|
Colapse all |
Post message
[RHSA-2003:042-07] Updated squirrelmail packages close cross-site scripting vulnerabilities 2003-03-05 bugzilla redhat com Re: Netscape Communicator 4.x sensitive informations in configuration file 2003-03-04 mstoltz netscape com In-Reply-To: <3E5F651E.35B09C5D (at) computec (dot) ch [email concealed]> >It seems that I'm one of the last Netscape 4.x users. >The following paste shows the IMAP mail part of this configuration file. >You can see that the line 17 shows the unencrypted password Netscape 4.x is out of date - we recommend that everyon [ more ] [ reply ] [OpenPKG-SA-2003.016] OpenPKG Security Advisory (sendmail) 2003-03-04 OpenPKG (openpkg openpkg org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ________________________________________________________________________ OpenPKG Security Advisory The OpenPKG Project http://www.openpkg.org/security.html http://www.openpkg.org openpkg-security (at) openpkg (dot) org [email concealed] [ more ] [ reply ] Log corruption on multiple webservers, log analyzers,... 2003-03-04 Hugo Vázquez Caramés (overclocking_a_la_abuela hotmail com) Hi, something that could be interesting... We have decided not to contact any vendor (many vendors are vulnerable and we have not enough time...sorry) and made this advisory public in this list. ILLC - Inverse Lookup Log Corruption We are using a technique that we have called ?ILLC? [ more ] [ reply ] [OpenPKG-SA-2003.017] OpenPKG Security Advisory (file) 2003-03-04 OpenPKG (openpkg openpkg org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ________________________________________________________________________ OpenPKG Security Advisory The OpenPKG Project http://www.openpkg.org/security.html http://www.openpkg.org openpkg-security (at) openpkg (dot) org [email concealed] [ more ] [ reply ] BIND 9.2.2 Vulnerabilities? 2003-03-04 John (bugtraq doomsday com) (2 replies) The ISC website lists the following as of today: http://www.isc.org/products/BIND/bind-security.html "ISC has discovered or has been notified of several bugs which can result in vulnerabilities of varying levels of severity in BIND as distributed by ISC. Upgrading to BIND version 9.2.2 is stron [ more ] [ reply ] iDEFENSE Security Advisory 03.04.03: Locally Exploitable Buffer Overflow in file(1) 2003-03-04 iDEFENSE Labs (labs idefense com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 iDEFENSE Security Advisory 03.04.03: http://www.idefense.com/advisory/03.04.03.txt Locally Exploitable Buffer Overflow in file(1) March 4, 2003 I. BACKGROUND file(1) is an application that utilizes a magic file (typically located in /usr/share/magic) [ more ] [ reply ] uploader.php script 2003-03-04 auto40951 hushmail com -----BEGIN PGP SIGNED MESSAGE----- The password is not enabled by default, but the readme has the following installation instructions: - --- open setup.php and edit these options $ADMIN[RequirePass] = "Yes"; // Checks to see if upload has a vaild password $ADMIN[Password] = "password"; // [ more ] [ reply ] [OpenPKG-SA-2003.015] OpenPKG Security Advisory (zlib) 2003-03-04 OpenPKG (openpkg openpkg org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ________________________________________________________________________ OpenPKG Security Advisory The OpenPKG Project http://www.openpkg.org/security.html http://www.openpkg.org openpkg-security (at) openpkg (dot) org [email concealed] [ more ] [ reply ] Re: New HP Jetdirect SNMP password vulnerability when using Web JetAdmin 2003-03-04 Sven Pechler (helpdesk tm tue nl) In-Reply-To: <3E63BA9C.3000303 (at) satx.rr (dot) com [email concealed]> Hello Geoff, Thank you for your reply. Some reactions on your statements: 1. I've tested the SNMP 'set community name'. None responded to 'internal' after I changed it to something else. You are right when you mean the SNMP 'GET community na [ more ] [ reply ] RE: Siemens *35 and 45 series phones SMS Danial of Service 2003-03-03 Willis Johnson (willisj microsoft com) What happens if the string is sent repeatedly while the phone is turned on but is unattended or receives text messages silently? Is the battery drained as predicted? Willis -----Original Message----- From: Jan Niehusmann [mailto:jan (at) gondor (dot) com [email concealed]] Sent: Monday, March 03, 2003 2:46 PM To: subj subj [ more ] [ reply ] Security Update: [CSSA-2003-SCO.3] UnixWare 7.1.1 Open UNIX 8.0.0 UnixWare 7.1.3 : ftp vulnerability with pipe symbols in filenames 2003-03-03 security caldera com To: bugtraq (at) securityfocus (dot) com [email concealed] announce (at) lists.caldera (dot) com [email concealed] scoannmod (at) xenitec.on (dot) ca [email concealed] full-disclosure (at) lists.netsys (dot) com [email concealed] ________________________________________________________________________ ______ SCO Security Advisory Subject: UnixWare 7.1.1 Open UNIX 8.0.0 UnixWare 7.1.3 : ftp vulnerability wit [ more ] [ reply ] HP-UX security bulletins digest [Fwd/sendmail issue] 2003-03-04 support_feedback us-support2-mail external hp com (IT Resource Center\ ) uploader.php vulnerability 2003-03-04 kingcope gmx net Uploader Version 1.1 which is available from http://www.phpscriptcenter.com/uploader.php includes "uploader.php", which lets you upload ANY file (even scripts eg. in PHP) onto the server if no password protection is specified in the configuration file (default set to off). The supplied files will be [ more ] [ reply ] Fwd: CERT Advisory CA-2003-07 Remote Buffer Overflow in Sendmail 2003-03-04 Muhammad Faisal Rauf Danka (mfrd attitudex com) *** There is an attachment in this mail. *** _____________________________________________________________ --------------------------- [ATTITUDEX.COM] http://www.attitudex.com/ --------------------------- _____________________________________________________________ Select your own custom email a [ more ] [ reply ] Fwd: APPLE-SA-2003-03-03 sendmail 2003-03-04 Bryan Blackburn (blb pobox com) ----- Forwarded message from Product Security <product-security (at) apple (dot) com [email concealed]> ----- Return-Path: <security-announce-admin (at) lists.apple (dot) com [email concealed]> Date: Mon, 03 Mar 2003 14:09:17 -0800 Subject: APPLE-SA-2003-03-03 sendmail From: Product Security <product-security (at) apple (dot) com [email concealed]> To: <security-announce (at) lists (dot) appl [email concealed]e. [ more ] [ reply ] |
|
Privacy Statement |
Issue: Shopfactory e-commerce application allows alteration of order details
Date: 03/05/03
Vendor first notified: December 2002
Affected versions: All available versions (current version Shopfactory 5.8)
ABOUT SHOPFACTORY:
Shopfactory is a shopping cart solution. According t
[ more ] [ reply ]