|
Colapse all |
Post message
[SCSA-025] Invision Power Board SQL Injection Vulnerability 2004-01-03 advisory security-corporation com ====================================================================== Security Corporation Security Advisory [SCSA-025] Invision Power Board SQL Injection Vulnerability ====================================================================== PROGRAM: Invision Power Board HOMEPAGE: http://www.invis [ more ] [ reply ] xsok local games exploit (2) 2004-01-03 c0wboy@0x333 (c0wboy tiscali it) [c0wboy@0x333 c0wboy]$ gcc "0x333xsok(2).c" -o exp_2 [c0wboy@0x333 c0wboy]$ ./exp_2 --- 0x333xsok => xsok 1.02 local games exploit --- --- Outsiders Se(c)urity Labs 2003 --- sh-2.05b$ id uid=500(c0wboy) gid=20(games) groups=500(c0wboy) sh-2.05b$ exit exit [c0wboy@0x333 c0wboy]$ sorry but too alcool [ more ] [ reply ] Webcam Watchdog Stack Overflow Vulnerability 2004-01-03 Peter Winter-Smith (peter4020 hotmail com) Webcam Watchdog Stack Overflow Vulnerability ############################################ Credit: Author : Peter Winter-Smith Software: Packages : Webcam Watchdog Version : 3.63 and below Vendor : Webcam Corp. Vendor Url : http://www.webcamsoft.com/en/watchdog.html Vulnerability: Bu [ more ] [ reply ] RE: Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part IV 2004-01-02 tlarholm pivx com Naturally, this only works from a local security zone such as the My Computer zone. You cannot exploit the Shell.Application object from the Internet Zone where you get an explanatory "Permission Denied" error. This eases the process of abusing local security zone privileges but does not change the [ more ] [ reply ] include() vuln in EasyDynamicPages v.2.0 2004-01-02 Vietnamese Security Group (security security com vn) Microsoft Word Protection Bypass 2004-01-02 Thorsten Delbrouck-Konetzko (Thorsten Delbrouck guardeonic com) Hi all, Microsoft Word provides an option to protect "forms" by password. This is used to ensure that unauthorized users cannot manipulate the contents of documents except within specially designed "form" areas. This feature is also often used to protect documents which do not even have form are [ more ] [ reply ] Re: Switch Off Multiple Vulnerabilities 2004-01-02 Peter Winter-Smith (peter4020 hotmail com) Hi, Re: http://www.elitehaven.net/switchoff.txt I neglected to mention the fact that just issuing a regular HTTP GET request with no other headers seems to cause the application to error within the module 'msvcrt.dll'. I have not attempted to investigate why this happens. Such a request may be as [ more ] [ reply ] Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part IV 2004-01-01 http-equiv (at) excite (dot) com [email concealed] (1 malware com) Thursday, January 01, 2004 The following file is an html file comprising both scripting and an executable [*.exe]. We inject scripting and an executable into the html file which is designed to point back to the executable in the html file and execute it. Provided the html file is an html f [ more ] [ reply ] Possible XSS vuln in VCard4J 2004-01-01 Just1n T1mberlake (hotpackets hellokitty com) Timberlake Advisory 2004010109h. Program: http://sourceforge.net/projects/vcard4j/ vCard4J is a complete toolkit to manipulate vCards (RFC 2426) in Java. It contains a parser to read vCard files. It is strange and fearsome to touch. It also includes a compiler to extend the library. And it contai [ more ] [ reply ] multiple payload handling flaws in isakmpd, again 2003-12-31 Thomas Walpuski (thomas thinknerd de) (1 replies) 0 Preface On 2003/11/06 a bug fix for a payload handling flaw in isakmpd described in http://securityfocus.com/archive/1/343173 was committed to CVS. Other payload handling flaws, which were not presented on a silver platter, but only mentioned in side notes, still remain unfixed. This [ more ] [ reply ] Re: multiple payload handling flaws in isakmpd, again 2004-01-01 Thomas Walpuski (thomas thinknerd de) MDKSA-2003:095-1 - Updated proftpd packages fix remote root vulnerability 2003-12-31 Mandrake Linux Security Team (security linux-mandrake com) Re: Local Denial Of Service Attack Against Apple MacOS X, MacOS X Server, and Darwin. 2003-12-31 William A. Carrel (william a carrel org) In article <BC175C14.1C6E%marukka (at) mac (dot) com [email concealed]>, Matt Burnett <marukka (at) mac (dot) com [email concealed]> wrote: > Advisory Name > Local Denial Of Service Attack Against The SecurityServer Daemon In MacOS X, > MacOS X Server, And Darwin. > Proof Of Concept Code > To build this code run ³gcc <file name> -framework Security o > [ more ] [ reply ] RE: IE 5.22 on Mac Transmitting HTTP Referer from Secure Page 2003-12-30 tlarholm pivx com This applies to ALL versions of Internet Explorer on all systems, though IE on Windows require that the HTTPS site is left through a redirection. I verified this on IE 5, 5.5, 6 and 6SP1. As an easily demonstrated example, open your Windows IE and go to https://login.yahoo.com/config/login then t [ more ] [ reply ] TOCTOU with NT System Service Hooking 2003-12-30 Andrey Kolishak (andr sandy ru) TOCTOU (Time-Of-Check-to-Time-Of-Use) problem is known for a while [1]. Nevertheless such bugs are still not uncommon. That is more or less acceptable for general software but not for security products. I believe there are drivers that hook kernel system services by well known technique [2,3,4]. Th [ more ] [ reply ] [SECURITY] [DSA 405-1] New xsok packages fix local group games exploit 2003-12-30 joey infodrom org (Martin Schulze) IE 5.x-6.0 allows executing arbitrary programs using showHelp() 2003-12-30 Arman Nayyeri (arman-n Phreaker net) IE 5.x-6.0 allows executing arbitrary programs using showHelp() =============================================================== Title: IE 5.x-6.0 allows executing arbitrary programs using showHelp() Date: Monday, December 29, 2003 Software: IE 5.x, 6.0 Vendor: Microsoft Corp. Patch: [ more ] [ reply ] Gallery v1.3.3 Cross Site Scripting Vulnerabillity 2003-12-30 The-Insider (nuritrv18 bezeqint net) (2 replies) ####################################################################### Application: Gallery Vendors: http://gallery.sourceforge.net http://gallery.menalto.com Versions: <= 1.3.3 Platforms: Windows/Unix Bug: Cross Site Scripting Vulnerabillity Risk: Lo [ more ] [ reply ] Re: Gallery v1.3.3 Cross Site Scripting Vulnerabillity 2003-12-30 Bharat Mediratta (bharat menalto com) NetObserve Security Bypass Vulnerability 2003-12-29 Peter Winter-Smith (peter4020 hotmail com) NetObserve Security Bypass Vulnerability ######################################## Credit: Author : Peter Winter-Smith Software: Packages : NetObserve Version : 2.0 and prior Vendor : ExploreAnywhere Software Vendor Url : http://www.exploreanywhere.com/no-intro.php Vulnerability: Bug [ more ] [ reply ] Cross Site Scripting vulnerability in miniBB 1.7 (latest) and earlier 2003-12-28 Chintan Trivedi (chesschintan hotmail com) ==================================================================== Advisory by Eye On Security Research Group - India www.eos-india.net ==================================================================== 1...............................................................Product 2..... [ more ] [ reply ] |
|
Privacy Statement |
'newsPHP arbitary file inclusion & bad login validation'
bug published on 1st sepember 2003.
===+++===+++===+++
Product: newsPHP
Version: <= v216
Vendor: http://www.nphp.net
Bug discover by: Officerrr <officerrr (at) poligon.com (dot) pl [email concealed]>
Vendor Response: no patch released since
[ more ] [ reply ]