BugTraq Mode:
(Page 1446 of 1748)  < Prev  1441 1442 1443 1444 1445 1446 1447 1448 1449 1450 1451  Next >
SQL injection in BroadBoard Instant ASP Message Board 2004-09-26
pigrelax (pigrelax yandex ru)
BroadBoard Instant ASP Message Board

URL: http://www.broadboard.com/

1. software does not properly validate user-supplied input in the 'keywords'
parameter in search.asp:
http://broadboard/forum/search.asp?archives=1&action=1&keywords=['SQL
code]&method=1&method=1&body=1&subject=1&board=1&result

[ more ]  [ reply ]
[Hat-Squad] Remote Buffer overflow Vulnerability in YahooPOPS 2004-09-27
Hat-Squad Security Team (bugtraq hat-squad com)


Hat-Squad Advisory: Remote Buffer overflow Vulnerability in YahooPOPS

September 22, 2004

Product: YahooPOPS!

Vendor URL: http://yahoopops.sourceforge.net

Version: YahooPOPS v0.4 up to v0.6

Vulnerability: Remote Buffer overflows

Release Date: 27 September 2004

Vendor Status:

Informe

[ more ]  [ reply ]
IPv4 fragmentation --> The Rose Attack 2004-09-27
Gandalf The White (gandalf digital net)
Greetings and Salutations:

While this discussion pertains to IPv4, IPv6 also allows fragmentation and I
suspect IPv6 will also be affected by this attack.

This is an extension of the "Rose Attack" previously posted to the Bugtraq
mailing list. I have decided to call this attack the "New Dawn atta

[ more ]  [ reply ]
Re: Diebold Global Election Management System (GEMS) Backdoor Account Allows Authenticated Users to Modify Votes 2004-09-26
Nick Knouf (nknouf MIT EDU)
for those who are interested, a joint project by caltech and mit have
been working on these very issues

http://www.vote.caltech.edu/

lots of good information about the current problems with electronic
voting and suggested solutions.

cheers,

nick

ps i'm not involved in the project

[ more ]  [ reply ]
MyWebServer 1.0.3 2004-09-27
nekd0 (nekd0 rambler ru)
Hello bugtraq,

-= Unl0ck Team Security Advisory =-

____ ___ __ _______ __ ___________
| | \____ | | \ _ \ ____ | | __ \__ ___/___ _____ _____
| | / \| | / /_\ \_ / ___\| |/ / | |_/ __

[ more ]  [ reply ]
RE: Microsoft's GDI Detetection Tool faults 2004-09-26
Dowling, Gabrielle (dowlingg sullcrom com)
How did you test this (and on what platform), and why do you propose
that the SANS tool is delivering more accurate results than the GDI tool
delivered by Microsoft?

I tested the SANS tool against a properly patched XP system on Friday
and found it to false positive on many of the locations it said

[ more ]  [ reply ]
[CLA-2004:869] Conectiva Security Announcement - kernel 2004-09-27
Conectiva Updates (secure conectiva com br)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
--
CONECTIVA LINUX SECURITY ANNOUNCEMENT
- ------------------------------------------------------------------------
--

PACKAGE : kernel
SUMMARY : Fix for kernel vulnerability

[ more ]  [ reply ]
New Macromedia Security Zone Bulletins Posted 2004-09-23
securityzone macromedia com (Macromedia Security Zone)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
IMPORTANT:

Several security issues that may affect ColdFusionMX customers
have come to our attention recently.

To learn about this new issue and what actions you can take
to address it, please visit the Macromedia Security Zone:

[ more ]  [ reply ]
RE: Diebold Global Election Management System (GEMS) Backdoor Account Allows Authenticated Users to Modify Votes 2004-09-23
Polazzo Justin (Justin Polazzo facilities gatech edu)
It is impossible for a company to be non-partisan. That is why it would
be nice to develop an open source solution. That would be non-partisan.
Having being created by democrats, republicans, anarchists, whoever
wanted to contribute.

-JP

-----Original Message-----
From: Barry Fitzgerald [mailto:b

[ more ]  [ reply ]
Motorola Wireless Router WR850G Authentication Circumvention 2004-09-23
Daniel Fabian (d fabian sec-consult com)
------------------------------------------------------------------------
-
| Motorola Wireless Router WR850G Authentication Circumvention |
------------------------------------------------------------------------
-

Date: 09-23-2004
Author: Daniel Fabian
Product: Motorola Wireless Router WR85

[ more ]  [ reply ]
RE: New whitepaper "The Phishing Guide" 2004-09-24
Dehner, Benjamin T. (Ben Dehner valmont com)

I think if major vendors used signed emails, it would be a good step.
However, I'm not sure in the long run it will do much good.

First, the real problem isn't technical, it's educational. Most users
sophisticated enough to download a public key, verify the fingerprint, and
install it on their ke

[ more ]  [ reply ]
RE: Diebold Global Election Management System (GEMS) Backdoor Account Allows Authenticated Users to Modify Votes 2004-09-23
Jeremy Epstein (jeremy epstein webmethods com) (2 replies)
As someone who's been involved in the electronic voting controversy, I'd
like to add a few points:

(1) I agree that source code should be inspected by someone truly
independent and competent, and that the standards for approving voting
machines should be stronger. However, that's NOT the same as o

[ more ]  [ reply ]
Motorola Wireless Router WR850G Authentication Circumvention 2004-09-24
Daniel Fabian (df sec-consult com)
------------------------------------------------------------------------
-
| Motorola Wireless Router WR850G Authentication Circumvention |
------------------------------------------------------------------------
-

Date: 09-23-2004
Author: Daniel Fabian
Product: Motorola Wireless Router WR85

[ more ]  [ reply ]
Re: ICMP spoofed source tunneling 2004-09-24
raiblehugo hotmail com
In-Reply-To: <20040922203047.GA16153 (at) nenya (dot) lan [email concealed]>

>On Wed, Sep 22, 2004 at 10:06:40AM -1000, Tim Newsham wrote:

>> How does this give anonymity? When sending to the server, I must use the

>> servers address as a source address. When the server replies to me, it

>> must use my address as a source

[ more ]  [ reply ]
New XSS vulnerabilities in paFileDB 3.1 final 2004-09-25
alireza hassani (trueend5 yahoo com)
Another XSS Vulnerability has been found in paFileDB!

paFileDB is designed to allow webmasters have a
database of files for download on their site.

Vulnerable:

Software: email & category & file paFileDB modules

Just Tested on: paFileDB 3.1 Final , but likely works
on another versions.

Exploit

[ more ]  [ reply ]
Re:[3] Corsaire Security Advisory - Multiple vendor MIME RFC2047 encoding issue 2004-09-24
advisories (advisories corsaire com) (1 replies)

# This has been re-sent several times in the last week, but for whatever
reason, my email hasn't been getting to the bugtraq list.

> In this case, you canonicalize by picking just one of the fields.
> As long as you pick something unambiguous, you will be OK.

However this is not possible; as I ha

[ more ]  [ reply ]
RE: Correction to latest Colsaire advisories 2004-09-24
advisories (advisories corsaire com)

# This has been re-sent several times in the last week, but for whatever
reason, my email hasn't been getting to the bugtraq list.

> I presume that these are nine of the
> "top 10 content providers".

Actually, no. Our internal testing covered a limited collection of what we
considered the most pr

[ more ]  [ reply ]
Re: Microsoft's GDI Detetection Tool faults 2004-09-25
John Bissell (monkey321_1 hotmail com) (1 replies)
In-Reply-To: <20040924141725.13699.qmail (at) www.securityfocus (dot) com [email concealed]>

>Received: (qmail 18580 invoked from network); 25 Sep 2004 02:57:58 -0000

>Received: from outgoing.securityfocus.com (HELO outgoing2.securityfocus.com) (205.206.231.26)

> by mail.securityfocus.com with SMTP; 25 Sep 2004 02:57:58 -00

[ more ]  [ reply ]
Re: Microsoft's GDI Detetection Tool faults 2004-09-25
Gadi Evron (ge linuxbox org)
(Page 1446 of 1748)  < Prev  1441 1442 1443 1444 1445 1446 1447 1448 1449 1450 1451  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus