Mail Index
- [security bulletin] HPSBUX02108 SSRT061133 rev.2 - HP-UX running Sendmail, Remote Execution of Arbitrary Code
- RE: WebVulnCrawl searching excluded directories for hackable web servers
- OSSTMM Security Analyst Training Live Stream on the Web
- Re: Sudo tricks
- Re: On classifying attacks
- EzASPSite <= 2.0 RC3 Remote SQL Injection Exploit Vulnerability.
- From: Mustafa Can Bjorn IPEKCI
- RE: recursive DNS servers DDoS as a growing DDoS problem
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data
- RE: Sudo tricks
- Re: Re: Cantv/Movilnet's Web SMS vulnerability.
- DbbS<=2.0-alpha SQL injection
- Buffer-overflow and in-game crash in Zdaemon 1.08.01
- Warcraft III Replay Parser Script Remote Command Exucetion Vulnerability And Cross-Site Scripting Attacking
- Mis-diagnosed XSS bugs hiding worse issues due to PHP feature
- linksubmit <= All version Html Tag Injector in index.php
- Re: recursive DNS servers DDoS as a growing DDoS problem
- SQuery <= 4.5 Remote File Inclusion Exploit
- Re: [Full-disclosure] Mis-diagnosed XSS bugs hiding worse issues due to PHP feature
- RE: recursive DNS servers DDoS as a growing DDoS problem
- FleXiBle Development Script Remote Command Exucetion And XSS Attacking
- Re: Mis-diagnosed XSS bugs hiding worse issues due to PHP feature
- Re: Re: Re: phpBB 2.06 search.php SQL injection
- From: theguywhocouldwipeyourphpBB
- DoS-ing sysklogd?
- PHPNuke-Clan 3.0.1 Remote File Inclusion Exploit
- GeSWall 2.2 – Free Intrusion Prevention System for Windows
- From: GentleSecurity Team
- Re: recursive DNS servers DDoS as a growing DDoS problem
- SiteMan <= All version SQL injection in admin_login.asp
- Phpwebgallery <= 1.4.1 SQL injection Vulnerability
- Secunia Research: AN HTTPD Script Source Disclosure Vulnerability
- Re: On product vulnerability history and vulnerability complexity
- [USN-266-1] dia vulnerabilities
- [SECURITY] [DSA 1000-2] New Apache2::Request packages fix denial of service
- Another Internet Explorer Address Bar Spoofing Vulnerability
- Hosting Controller AccountActions.asp and saveuploadfiles.asp vulns (PoC)
- Flaw in commonly used bash random seed method
- Re: Mis-diagnosed XSS bugs hiding worse issues due to PHP feature
- RE: DoS-ing sysklogd?
- VWar <= 1.5.0 R12 Remote File Inclusion Exploit
- Multiple Vulnerabilities in LucidCMS
- MyBB 1.10 New CrossSiteScripting
- Re: Flaw in commonly used bash random seed method
- Re: On product vulnerability history and vulnerability complexity
- RE: recursive DNS servers DDoS as a growing DDoS problem
- Re: On product vulnerability history and vulnerability complexity
- Re: On product vulnerability history and vulnerability complexity
- SQL Injection in Softbiz Image Gallery
- Re: WebVulnCrawl searching excluded directories for hackable web servers
- Re: Cantv/Movilnet's Web SMS vulnerability.
- Re: On classifying attacks
- Re: On product vulnerability history and vulnerability complexity
- From: Forrest J. Cavalier III
- Re: recursive DNS servers DDoS as a growing DDoS problem
- [ MDKSA-2006:064 ] - Updated MySQL packages fix logging bypass vulnerability
- [ MDKSA-2006:062 ] - Updated dia packages fix buffer overflow vulnerabilities
- Re: recursive DNS servers DDoS as a growing DDoS problem
- ReloadCMS <= 1.2.5stable Cross site scripting / remote command execution
- SYMSA-2006-002: McAfee WebShield SMTP Format String Vulnerability
- From: CS_Advisories Mailbox
- Bypassing ISA Server 2004 with IPv6
- Re: Flaw in commonly used bash random seed method
- Re: Bypassing ISA Server 2004 with IPv6
- RUXCON 2006 Call for Papers
- SMART Technologies SynchronEyes Remote Denial of Services
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Re: On product vulnerability history and vulnerability complexity
- Re: recursive DNS servers DDoS as a growing DDoS problem
- RE: recursive DNS servers DDoS as a growing DDoS problem
- Format string in Doomsday 1.8.6
- Re: On product vulnerability history and vulnerability complexity
- [USN-267-1] mailman vulnerability
- Re: On product vulnerability history and vulnerability complexity
- RE: recursive DNS servers DDoS as a growing DDoS problem
- [ GLSA 200604-01 ] MediaWiki: Cross-site scripting vulnerability
- Barracuda LHA archiver security bug leads to remote compromise
- From: Jean-Sébastien Guay-Leroux
- Re: DoS-ing sysklogd?
- Re: DoS-ing sysklogd?
- Barracuda ZOO archiver security bug leads to remote compromise
- From: Jean-Sébastien Guay-Leroux
- [security bulletin] HPSBPI2109 SSRT061141 rev.1 - HP Color LaserJet 2500 and 4600 Toolbox Running on Microsoft Windows Remote Unauthorized Disclosure of Information
- [ GLSA 200604-02 ] Horde Application Framework: Remote code execution
- Re: recursive DNS servers DDoS as a growing DDoS problem
- [ GLSA 200604-03 ] FreeRADIUS: Authentication bypass in EAP-MSCHAPv2 module
- RE: recursive DNS servers DDoS as a growing DDoS problem
- From: Thomas Guyot-Sionnest
- Buffer-overflow in Ultr@VNC 1.0.1 viewer and server
- Re: Flaw in commonly used bash random seed method
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data
- RE: recursive DNS servers DDoS as a growing DDoS problem
- Re: Another Internet Explorer Address Bar Spoofing Vulnerability
- ArabPortal 2.0.1 Stable [ 9 CrossSiteScripting & 1 SQL Injection ] MultBugz
- Re: Flaw in commonly used bash random seed method
- NOD32 local privilege escalation vulnerability
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data
- From: Jasper Bryant-Greene
- Another way to spoof Internet Explorer Address Bar
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are runningweb with sen
- From: mailinglist mailinglist
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data
- Re: Limbo CMS code execution
- Black Hat Call for Papers and Registration now open
- [Full-disclosure] PIRANA exploitation framework and SMTP contentfilter security
- From: Jean-Sébastien Guay-Leroux
- [SECURITY] [DSA 1022-1] New storebackup packages fix several vulnerabilities
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Re: recursive DNS servers DDoS as a growing DDoS problem
- [ECHO_ADV_27$2006] AngelineCMS 0.8.1 Installpath Remote File Inclusion
- [SEC-1 LTD] HP Colour LaserJet 2500 and 4600 Toolbox Directory Traversal Vulnerability
- [ECHO_ADV_27$2006] AngelineCMS 0.8.1 Installpath Remote File Inclusion
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data
- From: Jasper Bryant-Greene
- Re: Flaw in commonly used bash random seed method
- Linux Kernel Local DoS vulnerability.
- Re: Re: Bypassing ISA Server 2004 with IPv6
- [FLSA-2006:152873] Updated xine package fixes security issues
- Re: Bypassing ISA Server 2004 with IPv6
- [SECURITY] [DSA 1024-1] New clamav packages fix several vulnerabilities
- Cisco Security Advisory: Cisco 11500 Content Services Switch HTTP Request Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Re: Buffer-overflow in Ultr@VNC 1.0.1 viewer and server
- [FLSA-2006:152896] Updated mod_python package fixes a security issue
- Autonomous LAN party File iNclusion
- [ MDKSA-2006:066 ] - Updated FreeRADIUS packages fix off-by-one overflow vulnerabilty
- Xss In SaphpLesson3.0
- [FLSA-2006:156139] Updated tcpdump packages fix security issues
- [FLSA-2006:156290] Updated cyrus-imapd packages fix security issues
- [FLSA-2006:170411] Updated imap packages fix security issue
- [FLSA-2006:183571-1] Updated tar package fixes security issue
- [FLSA-2006:183571-2] Updated tar package fixes security issue
- [FLSA-2006:180159] Updated unzip package fixes security issue
- [eVuln] Null news SQL Injection Vulnerability
- [FLSA-2006:184074] Updated pine package fixes security issue
- [FLSA-2006:184098] Updated libc-client packages fixes security issue
- [Updated] [FLSA-2006:186277] Updated sendmail packages fix security issue
- SQL Injection in Chipmunk Guestbook
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Sire 2.0 Nws Remote File inclusion & Arbitary Files Upload
- [Kaffeine Security Advisory] Heap based buffer overflow in http_peek()
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Black Hat Call for Papers and Registration now open
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Re: FleXiBle Development Script Remote Command Exucetion And XSS Attacking
- [eVuln] phpNewsManager Multiple SQL Injections
- Re: Bypassing ISA Server 2004 with IPv6
- Welcome to XCon2006 in China!
- [SECURITY] [DSA 1031-1] New cacti packages fix several vulnerabilities
- [SECURITY] [DSA 946-2] New sudo packages fix privilege escalation
- google xss
- [security bulletin] HPSBUX02108 SSRT061133 rev.3 - HP-UX running Sendmail, Remote Execution of Arbitrary Code
- RE: Another way to spoof Internet Explorer Address Bar
- [ MDKSA-2006:068 ] - Updated mplayer packages fix integer overflow vulnerabilities
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Re: Re: Another Internet Explorer Address Bar Spoofing Vulnerability
- [KAPDA::#38] - MyBB 1.1.0~functions_post.php~XSS Attack
- [eVuln] VSNS Lemon Multiple Vulnerabilities
- PHPMyChat 0.15.0dev "SYS enter" remote commands xctn (not properly patched from previous versions)
- [ MDKSA-2006:065 ] - Updated kaffeine packages fix remote buffer overflow vulnerability
- Matt Wright Guestbook Xss Script İnjection
- [eVuln] vCounter - sourceworkshop SQL Injection Vulnerability
- [USN-268-1] Kaffeine vulnerability
- LayerOne 2006 - Finalized Speaker Line-Up Announced
- PHPMyChat <= 0.14.5 remote commands execution
- Re: SQL injection in Invision Power Board v2.1.5
- [SECURITY] [DSA 1028-1] New libimager-perl packages fix denial of service
- [ECHO_ADV_28$2006] Clever Copy <= 3.0 Connect.inc Critical Information Disclosure
- [ MDKSA-2006:067 ] - Updated clamav packages fix vulnerabilities
- [ GLSA 200604-05 ] Doomsday: Format string vulnerability
- MAXDEV CMS Multiple vulnerabilities
- [SECURITY] [DSA 1018-2] New Linux kernel 2.4.27 packages fix several vulnerabilities
- Re: recursive DNS servers DDoS as a growing DDoS problem
- [eVuln] newsletter - sourceworkshop SQL Injection Vulnerability
- [ GLSA 200604-04 ] Kaffeine: Buffer overflow
- From: Sune Kloppenborg Jeppesen
- Shadowed Portal Cross Site Scripting
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data
- [SECURITY] [DSA 1027-1] New mailman packages fix denial of service
- Re: Another Internet Explorer Address Bar Spoofing Vulnerability
- Re: Flaw in commonly used bash random seed method
- XSS Bug in Cherokee Webserver
- [SECURITY] [DSA 1029-1] New libphp-adodb packages fix several vulnerabilities
- Google Reader "preview" and "lens" script improper feed validation
- Virtual War File İnclusion
- Cisco Security Advisory: Cisco Optical Networking System 15000 series and Cisco Transport Controller Vulnerabilities
- From: Cisco Systems Product Security Incident Response Team
- Re: Format string in Doomsday 1.8.6
- [SECURITY] [DSA 1030-1] New moodle packages fix several vulnerabilities
- Multiple vulnerability in jupiter CMS
- [SECURITY] [DSA 1026-1] New sash packages fix potential arbitrary code execution
- [ GLSA 200604-06 ] ClamAV: Multiple vulnerabilities
- From: Sune Kloppenborg Jeppesen
- Re: Buffer-overflow in Ultr@VNC 1.0.1 viewer and server
- [SECURITY] [DSA 1023-1] New kaffeine packages fix arbitrary code execution
- Re: Bios Information Leakage
- [security bulletin] HPSBUX02110 SSRT061110 rev.1 - HP-UX Running wu-ftpd Remote Denial of Service (DoS)
- [security bulletin] HPSBUX02111 SSRT061132 rev.1 - HP-UX su(1) Local Unauthorized Access
- [SECURITY] [DSA 1025-1] New dia packages fix arbitrary code execution
- RE: recursive DNS servers DDoS as a growing DDoS problem
- IE6 Crash
- [Overflow.pl] Clam AntiVirus Win32-UPX Heap Overflow (not default configuration)
- Re: IE6 Crash
- XMB Forum 1.9.5-Final XSS
- Oracle read-only user can insert/update/delete data via specially crafted views
- Re[2]: Bypassing ISA Server 2004 with IPv6
- TUGZip Archive Extraction Directory traversal
- Vulnerabilities in SPIP
- PhpOpenChat 3.0.x ADODB Server.php "sql" SQL injection
- phpinfo() Cross Site Scripting PHP 5.1.2 and 4.4.2
- function *() php/apache Crash PHP 4.4.2 and 5.1.2
- tempnam() open_basedir bypass PHP 4.4.2 and 5.1.2
- copy() Safe Mode Bypass PHP 4.4.2 and 5.1.2
- MyBB 1.10 'newthread.php' < CrossSiteScripting >
- Myspace.com - Intricate Script Injection
- Re: Bypassing ISA Server 2004 with IPv6
- From: Thor (Hammer of God)
- RE: google xss
- Re: Bypassing ISA Server 2004 with IPv6
- From: Thor (Hammer of God)
- Vegadns blind sql injection and cross site scripting
- PHPList <= 2.10.2 remote commands execution
- [eVuln] phpNewsManager Multiple SQL Injections
- Jbook Cross Site Scripting
- phpMyForum Cross Site Scripting & CRLF injection
- PHPWebGallery Multiple Cross Site Scripting Vulnerabilities
- [USN-269-1] xscreensaver vulnerability
- Re: PHPList <= 2.10.2 remote commands execution
- Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2
- Confixx 3.1.2 <= Cross Site Scripting Vuln
- INDEXU <= 5.0.1 (theme_path)and (base_path) Remote File Inclusion Exploit
- [ MDKSA-2006:069 ] - Updated openvpn packages fix vulnerability
- Multiple vulnerabilities in Blur6ex
- phpListPro <= 2.0 - Remote File Include Vulnerability
- Realplayer .SWF Multiple Remote Memory Corruption Vulnerabilities
- [eVuln] [V]Book Multiple Vulnerabilities
- ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability
- Manila <= 9.5 - XSS Vulnerabilities
- Confixx 3.1.2 <= SQL Injection
- IBM
- Tritanium Bulletin Board 1.2.3 - XSS
- [eVuln] VNews Multiple Vulnerabilities
- Re: google xss
- Re: Re: PHPList <= 2.10.2 remote commands execution
- [SRC-Telindus advisory] - HP System Management Homepage Remote Unauthorized Access
- AzDGVote File inclusion
- Re: Bypassing ISA Server 2004 with IPv6
- [ MDKSA-2006:071 ] - Updated xscreensaver packages fix clear-text password vulnerability
- [ MDKSA-2006:070 ] - Updated openvpn packages fix vulnerability
- IMF 2006 - Submission Deadline Extension
- IT Underground, London 2006 - call for papers
- Re: google xss
- SAXoPRESS - directory traversal
- 2nd European Conference on Computer Network Defense (EC2ND)
- Microsoft Internet Explorer DBCS Remote Memory Corruption Vulnerability
- Re: Buffer-overflow in Ultr@VNC 1.0.1 viewer POC
- [SECURITY] [DSA 1032-1] New zope-cmfplone packages fix unprivileged data manipulation
- [eVuln] QLnews XSS and PHP Code Insertion Vulnerabilities
- Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2
- Simplog <=0.9.2 multiple vulnerabilities
- [SECURITY] [DSA 1033-1] New horde3 packages fix several vulnerabilities
- Exploiting out of memory crashes and null pointers [was: Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2]
- Vulnerability in Microsoft FrontPage Server Extensions Could Allow Cross-Site Scripting
- From: Esteban Martinez Fayo
- [security bulletin] HPSBUX02108 SSRT061133 rev.6 - HP-UX running Sendmail, Remote Execution of Arbitrary Code
- [USN-270-1] xpdf vulnerabilities
- Clansys Multiple Xss Vulnerabilities
- Re: phpWebsite <= SQL Injection (friend.php) & (article.php)
- PatroNet CMS Xss Vuln
- Windows Help Heap Overflow
- SimpleBBS v1.1(posts.php) remote command execution
- [BuHa-Security] DoS Vulnerability in Firefox 1.5.0.1
- [eVuln] qliteNews SQL Injection Vulnerability
- [BuHa-Security] Stack Based Buffer Overflow Vulnerability in Amaya 9.4
- [BuHa-Security] Stack Based Buffer Overflow Vulnerability in Amaya 9.4 #2
- Remote File Inclusion in VBulletin ImpEx
- [BuHa-Security] Multiple Vulnerabilities in MS IE 6.0 SP2
- phpWebSite 0.10.? (topics.php) Remote SQL Injection Exploit
- Re: Multiple vulnerabilities in Blur6ex
- RevoBoard [email] tag XSS
- Re: google xss
- Recon 2006: speaker lineup announcement
- MyBB 1.10 New XSS ' member.php '
- Re: Confixx 3.1.2 <= SQL Injection
- Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2
- QuickBlogger v1.4 Cross-Site Scripting
- RE: IBM
- phpMyAdmin 2.7.0-pl1
- Re: Jupiter CMS <= 1.1.5 multiple XSS attack vectors.
- MyBB 1.10 New CrossSiteScripting ' member.php '
- SaphpLesson 2.0 (forumid) Remote SQL Injection Exploit
- Secunia Research: Adobe Document Server for Reader Extensions Multiple Vulnerabilities
- SEC Consult SA-20060314 :: Opera Browser CSS Attribute Integer Wrap / Buffer Overflow
- ZDI-06-008: Novell GroupWise Messenger Accept-Language Buffer Overflow
- Re: IBM
- TalentSoft Web+Shop Path Disclosure
- Re: RE: IBM
- [eVuln] RedCMS Multiple XSS and SQL Injection Vulnerabilities
- Camino Browser HTML Parsing Null Pointer Dereference Denial of Service Vulnerability
- PowerClan 1.14 - SQL Injection
- Re: Simplog <=0.9.2 multiple vulnerabilities
- [eVuln] aWebNews Multiple XSS and SQL Injection Vulnerabilities
- Vulnerabilities in lifetype
- Vulnerabilities in Papoo
- Vulnerabilities in MODx
- Farsinews Cross-Site Scripting & Path disclosure vulnerability
- osCommerce "extras/" information/source code disclosure
- Re: phpMyAdmin 2.7.0-pl1
- Encyclopedia <= 3.0 (login.php) CrossSite Scripting - XSS
- phpBB Admin command execution
- Serendipity Blog vuln
- [SECURITY] [DSA 1034-1] New horde2 packages fix several vulnerabilities
- phpBB template file code execution
- Re: Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2
- Avast Linux Home Edition (vulnerability on a temporary folder creation)
- [ GLSA 200604-07 ] Cacti: Multiple vulnerabilities in included ADOdb
- Firefox 1.5.0.1 Password Manager Arbtirary User Browsing History Disclosure
- Re: [Full-disclosure] SEC Consult SA-20060314 :: Opera Browser CSS Attribute Integer Wrap / Buffer Overflow
- Re: phpWebSite 0.10.? (topics.php) Remote SQL Injection Exploit
- Re: Re: NETGEAR WGT624 Wireless DSL router default user name/password vulnerability
- [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- From: Brandon S. Allbery KF8NH
- PAJAX Remote Code Injection and File Inclusion Vulnerability
- Xss In ar-blog v 5.2
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- RE: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- planetSearch+ - XSS Vulnerabilities
- Re: [ECHO_ADV_27$2006] Indexu <= 5.0.1 Remote File Inclusion
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- Re: SAXoPRESS - directory traversal aka Saxotech Online
- Re: Sql Injection in Confixx 3.06 & 3.08 & 3.?? ?
- a Yahoo Vulnerability
- Re[2]: Bypassing ISA Server 2004 with IPv6
- Dokeos 1.6.4 SQL Injection Vulnerability
- manila.userland cross site scriptable
- Re: QuickBlogger v1.4 Cross-Site Scripting
- ZDI-06-010: Mozilla Firefox CSS Letter-Spacing Heap Overflow Vulnerability
- [KAPDA]MyBB1.1.0~global.php~ParameterExtracting
- [KAPDA]CopperminePhotoGallery1.4.4~ PluginInclusionSystem(index.php)~ RemoteFileInclusion attack
- Re: Firefox 1.5.0.1 Password Manager Arbtirary User Browsing History Disclosure
- [eVuln] aWebBB Multiple XSS and SQL Injection Vulnerabilities
- [SECURITY] [DSA 1035-1] New fcheck packages fix insecure temporary file creation
- Re[3]: Bypassing ISA Server 2004 with IPv6
- PHP Album <= 0.3.2.3 remote commnads execution
- RE: osCommerce "extras/" information/source code disclosure
- Tiny Web Gallery <= 1.4 XSS
- PhpGuestbook <= 1.0 XSS
- FlexBB <= 0.5.7 BETA XSS
- Boardsolution <= 1.12 XSS
- phpFaber TopSites Script Cross-Site Scripting
- Snipe Gallery <= 3.1.4 Multiple XSS
- Re: Vulnerabilities in MOD
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Thor (Hammer of God)
- DbbS<=2.0-alpha Multiple Vulnerabilities
- Re: [KAPDA]CopperminePhotoGallery1.4.4~ PluginInclusionSystem(index.php)~ RemoteFileInclusion attack
- Xss In bMachine 2٫7
- FlexBB v0.5.5 BETA [SQL Inj] [XSS] [Login bypass]
- Calendarix "yearcal.php" XSS Attacking
- Re: Snipe Gallery <= 3.1.4 Multiple XSS
- MyEvent Remote File Execution And XSS Attacking
- BetaBoard Cross Site Scripting vulnerability
- PhpWebFTP 3.2 Login Script
- [SECURITY] [DSA 1036-1] New bsdgames packages fix local privilege escalation
- - PHPGraphy <= 0.9.11 "editwelcome" unauthorized access / cross site scripting -
- ShoutBOOK <= 1.1 XSS
- Neuron Blog <= 1.1 XSS
- [eVuln] CzarNews XSS and Multiple SQL Injection Vulnerabilities
- Tiny PHP forum - vulns
- AnimeGenesis <= XSS
- ZDI-06-009: Mozilla Firefox Tag Parsing Code Execution Vulnerability
- [ GLSA 200604-08 ] libapreq2: Denial of Service vulnerability
- FlexBB 0.5.5 Bypass Exploit
- Neon Responder (Dos,Exploit)
- [Argeniss] Alert - Yahoo! Webmail XSS
- gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- [eVuln] Wire Plastik wpBlog SQL Injection Vulnerability
- [SA-03] Example of Grsecurity protection avoid.
- Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- From: Michael Chamberlain
- Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- From: Forrest J. Cavalier III
- RE: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- Linpha 1.1.0 - XSS Vulnerabilities
- Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- Remote Xine Format String Vulnerability
- Re: [Full-disclosure] [Argeniss] Alert - Yahoo! Webmail XSS
- Another flaw in Firefox 1.5.0.2: to open files from remote
- Re: - PHPGraphy <= 0.9.11 "editwelcome" unauthorized access / cross site scripting -
- axoverzicht.cgi <= XSS
- blur6ex Local File Inclusion and SQL injection .
- Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- Re: [Full-disclosure] [Argeniss] Alert - Yahoo! Webmail XSS
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Ansgar -59cobalt- Wiechers
- Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- phpLister v. 0.4.1 XSS Attacking
- [ MDKSA-2006:072 ] - Updated kernel packages fix multiple vulnerabilities
- [KAPDA::#41] - Mambo/Joomla rss component vulnerability
- Multiple critical and high risk issues in Oracle's database server
- From: NGSSoftware Insight Security Research
- [Symantec Security Advisory] LiveUpdate for Macintosh Local Privilege Escalation
- Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- CuteNews 1.4.1 <= Cross Site Scripting
- SQL Injection in package SYS.DBMS_LOGMNR_SESSION
- FreeBSD Security Advisory FreeBSD-SA-06:14.fpu
- From: FreeBSD Security Advisories
- Oracle 10g 10.2.0.2.0 DBA exploit
- [MajorSecurity]ActualAnalyzer - Remote File Include Vulnerability
- XSS Vulnerability in Guest-book script powered by Community Architect
- Cisco Security Advisory: Cisco IOS XR MPLS Vulnerabilities
- From: Cisco Systems Product Security Incident Response Team
- Re: Path Disclosure and Arbitrary File Read Vulnerability in SLAB5000
- Re: [KAPDA::#41] - Mambo/Joomla rss component vulnerability
- [security bulletin] HPSBUX02108 SSRT061133 rev.7 - HP-UX running Sendmail, Remote Execution of Arbitrary Code
- Re: Multiple vulnerabilities in Linux based Cisco products
- Multiple vulnerabilities in Linux based Cisco products
- RechnungsZentrale V2 - SQL injection and Remote PHP inclusion vulnerabilities
- ThWboard <= 3 Beta 2.84 SQL Injection
- Cisco Security Advisory: Multiple Vulnerabilities in the WLSE Appliance
- From: Cisco Systems Product Security Incident Response Team
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Re: phpBB Admin command execution
- redirection vuln crawlers breed & security through obscurity
- From: Ivan Sergio Borgonovo
- Shbablek Mail Vulnerablitiy - Cross-Site Scripting
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- WWWThread RC 3 MultBugs
- Re: RE: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- ContentBoxx Login.php Cross-Site Scripting
- Fortinet28 box does not resist has small synflood!
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Re: Multiple Vulnerabilities in LucidCMS
- Tlen.PL e-mail XSS vulnerability.
- RE: redirection vuln crawlers breed & security through obscurity
- Re: RE: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Re: Re[2]: Bypassing ISA Server 2004 with IPv6
- From: Thor (Hammer of God)
- Confixx SQL Injection exploit (confixx_exploit.pl)
- EasyGallery Cross-Site Scripting
- Re[3]: Bypassing ISA Server 2004 with IPv6
- [eVuln] MD News Authentication Bypass and SQL Injection Vulnerabilities
- Re: Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- From: somerandomaddress99
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- Re: Re[2]: Bypassing ISA Server 2004 with IPv6
- SQL Injection in incredibleindia.org
- [eVuln] N.T. Version 1.1.0 XSS and PHP Code Insertion Vulnerabilities
- PCPIN Chat <= 5.0.4 "login/language" remote cmmnds xctn
- [USN-271-1] Firefox vulnerabilities
- Strengthen OpenSSH security?
- ASPSitem <= 1.83 Remote SQL Injection Vulnerability
- From: Mustafa Can Bjorn IPEKCI
- [eVuln] MWGuest XSS Vulnerability
- PHPSurveyor <= 0.995 'save.php/surveyid' remote cmmnds xctn
- ThWboard 3 Beta 2.84 Cross Site Scripting
- axoverzicht.cgi<==Remote File Inclusion
- Re: CuteNews 1.4.1 <= Cross Site Scripting
- [security bulletin] HPSBTU02095 SSRT051007 rev.3 - HP Tru64 UNIX Running DNS BIND4/BIND8 as Forwarders: Remote Unauthorized Privileged Access
- [security bulletin] HPSBST02112 SSRT061129 rev.1 - HP StorageWorks Secure Path for Windows Remote Denial of Service (DoS)
- Ad-Aware Revisited
- New site about security conferences : www.security-briefings.com
- From: newslist@xxxxxxxxxxxxxxxxxxxxxx
- Allied Telesyn Switch UDP Data Flood Management Denial Of Service Vulnerability
- RE: (addendum) redirection vuln crawlers breed & security through obscurity
- [Argeniss] Oracle Database 10gR1 Buffer overflow in VERIFY_LOG procedure
- Re: Strengthen OpenSSH security?
- Re: Strengthen OpenSSH security?
- Re: Strengthen OpenSSH security?
- Re: Re[3]: Bypassing ISA Server 2004 with IPv6
- From: Thor (Hammer of God)
- Re: Strengthen OpenSSH security?
- Re: Strengthen OpenSSH security?
- Re: Re[3]: Bypassing ISA Server 2004 with IPv6
- RE: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- RE: Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- 4images <= 1.7 XSS
- Websense Filter Bypass
- Re: Strengthen OpenSSH security?
- Mini-NUKE v2.3<<--- SQL Injection
- [ GLSA 200604-09 ] Cyrus-SASL: DIGEST-MD5 Pre-Authentication Denial of Service
- From: Sune Kloppenborg Jeppesen
- [ GLSA 200604-10 ] zgv, xzgv: Heap overflow
- From: Sune Kloppenborg Jeppesen
- [SecuriWeb 2006.1] directory traversal in Asterisk@Home and ARI
- BK Forum <<--V.4.0 SQL Injection
- Re: Strengthen OpenSSH security?
- [eVuln] MWNewsletter SQL Injection and XSS Vulnerabilities
- r57shell.php <= 1.3 XSS
- bloggage Remote SQL Injection
- [SECURITY] [DSA 1037-1] New zgv packages fix arbitrary code execution
- RE: [BULK] - Websense Filter Bypass
- Re: Mini-NUKE v2.3<<--- SQL Injection
- Scry Gallery Directory Traversal & Full Path Disclosure Vulnerabilites
- Rapid7 Advisory R7-0021: Symantec Scan Engine Authentication Fundamental Design Error
- Rapid7 Advisory R7-0022: Symantec Scan Engine Known Immutable DSA Private Key
- Rapid7 Advisory R7-0023: Symantec Scan Engine File Disclosure Vulnerability
- Rapid7 Advisory R7-0019: Directory traversal vulnerability in SolarWinds TFTP Server for Windows
- [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities
- [SECURITY] [DSA 1038-1] New xzgv packages fix arbitrary code execution
- VWar <= ver 1.21 Remote Code Execution Exploit
- dForum <= 1.5 Multiple Remote File Inclusion Vulnerabilities.
- From: Mustafa Can Bjorn IPEKCI
- vBulletin <= 3.5.4 with MKPortal 1.1 Remote SQL Injection Vulnerability.
- From: Mustafa Can Bjorn IPEKCI
- Advisory: Simplog <= 0.93 Multiple Remote Vulnerabilities.
- From: Mustafa Can Bjorn IPEKCI
- Advisory: CoreNews <= 2.0.1 Multiple Remote Vulnerabilities.
- From: Mustafa Can Bjorn IPEKCI
- [ GLSA 200604-11 ] Crossfire server: Denial of Service and potential arbitrary code execution
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Thor (Hammer of God)
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Thor (Hammer of God)
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Thor (Hammer of God)
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Thor (Hammer of God)
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Thor (Hammer of God)
- Re: Strengthen OpenSSH security?
- FlexBB 0.5.5 Exploit [ function/showprofile.php ] Remote SQL Injection
- Re: redirection vuln crawlers breed & security through obscurity
- Yahoo! Mail XSS Vulnerability
- MSIE (mshtml.dll) OBJECT tag vulnerability
- [USN-272-1] cyrus-sasl2 vulnerability
- NSFOCUS SA2006-03 : IBM AIX rm_mlcache_file Local Race Condition Vulnerability
- From: NSFOCUS Security Team
- NSFOCUS SA2006-02 : IBM AIX mklvcopy Local Privilege Escalation Vulnerability
- From: NSFOCUS Security Team
- [SECURITY] [DSA 1040-1] New gdm packages fix local root exploit
- [SECURITY] [DSA 1039-1] New blender packages fix several vulnerabilities
- Scry Gallery XSS Vulnerability
- [ GLSA 200604-14 ] Dia: Arbitrary code execution through XFig import
- From: Sune Kloppenborg Jeppesen
- [ GLSA 200604-13 ] fbida: Insecure temporary file creation
- From: Sune Kloppenborg Jeppesen
- [eVuln] RateIt SQL Injection Vulnerability
- [ GLSA 200604-12 ] Mozilla Firefox: Multiple vulnerabilities
- FileLodge Bolt (showonlineusers.php) Cross-Site Scripting Vulnerbility
- XSS Bug in OpenGear Server Website
- BK Forum <= 4.0 Remote SQL Injection
- [MajorSecurity] TotalCalendar 2.30 - Remote File Include Vulnerability
- [USN-273-1] Ruby vulnerability
- RIblog Remote SQL Injection Exploit
- Re: evoBlog Remote Name tag Script injection
- Buffer-overflow and crash in Fenice OMS 1.10
- Denial of service bugs in OpenTTD 0.4.7
- Multiple PHP4/PHP5 vulnerabilities
- Format string bug in Skulltag 0.96f
- Advisory: Clansys <= 1.1 PHP Code Insertion Vulnerability.
- From: Mustafa Can Bjorn IPEKCI
- Apple Mac OS X Safari 2.0.3 Vulnerability
- Firefox Remote Code Execution and DoS 1.5.0.2
- [MajorSecurity] phpMyAgenda 3.0 Final - Remote File Include Vulnerability
- VWar Path Disclosure
- vbulletin<--3.0.x SQL Injection
- Advisory: My Gaming Ladder Combo System <= 7.0 Remote File Inclusion Vulnerability.
- From: Mustafa Can Bjorn IPEKCI
- ADVISORY FOR IOPUS SECURE EMAIL ATTACHMENTS
- RE: [BULK] - Websense Filter Bypass
- Quick 'n Easy FTP Server pro/lite Logging unicode stack overflow
- Re: Apple Mac OS X Safari 2.0.3 Vulnerability
- Re: vbulletin<--3.0.x SQL Injection
- [ MDKSA-2006:074 ] - Updated php packages address multiple vulnerabilities.
- [ MDKSA-2006:073 ] - Updated cyrus-sasl packages addresses vulnerability
- photokorn 1.53 , 1.542 << Sql
- NextAge Shopping Cart Software XSS
- [ MDKSA-2006:075 ] - Updated mozilla-firefox packages fix numerous vulnerabilities
- PhpWebFtp Cross Site Scripting Vulnerability
- [SECURITY] [DSA 1041-1] New abc2ps packages fix arbitrary code execution
- NASL 'Split' function Buffer overflow Vulnerability
- Re: ADVISORY FOR IOPUS SECURE EMAIL ATTACHMENTS
- Re: ADVISORY FOR IOPUS SECURE EMAIL ATTACHMENTS
- Invision Vulnerabilities, including remote code execution
- Re: Apple Mac OS X Safari 2.0.3 Vulnerability
- Re: NASL 'Split' function Buffer overflow Vulnerability
- [SECURITY] [DSA 1042-1] New Cyrus SASL packages fix denial of service
- Re: NASL 'Split' function Buffer overflow Vulnerability
- Fenice - Open Media Streaming Server remote BOF exploit
- PowerPoint Phishing Trojan
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Thor (Hammer of God)
- Multiple vulnerabilities in IP3 Networks 'NetAccess' NA75 appliance
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- RE: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Re: Advisory: Clansys <= 1.1 PHP Code Insertion Vulnerability.
- Multiple browsers Windows mailto protocol Office 2003 file attachment exploit
- Instant Photo Gallery <= Multiple XSS
- Re: Apple Mac OS X Safari 2.0.3 Vulnerability
- Instant Photo Gallery <= Multiple XSS
- DCForumLite V 3.0<--XSS/SQL Injection
- Recent Oracle exploit is _actually_ an 0day with no patch
- [ MDKSA-2006:076 ] - Updated mozilla packages fix numerous vulnerabilities
- [ MDKSA-2006:077 ] - Updated ethereal packages fix numerous vulnerabilities
- [ MDKSA-2006:078 ] - Updated mozilla-thunderbird packages fix numerous vulnerabilities
- [ MDKSA-2006:079 ] - Updated ruby packages fix vulnerability
- Cisco Security Advisory: Cisco VPN 3000 Concentrator Vulnerable to Crafted HTTP Attack
- From: Cisco Systems Product Security Incident Response Team
- [SECURITY] [DSA 1044-1] New Mozilla Firefox packages fix several vulnerabilities
- MySmartBB<---v 1.1.x SQL Injection/XSS
- DevBB <= 1.0.0 XSS
- [SECURITY] [DSA 1044-1] New Mozilla Firefox packages fix several vulnerabilities
- Secunia Research: SpeedProject Products ACE Archive Handling Buffer Overflow
- [ GLSA 200604-15 ] xine-ui: Format string vulnerabilities
- From: Sune Kloppenborg Jeppesen
- [SECURITY] [DSA 1043-1] New abcmidi packages fix arbitrary code execution
- [ GLSA 200604-16 ] xine-lib: Buffer overflow vulnerability
- From: Sune Kloppenborg Jeppesen
- [eVuln] warforge.NEWS SQL Injection and Multiple XSS Vulnerabilities
- SQL Injection On DUportal
- Open Bulletin Board < Multiple Vulnerability
- XXS Attack On FarsiNews
- Local XXS Attack On CuteNews
- ZDI-06-011: Mozilla Firefox Table Rebuilding Code Execution Vulnerability
- Re: Apple Mac OS X Safari 2.0.3 Vulnerability
- Re: XV multiple buffer overflows (update)
- Re: Invision Vulnerabilities, including remote code execution
- [EEYEB-20060227] Juniper Networks SSL-VPN Client Buffer Overflow
- Re: Apple Mac OS X Safari 2.0.3 Vulnerability
- Re: Invision Vulnerabilities, including remote code execution
- MyBB 1.1.1 Local SQL Injections
-
- [USN-274-1] MySQL vulnerability
- Land Down Under 802 and below version Path Disclosure Vulnerability
- [security bulletin] HPSBUX02108 SSRT061133 rev.9 - HP-UX running Sendmail, Remote Execution of Arbitrary Code
- [security bulletin] HPSBUX02075 SSRT051074 rev.4 - HP-UX Running xterm Local Unauthorized Access
- Re: Instant Photo Gallery <= Multiple XSS
- From: security curmudgeon
- [ GLSA 200604-17 ] Ethereal: Multiple vulnerabilities in protocol dissectors
- From: Sune Kloppenborg Jeppesen
- [security bulletin] HPSBMA02113 SSRT061148 rev.1 - HP Oracle for OpenView (OfO) Critical Patch Update April 2006
- SQL injection exploit IPB <= 2.1.4
- Re: Instant Photo Gallery <= Multiple XSS
- [USN-275-1] Mozilla vulnerabilities
- [SECURITY] [DSA 1045-1] New OpenVPN packages fix arbitrary code execution
- [SECURITY] [DSA 1046-1] New Mozilla packages fix several vulnerabilities
- BL4's SMTP server BufferOverflow Vulnerable
- Re: Recent Oracle exploit is _actually_ an 0day with no patch
- Secunia Research: Servant Salamander unacev2.dll Buffer Overflow Vulnerability
- [ECHO_ADV_31$2006] Sws Web Server 0.1.7 Strcpy() & Syslog() Format String Vulnerability
- WinISO/UltraISO/MagicISO/PowerISO Directory Traversal Vulnerability
- Cireos Portal Cross Site Scripting
- [Argeniss] Alert - Yahoo! Mail XSS vulnerability
- Re: Recent Oracle exploit is _actually_ an 0day with no patch
- [Kurdish Security #3] CoolMenus Event Remote File Include Vulnerability (For PHP)
- [ GLSA 200604-18 ] Mozilla Suite: Multiple vulnerabilities
- [Kurdish Security #2] Artmedic Event Remote File Include Vulnerability
- RE: Recent Oracle exploit is _actually_ an 0day with no patch
- From: Kornbrust, Alexander
- Neomail.pl Local Cross Site Scripting
- Re: Recent Oracle exploit is _actually_ an 0day with no patch
- [Kurdish Secure Advisory #1] I-RATER Platinum "Admin/configsettings.tpl.php" Remote File Include Vulnerability
- Re: VWar Path Disclosure
- RE: Invision Vulnerabilities, including remote code execution
- Re: Apple Mac OS X Safari 2.0.3 Vulnerability
- Re: Recent Oracle exploit is _actually_ an 0day with no patch
- Re: phpMyForum Cross Site Scripting & CRLF injection
- Invision Power Board 2.1.5 POC
- poll.pl<--remote commands execution exploit
- W-Agora 4.20 XSS
- XSS Attack On DirectAdmin Hosting Managment
- TopList <= 1.3.8 (PHPBB Hack) Remote File Inclusion Vulnerability
- TextFileBB 1.0.16 Multiple XSS
Mail converted by MHonArc