|
Colapse all |
Post message
ASPR #2004-01-20-1: Internet Explorer/Outlook double null character DoS 2004-02-10 ACROS Security (lists acros si) Re: HelpCtr - allow open any page or run 2004-02-10 N|ghtHawk (nighthawk hackers4hackers nl) Hello, > We can use Help Center to open any page or run any file. On which operation system? I guess windows, so on which windows version(s)? > hcp://services/layout/contentonly?topic=... <snip> To me this looks like http://www.microsoft.com/technet/treeview/default.asp?url=/technet/secur ity/bu [ more ] [ reply ] Possible new cross zone scripting in IE 2004-02-10 Cheng Peng Su (apple_soup msn com) title:Possible new cross zone scripting in IE program:MS Internet Explorer test on:IE 6.0(sp1),winXP/ME Proof of Concept: From res://C:\WINDOWS\SYSTEM\BROWSELC.DLL/mbOffline.htm ,i found <a href="shell:My Music" onmouseover="window.status=L_MyMusic_Text;return true" onmouseout="wind [ more ] [ reply ] Re: HelpCtr - allow open any page or run 2004-02-10 Bartosz Kwitkowski (bartosz wb pl) In-Reply-To: <20040207214926.28580.qmail (at) www.securityfocus (dot) com [email concealed]> It was tested on Win XP Prof (ver 2002) Polish with Hotfixes: KB824146 and KB823980. hcp://services/layout/contentonly?topic=http://www.securityfocus.com Help Center opens page with given URL. For sure. [ more ] [ reply ] XSS, Sql Injection and Avatar ScriptCode Injection in MaxWebPortal 2004-02-10 Manuel López (mantra gulo org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Title: XSS, Sql Injection and Avatar ScriptCode Injection in MaxWebPortal By: Manuel López Vendor Description: MaxWebPortal is a web portal and online community system which includes advanced features such as web-based administration, poll, priva [ more ] [ reply ] Directory traversal in RealPlayer allows code execution 2004-02-10 Jouko Pynnonen (jouko iki fi) OVERVIEW ======== RealPlayer is a popular multimedia player developed by RealNetworks. One of its features are RMP files, RealJukebox Metadata Packages. These are XML formatted files which may contain e.g. playlists, references to skin files (*.rjs), and information about related web pages. A [ more ] [ reply ] Re: TrackMania Demo Denial of Service 2004-02-09 Luigi Auriemma (aluigi altervista org) > TrackMania Demo Denial of Service > The original document can be found at > http://www.securiteinfo.com/attaques/hacking/trackmaniados.shtml Also Virtual Skipper 3 is vulnerable so the problem is in the game engine developed by Nadeo (http://www.nadeo.com) > The multiplayer game use TCP port 23 [ more ] [ reply ] Brinkster Multiple Vulnerabilities 2004-02-09 Ferruh Mavituna (ferruh mavituna com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - ------------------------------------------------------ BRINKSTER MULTIPLE VULNERABILITIES - - ------------------------------------------------------ Online URL : http://ferruh.mavituna.com/article/?435 1. Retrieving other users ASP Source Codes Sev [ more ] [ reply ] Samba 3.x + kernel 2.6.x local root vulnerability 2004-02-09 Michal Medvecky (M Medvecky sh cvut cz) (2 replies) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 "share" - smb server "slovakia" - smb client misko@slovakia:~$ smbmount --version Usage: mount.smbfs service [ more ] [ reply ] Re: Samba 3.x + kernel 2.6.x local root vulnerability 2004-02-09 Seth Arnold (sarnold wirex com) (1 replies) Re: Samba 3.x + kernel 2.6.x local root vulnerability 2004-02-09 Patrick J. Volkerding (security slackware com) Re: Samba 3.x + kernel 2.6.x local root vulnerability 2004-02-09 Michael Kjorling (michael kjorling com) [local problems] eTrust Virus Protection 6.0 InoculateIT for linux 2004-02-09 Rene (l0om excluded org) author: l0om <l0om (at) excluded (dot) org [email concealed]> software: eTrust Virus Protection 6.0 InoculateIT for linux local phun with etrust antivirus 6.0 inoculateIT linux ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ eTrust InnoculateIT 6.0 comes for the following OSes: -windows 95/98/ME [ more ] [ reply ] |
|
Privacy Statement |
PUBLIC
========================================================================
=
ACROS Security Problem Report #2004-01-20-1
------------------------------------------------------------------------
-
ASPR #2004-01-20-1: Internet Explorer/Outlook double null character
[ more ] [ reply ]