover" 2006-02-02
Maximillian Dornseif (dornseif informatik uni-mannheim de)
During a lab exercise one of our students found several privacy
security issues in products and services offered by http://orbicule.com.

orbicule.com offers what is claimed to be a Notebook Anti-Theft
solution for Apple MacOS X called Undercover. You install their
software on their machine, r

[ more ]  [ reply ]
[KAPDA::#26] - MyTopix Sql Injection & Path Disclosure 2006-02-04
alireza hassani (trueend5 yahoo com)

KAPDA New advisory

Vendor: http://www.jaia-interactive.com
Vulnerable: Version: 1.2.3
Bug: Sql Injection & Path Disclosure
Exploitation: Remote with browser

Description:
--------------------
MyTopix is a PHP-based message board system that uses
a MySQL database.

Vulnerability:
-----------------

[ more ]  [ reply ]
sql injection in ASP Survey 2006-02-04
mfoxhacker gmail com
Hi guys
there is a simple sql injection in web app. (ASP Survey) by this vuln. you can go into the admin page

Target Page : login.asp
Vendor : ASP Survey
Exploit : User: admin Password: 'or'

Hacking: 1. search on google.com as :
allinurl:"login.asp" ASPsurvey
and then type the Exploit in correct o

[ more ]  [ reply ]
PluggedOut Blog SQL injection and XSS 2006-02-04
h e (het_ebadi yahoo com)
PluggedOut Blog SQL INJECTION and XSS

PluggedOut Blog is an open source script you can run
on your web server to give you an online multi-user
journal or diary.
It can be used equally well for any kind of calendar
application.Rather than give you a thousand things you
don't really want ...
Plugged

[ more ]  [ reply ]
LoudBlog <= 0.4 arbitrary remote inclusion 2006-02-04
rgod autistici org
------------- LoudBlog <= 0.4 arbitrary remote inclusion -----------

software:
site: http://loudblog.de/
description: "Loudblog is a sleek and easy-to-use Content Management
System (CMS) for publishing media content on the web. It automatically
generates a skinnable website and an RSS-Feed fo

[ more ]  [ reply ]
VSR Advisory: IBM Tivoli Access Manager - Web Server Plug-in File Retrieval Vulnerability 2006-02-03
VSR Advisories (advisories vsecurity com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Virtual Security Research, LLC.
http://www.vsecurity.com/
Security Advisory

-
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
-=-=-

Advisory Name: Remote Directory Traver

[ more ]  [ reply ]
[eVuln] MyQuiz Arbitrary Command Execution Vulnerability 2006-02-03
alex evuln com
New eVuln Advisory:
MyQuiz Arbitrary Command Execution Vulnerability
http://evuln.com/vulns/57/summary.html

--------------------Summary----------------

Software: MyQuiz
Sowtware's Web Site: http://www.corantodemo.net/
Versions: 1.01
Critical Level: Dangerous
Type: Command Execution
Class: Remote
S

[ more ]  [ reply ]
Outblaze Cross Site Scripting Vulnerability 2006-02-03
simo morx org
Title: outblaze Cross Site Scripting

Author: Simo Ben youssef aka _6mO_HaCk <simo_at_morx_org>
Discovered: 23 january 2005
Published: 02 february 2006
MorX Security Research Team
http://www.morx.org
Original advisory: http://www.morx.org/outblazeXSS.txt

Service: Webmail manager

Vendor: outblaze /

[ more ]  [ reply ]
Blacklist defenses as a breeding ground for vulnerability variants 2006-02-03
Steven M. Christey (coley mitre org)

David Litchfield recently provided a detailed description of a number
of vulnerabilities in Oracle PLSQL Gateway. He showed how, each time
the blacklist defense was modified, he was able to find a new variant
that worked around the more restrictive blacklist.

This type of pattern has emerged time

[ more ]  [ reply ]
AOL Instant Messenger Version 5.9.3861 Local Buffer Overrun Vulnerability 2006-02-03
shell dotshell net (2 replies)
As I submitted to full disclosure:

"I have discovered that there is a buffer overrun vulnerability in AOL's Instant Messenger program. I have only tested this on version 5.9.3861. The problem causes a minimum of a program crash. I am not sure as to the posibility of shellcode execution.

The vulner

[ more ]  [ reply ]
Re: AOL Instant Messenger Version 5.9.3861 Local Buffer Overrun Vulnerability 2006-02-04
Stan Bubrouski (stan bubrouski gmail com)
Re: AOL Instant Messenger Version 5.9.3861 Local Buffer Overrun Vulnerability 2006-02-03
Stan Bubrouski (stan bubrouski gmail com)
Exchangepop3 rcpt buffer overflow vulnerability 2006-02-03
securma morx org

Author: securma massine <securma (at) morx (dot) org [email concealed]>
MorX Security Research Team
http://www.morx.org

Product info :
EXchangepop3 is an email gateway (connector) that retrieves messages from
Internet POP3 email accounts and delivers them to Exchange Server.
Vulnerability Description:
eXchangepop3 is vulnera

[ more ]  [ reply ]
cPanel Multiple Cross Site Scripting Vulnerability 2006-02-03
simo morx org
Title: cPanel Multiple Cross Site Scripting

Author: Simo Ben youssef aka _6mO_HaCk <simo_at_morx_org>
Discovered: 22 january 2005
Published: 02 february 2006
MorX Security Research Team
http://www.morx.org

Service: Web Hosting Manager

Vendor: cPanel

Vulnerability: Cross Site Scripting / Cookie-T

[ more ]  [ reply ]
Neomail Cross Site Scripting Vulnerability 2006-02-03
simo morx org
Title: Neomail Cross Site Scripting

Author: Simo Ben youssef aka _6mO_HaCk <simo_at_morx_org>
Discovered: 24 january 2005
Published: 02 february 2006
MorX Security Research Team
http://www.morx.org

Service: Webmail Perl Client

Vendor: neomail / www.neocodesolutions.com

Vulnerability: Cross Site

[ more ]  [ reply ]
Re: Cross Site Cooking 2006-02-03
Yngve Nysaeter Pettersen (yngve opera com) (1 replies)
On Sun, 29 Jan 2006 01:50:23 +0100, Michal Zalewski <lcamtuf (at) dione.ids (dot) pl [email concealed]>
wrote:

> Problem #1 - trouble with these pesky foreigners
> ------------------------------------------------
>
> The mechanism for preventing overly relaxed cookie domain
> specification seems to be broken in

[ more ]  [ reply ]
Re: Cross Site Cooking 2006-02-03
Glynn Clements (glynn gclements plus com)
[KDE Security Advisory] kpdf/xpdf heap based buffer overflow 2006-02-02
Dirk Mueller (mueller kde org)


KDE Security Advisory: kpdf/xpdf heap based buffer overflow
Original Release Date: 2006-02-02
URL: http://www.kde.org/info/security/advisory-20060202-1.txt

0. References
CVE-2006-0301

1. Systems affected:

KDE 3.4.0 up to including KDE 3.5.1

2. Overview:

kpdf, the KDE

[ more ]  [ reply ]
IronMail-5.0.1-Denial of-Service-Protection-Lets-Remote-Users-Deny-Service 2006-02-03
mark gmail com

IronMail 5.0.1 Denial of Service Protection Lets Remote Users Deny Service

Date
====
November 29, 2005 ? Research and Testing
Junary 10, 2006 ? Update Release

Vulnerability
=============
SYN attack Denial of Service (Flood Connections)

Severity
========
High

Affect Products
===============

[ more ]  [ reply ]
(Page 1212 of 1748)  < Prev  1207 1208 1209 1210 1211 1212 1213 1214 1215 1216 1217  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus