|
Colapse all |
Post message
RE: DANGER ZONE: Internet Explorer 2003-12-29 tlarholm pivx com (1 replies) RE: DANGER ZONE: Internet Explorer 2003-12-29 http-equiv (at) excite (dot) com [email concealed] (1 malware com) [Hat-Squad] Remote buffer overflow in Mdaemon Raw message Handler 2003-12-29 Hat-Squad Security Team (service hat-squad com) php-ping: Executing arbritary commands 2003-12-29 ppp-design (security ppp-design de) ppp-design found the following design error in php-ping: Details ------- Product: php-ping Affected Version: (no version information included in the script) Immune Version: latest version OS affected: all OS with php Vendor-URL: http://www.theworldsend.net/ Vendor-Status: informed, new version ava [ more ] [ reply ] SQL Injection in phpBB's groupcp.php 2003-12-29 Jay Gates (zarath knightsofchaos com) BugTraq, I have found an SQL injection vulnerability in phpBB. Hoever, I don't think this is going to be be a wide spread problem as it will only work if you are the moderator of a group. How the SQL injection works: In groupscp, it uses an array set to delete members from certain groups. [ more ] [ reply ] GLSA: cvs (200312-08) 2003-12-29 Rajiv Aaron Manglani (rajiv gentoo org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- GENTOO LINUX SECURITY ANNOUNCEMENT 200312-08 - ------------------------------------------------------------------------ -- GLSA: 200312-08 package: dev-util/cvs su [ more ] [ reply ] New VISA scam exploits IE vulnerability 2003-12-24 Marek Szuba (cyberman if pw edu pl) (Moderators: feel free to wrap the long lines if you think it's necessary, I'm posting it as I received it) Hello bugtraq, The VISA scam rides again! === Cut === From 1863qb (at) yahoo (dot) com [email concealed] Wed Dec 24 00:42:50 2003 Received: from 172.153.31.70 (AC991F46.ipt.aol.com [172.153.31.70]) by xxxx.xxxx.xxx [ more ] [ reply ] Re: Reported Command Injection in Squirrelmail GPG 2003-12-26 Brian G. Peterson (brian braverock com) Bugtraq Security Systems released an advisory on Dec 24th to the Full Disclosure email list about a possible Command Injection Issue in the GPG subsystem of Squirrelmail. Please note that Bugtraq Security Systems Inc has no affiliation with the well-regarded official Bugtraq list at securityfocus.c [ more ] [ reply ] DANGER ZONE: Internet Explorer 2003-12-26 http-equiv (at) excite (dot) com [email concealed] (1 malware com) Friday, December 26, 2003 Technical 'silent delivery and installation of an executable on a target computer. No client input other than viewing and web site'. This may be achieved with the Internet Explorer series of so- called "browsers", all security settings set to HIGH ! [***premium adver [ more ] [ reply ] OpenBB 1.06 SQL Injection 2003-12-26 n teusink planet nl Hello bugtraq readers, A vulnerability exists in OpenBB 1.06 that could allow an attacker to manipulate SQL queries and obtain sensitive information from the database such as the administrator md5 password hash. This vulnerability exists because the index.php script of the application does not [ more ] [ reply ] IE 5.22 on Mac Transmitting HTTP Referer from Secure Page 2003-12-24 deane deanebarker net Documented instance of Internet Explorer 5.22 on a Mac transmitting an HTTP Referer header from a link on a secure page (https): http://www.gadgetopia.com/2003/12/23/OutlookWebAccessPrivacyHole.html This is clearly covered in the HTTP 1.1 spec (RFC 2616), Section 15.1.3, "Encoding Sensitive [ more ] [ reply ] Remote Code Execution in Knowledge Builder. 2003-12-24 Zero_X www.lobnan.de Team (zero-x linuxmail org) Multiple Vulns in Psychoblogger beta1 2003-12-23 Andrew Smith (parenthesis elitehaven net) Hello Bugtraq, As a part of a recent code audit of the Psychoblogger beta1 code, multiple vulnerabilities were found in the standard distributed code base. These vulnerabilities range from XSS exploits to SQL Injection exploits. All details in attached advisory or at http://www.fribble.net/adviso [ more ] [ reply ] QuikStore Shopping Cart Discloses Installation Path & Files to Remote Users 2003-12-23 Dr`Ponidi Haryanto (drponidi hackermail com) Re: phpBB v2.06 search_id sql injection exploit 2003-12-23 Micheal Cottingham (micheal michealcottingham com) It'd be nice if people would actually check the software site first for fixes ... http://www.phpbb.com/phpBB/viewtopic.php?t=153818 All you need to know is there. International Veneer Co., Inc. wrote: >----- Original Message ----- >From: "f3sy1 f3sy1" <f3sy1 (at) mail (dot) ru [email concealed]> >To: <bugtraq@securityfocus [ more ] [ reply ] ProjectForum Multiple Vulnerabilities 2003-12-22 Peter Winter-Smith (peter4020 hotmail com) ProjectForum Multiple Vulnerabilities ##################################### Credit: Author : Peter Winter-Smith Software : ProjectForum Versions : Version 8.4.2.1 and below Vendor : Equi4 Software Vendor Url : http://www.projectforum.com/projectforum/ Vulnerability: Bug Type : Deni [ more ] [ reply ] Re: Remote crash in tcpdump from OpenBSD 2003-12-21 mrh_tech yahoo com In-Reply-To: <3FE4CAC1.8010306 (at) freebsd.lublin (dot) pl [email concealed]> When an l2tp control packet is sent with optional bits set but containing invalid data, l2tp_avp_print() is passed this bad data. Then, l2tp_avp_print() calls itself and continues an infinite loop of passing bad data to itself. I had the consist [ more ] [ reply ] CesarFTP v0.99g CPU OverLoad [Proof of concept] 2003-12-22 zib zib (zibelette aol com) Description : FTP server CesarFTP v0.99g has a security hole in the command CWD. This command allow somebody to rise up the CPU usage with the following command : USER user PASS pass CWD ..................per 10000.... The CPU utilisation will be equal to 100%, the connection will not res [ more ] [ reply ] An undetectable Online Bank Vulnerability? 2003-12-21 Mark Peterson (apalamen sbcglobal net) (1 replies) December 20, 2003 RE: Banking/eCommerce Basic Vulnerability - Undetectable Due to the well-known documented ability of XSS/CSS capabilities and the proliferation of 3rd-party web-services, can anyone confirm the following: If an Online Bank utilizes 3rd-party webservices (javascript/.JS) [ more ] [ reply ] |
|
Privacy Statement |
Zone you are giving it additional privileges - this is by design and not
a vulnerability. You can read more about IE Security Settings at
http://www.microsoft.com/windows/ie/using/howto/security/settings.asp
from which we can a
[ more ] [ reply ]