Mail Index
- Browser bugs hit IE, Firefox today (SANS)
- Re: [Full-disclosure] Browser bugs hit IE, Firefox today (SANS)
- ezWaiter v3.0 - XSS
- [SECURITY] [DSA 1104-1] New OpenOffice.org packages fix several vulnerabilities
- libwmf integer/heap overflow
- [ GLSA 200606-30 ] Kiax: Arbitrary code execution
- From: Sune Kloppenborg Jeppesen
- Zen-Cart 1.3.0.2 Full Path Disclosure
- [Kil13r-SA-20060701-1] Ahnlab Search Cross-Site Scripting Vulnerability
- [Kil13r-SA-20060701-2] MoniWiki 1.1.1 Cross-Site Scripting Vulnerability
- [Kil13r-SA-20060701-3] Massting Cross-Site Scripting Vulnerability
- ISC: Firefox immune to outerHTML flaw in MSIE [Was: Browser bugs hit IE, Firefox]
- ZDI-06-020: Apple iTunes AAC File Parsing Integer Overflow Vulnerability
- FreeHost "misc.php & news.php" SQL Injection
- MyNewsGroups<<--v. 0.6 "tree.php" SQL Injection
- CDJ<<--V NITKID 2.0 "category.php" SQL Injection
- Module's Name "Classifieds" SQL Injection
- My smiles "browse.php" SQL Injection
- Hobbit monitor: Security issue with Hobbit 4.2-beta client
- NewsPHP 2006 PRO XSS SQL injection Vulnerability
- News <= 5.2 XSS, SQL Injection, Full Path Disclosure
- Re: [Full-disclosure] Re[2]: Is Windows TCP/IP source routing PoC code available?
- phpBB 2.0.21 Full Path Disclosure
- Re: PHP security (or the lack thereof)
- RE: [Full-disclosure] Browser bugs hit IE, Firefox today (SANS)
- Re: Browser bugs hit IE, Firefox today (SANS)
- Re: Msie 7.0 beta Crash
- [security bulletin] HPSBUX02128 SSRT5996 - rev.1 HP-UX mkdir(1) Local Unauthorized Access
- [security bulletin] HPSBUX02103 SSRT5953 rev.3 - HP-UX passwd(1) Local Denial of Service (DoS)
- Buddy Zone Version 1.0.1 - XSS
- mAds v1.0
- phpMyAdmin : Cross-Site Scripting Vulnerability
- From: bug@xxxxxxxxxxxxxxx
- DEF CON 14: Speakers Selected and more.
- OPERA Web Browser 9 Denial OF Service
- Internet Crna Gora SQL Injection
- SmS Script SQL Injection
- Sql injection in Diesel joke site script
- SturGeoN Upload v1 Remote Command Execution Exploit
- Whitepaper: IT (in)security implementation in a real world example
- Php-Fusion (Xss) With Avatar Upload
- Glossaire<<--v1.7 Remote File Include
- call for papers - IT Underground, Italy 2006
- [MajorSecurity #19] AutoRank <= 5.01 - Multiple XSS and cookie disclosure
- WordPress 2.0.3 SQL Error and Full Path Disclosure
- plume-cms v1.0.4 Multiple Remote File include
- Pearl Products Multiple Remote File Inclusion
- free QBoard v1.1 Multiple Remote File include
- Re: [Full Disclosure] [Kil13r-SA-20060701-2] MoniWiki 1.1.1 Cross-Site Scripting Vulnerability
- Multiple vulnerabilities in TK8 Safe v.3.0.5
- popup Vacation Rentals[calendar_year.php] SQL Injection
- QTOFileManager 1.0
- Invision Power Board v1.3 Final SQL Injection
- Contact for nhl.com
- Excel 2000/XP/2003 Style 0day POC
- 5 php scripts remote database password disclosure
- Call For Papers - No cON Name 2006 Edition Spain
- [ GLSA 200607-01 ] mpg123: Heap overflow
- From: Sune Kloppenborg Jeppesen
- ZoneAlarm Insufficient protection of registry key 'VETFDDNT\Enum' Vulnerability
- TBE 4.0 XSS
- imgsvr dos exploit by n00b
- Re: Browser bugs hit IE, Firefox today (SANS)
- [scip_Advisory 2351] Kyberna AG ky2help various form fields SQL Injection
- galleria <= 1.0 Remote File Inclusion Vulnerability
- Re: WordPress 2.0.3 SQL Error and Full Path Disclosure
- [scip_Advisory 2352] F5 FirePass 4100 prior 6.x multiple Cross Site Scripting
- file include exploits in randshop v1.2
- PhpWebGallery Cross Site Scripting Vulnerability
- Re: file include exploits in randshop v1.2
- Re: WordPress 2.0.3 SQL Error and Full Path Disclosure
- [Bugtraq] Re: flock d0s exploit remote. beta 1 (v0.7)
- Invision Power Board "v1.X & 2.X" SQL Injection
- Re: Browser bugs hit IE, Firefox today (SANS)
- Shopping Cart V0.9
- Windows Explorer URL File format overflow
- Touch arbitrary file execute vulnerability
- sNews 1.3 XSS SQL
- BLOG:CMS 4.1.0 SQL injection File Include Vulnerability
- Re: PHP security (or the lack thereof)
- [ MDKSA-2006:116 ] - Updated kernel packages fixes multiple vulnerabilities
- vBulletin 3.5.4 (install_path) Exploit
- TigerTom Scripts
- [SECURITY] [DSA 1104-2] New OpenOffice.org packages fix arbitrary code execution
- Public Advisory: Horde 3.1.1, 3.0.10 Multiple Security Issues
- Re: vBulletin 3.5.4 (install_path) Exploit
- [USN-308-1] shadow vulnerability
- [USN-309-1] libmms vulnerability
- [USN-310-1] ppp vulnerability
- Re: vBulletin 3.5.4 (install_path) Exploit
- Re: IBM AIX Security contact?
- Major updates to Excel 0-day Vulnerability FAQ at SecuriTeam Blogs
- Various heap and stack overflow bugs in AdPlug library 2.0 (CVS 04 Jul 2006)
- McAfee VirusScan Enterprise 8.0.0 Buffer Overflow
- Mico crashes when contected with wrong IOR / DoS
- TSLSA-2006-0040 - kernel
- From: Trustix Security Advisor
- WebEx Downloader Plug-in Multiple Vulnerabilities + rant
- PHP-Blogger Multiple Cross Site Scripting Vulnerabilities
- ATutor : Cross-Site Scripting Vulnerabilities
- From: bug@xxxxxxxxxxxxxxx
- [ECHO_ADV_36$2006] ExtCalendar <== v2.0 Remote File Include Vulnerabilities
- Possible code execution in Kaillera 0.86
- rPSA-2006-0122-1 kernel
- Format string bug in Sparklet 0.9.4try3
- PBL Guestbook <= 1.32 XSS & SQL Querys Vulnerabilities
- [ MDKSA-2006:117 ] - Updated libmms packages fix buffer overflow vulnerability
- HostingController: An attacker can gain reseller privileges and after that can gain admin privileges
- Sport-slo.net Guestbook v1.0
- IBM AIX Security contact?
- Pivot <=1.30rc2 privilege escalation / remote commands execution
- [SECURITY] [DSA 1105-1] New xine-lib packages fix denial of service
- lintah_|adv|_01@2006>=========<[Aura-CMS v1.62]<===>[XSS vulnerable]&[bug]
- ZDI-06-021: WebEx Downloader Plug-in Code Execution Vulnerability
- [ MDKSA-2006:118 ] - Updated OpenOffice.org packages fix various vulnerabilities
- PAPOO <=3RC3 sql injection / admin credentials disclosure
- Re: [Bugtraq] Re: flock d0s exploit remote. beta 1 (v0.7)
- [KAPDA::#46] - AjaxPortal Authentication Bypass
- ATutor 1.5.3 Cross Site Scripting
- RW::Download stats.php Remote File Inc.
- [ GLSA 200607-03 ] libTIFF: Multiple buffer overflows
- From: Sune Kloppenborg Jeppesen
- Webvizyon Portal 2006 Version SQL Injection
- Securing PHP or finding PHP alternatives (was: PHP security (or the lack thereof))
- Re: Invision Power Board "v1.X & 2.X" SQL Injection
- Graffiti Forums v1.0 SQL Injection Vulnerabilities
- Re: Mico crashes when contected with wrong IOR / DoS
- [ GLSA 200607-04 ] PostgreSQL: SQL injection
- From: Sune Kloppenborg Jeppesen
- MT rmcek Toplist v2.2 Version Microsoft Access Driver ( MDB ) Download
- LAMP vs Microsoft
- Re: RE: Invision Vulnerabilities, including remote code execution
- Re: [KAPDA::#46] - AjaxPortal Authentication Bypass
- ERNW Security Advisory 02/2006 - Buffer Overflow in sipXtapi (used in AOL Triton)
- Re: rPSA-2006-0122-1 kernel
- [ECHO_ADV_37$2006] pc_cookbook Mambo/Joomla Component <= v0.3 Remote File Include Vulnerabilities
- [SECURITY] [DSA 1106-1] New ppp packages fix privilege escalation
- Re: [ MDKSA-2006:116 ] - Updated kernel packages fixes multiple vulnerabilities
- phpPolls 1.0.3 Administration ByPass
- Re: galleria <= 1.0 Remote File Inclusion Vulnerability
- Re: Invision Power Board v1.3 Final SQL Injection
- [USN-312-1] gimp vulnerability
- RE: MIMESweeper For Web 5.X Cross Site Scripting
- CC announces new Rootkit help forum insync with Book
- MS Word Unchecked Boundary Condition Vulnerability
- Re: Re: vBulletin 3.5.4 (install_path) Exploit
- RE: WebEx Downloader Plug-in Multiple Vulnerabilities + rant
- Digital Armaments Security Advisory 10.07.2006: Flexwath Authorization Bypassing and XSS Vulnerability
- Re: Mico crashes when contected with wrong IOR / DoS
- Re: PHP security (or the lack thereof)
- Old vulnerable sotwares collection
- Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit
- Re: Windows Explorer URL File format overflow
- Re: Mico crashes when contected with wrong IOR / DoS
- [SECURITY] [DSA 1107-1] New GnuPG packages fix denial of service
- Re: Mico crashes when contected with wrong IOR / DoS
- Local file inclusion in Farsinews3.0BETA1
- [ANNOUNCEMENT] Samba 3.0.1 - 3.0.22: memory exhaustion DoS against smbd
- From: Gerald (Jerry) Carter
- randshop <= 1.1.x (index.php) Remote File Inclusion Vulnerability
- Re: LAMP vs Microsoft
- Juniper Networks DX Web Administration Persistent System Log XSS Vulnerability
- Re: LAMP vs Microsoft
- Re: Securing PHP or finding PHP alternatives
- [ GLSA 200607-02 ] FreeType: Multiple integer overflows
- From: Sune Kloppenborg Jeppesen
- [ GLSA 200607-05 ] SHOUTcast server: Multiple vulnerabilities
- From: Sune Kloppenborg Jeppesen
- SYMSA-2006-007: Microsoft Office Malformed String Parsing Vulnerability
- CYBSEC - Security Pre-Advisory: Microsoft Windows DHCP Client Service Remote Buffer Overflow
- From: Mariano Nuñez Di Croce
- TSRT-06-02: Microsoft SRV.SYS Mailslot Ring0 Memory Corruption Vulnerability
- From: Tippingpoint Security Research Team
- ZDI-06-022: Microsoft Office Excel File Rebuilding Code Execution Vulnerability
- Re: LAMP vs Microsoft
- [USN-313-1] OpenOffice.org vulnerabilities
- [USN-316-1] installer vulnerability
- [USN-315-1] libmms, xine-lib vulnerabilities
- Cisco Security Advisory: Multiple Cisco Unified CallManager Vulnerabilities
- From: Cisco Systems Product Security Incident Response Team
- [ MDKA-2006:119 ] - Updated ppp packages fix plugin vulnerability
- Cisco Security Advisory: Cisco Router Web Setup Ships with Insecure Default IOS Configuration
- From: Cisco Systems Product Security Incident Response Team
- Re: ATutor 1.5.3 Cross Site Scripting
- SQuery <= 4.5(libpath) Remote File Inclusion Exploit
- Re: [ANNOUNCEMENT] Samba 3.0.1 - 3.0.22: memory exhaustion DoS against smbd
- From: Gerald (Jerry) Carter
- [USN-314-1] samba vulnerability
- Cisco Security Advisory: Cisco Intrusion Prevention System Malformed Packet Denial of Service
- From: Cisco Systems Product Security Incident Response Team
- rPSA-2006-0128-1 samba samba-swat
- Fuzzing Microsoft Office
- SMB Information Disclosure Vulnerability
- Linux Kernel 2.6.x PRCTL Core Dump Handling - Local r00t Exploit ( BID 18874 / CVE-2006-2451 )
- From: Roman Medina-Heigl Hernandez
- Microsoft Excel Array Index Error Remote Code Execution
- [ MDKSA-2006:117-1 ] - Updated libmms packages fix buffer overflow vulnerability
- NSFOCUS SA2006-04 : Microsoft Office GIF Filter Buffer Overflow Vulnerability
- From: NSFOCUS Security Team
- [SECURITY] [DSA 1108-1] New mutt packages fix arbitrary code execution
- TOPo v.2.2.178 Account Reset
- S21Sec-032-en: Vulnerability in Fatwire Content Server
- Re: Browser bugs hit IE, Firefox today (SANS)
- RE: Old vulnerable sotwares collection
- Lazarus Guestbook Cross Site Scripting Vulnerabilities
- [ MDKSA-2006:120 ] - Updated samba packages fix DoS vulnerability
- NSFOCUS SA2006-06 : Microsoft Excel COLINFO Record Buffer Overflow Vulnerability
- From: NSFOCUS Security Team
- New CVE number states Excel Style handling as a separate issue
- Re: WordPress 2.0.3 SQL Error and Full Path Disclosure
- Re: # MHG Security Team --- PHPAskIt v2.0.1 Remote File Inc.
- NSFOCUS SA2006-05 : Microsoft Excel SELECTION Record Memory Corruption Vulnerability
- From: NSFOCUS Security Team
- FLV Players Multiple Input Validation Vulnerabilities
- [ MDKSA-2006:121 ] - Updated xine-lib packages fix buffer overflow vulnerability
- Re: # MHG Security Team --- PHPAskIt v2.0.1 Remote File Inc.
- [ECHO_ADV_38$2006] Multiple Mambo/Joomla Component Remote File Include Vulnerabilities
- RE: WordPress 2.0.3 SQL Error and Full Path Disclosure
- SYMSA-2006-004 (Full Details): Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution
- [USN-317-1] zope2.8 vulnerability
- Photocycle v1.0 - XSS
- ScozNews Final-Php <=1.1 Remote File Inclusion Vulnerability
- Orbitmatrix PHP Script v1.0
- Flipper Poll <= 1.1.0 Remote File Inclusion Vulnerability
- [USN-318-1] libtunepimp vulnerability
- [ MDKSA-2006:122 ] - Updated php packages fix multiple vulnerabilities
- flatnuke <= 2.5.7 arbitrary php file upload
- PHORUM 5 arbitrary local inclusion
- phpbb 3.x sql injection (with global moderator rights)
- [ MDKSA-2006:123 ] - Updated kernel packages fixes multiple vulnerabilities
- Re: [ECHO_ADV_38$2006] Multiple Mambo/Joomla Component Remote File Include Vulnerabilities
- perForms <= 1.0 ([mosConfig_absolute_path]) Remote File Inclusion
- [security bulletin] HPSBUX02120 SSRT051057 rev.2 - HP-UX Local Denial of Service (DoS)
- rPSA-2006-0122-2 kernel
- Re: WebEx Downloader Plug-in Multiple Vulnerabilities + rant
- IE <= 6 DoS vulnerability
- Phorum 5.1.15 security release (fixes "PHORUM 5 arbitrary local inclusion")
- Microsoft Works - Buffer Overflows / Denial of Service (DoS)-Vulnerabilities
- From: Benjamin Tobias Franz
- Linux Kernel 2.6.x PRCTL Core Dump Handling -- Simple workaround
- From: Caveo Internet BV - Security
- EEYE: McAfee ePolicy Orchestrator Remote Compromise
- Re: Photocycle v1.0 - XSS
- Re: Linux Kernel 2.6.x PRCTL Core Dump Handling -- Simple workaround
- Bybass HTTP ( extension files ) in ISA 2004
- MS Power Point Multiple Vulnerabilities (powerpnt.exe)- POC
- MS Power Point Multiple Vulnerabilities - (mso.dll) POC
- MS Power Point Multiple Vulnerabilities - (memory corruption) POC
- Norton Insufficient protection of Norton service registry keys
- Kerio Terminating 'kpf4ss.exe' using internal runtime error Vulnerability
- Re: Securing PHP or finding PHP alternatives
- Re: Securing PHP or finding PHP alternatives
- Linux sys_prctl LKM based hotfix
- crashing firefox <= 1.5.0.4
- saphp "add.php" forumid Parameter SQL Injection
- RE: Re: vBulletin 3.5.4 (install_path) Exploit
- XSS phpBB 2.0.21 in administration
- MyGallery "Room.php" SQL Injection
- Rocks Clusters <=4.1 local root
- Re: WordPress 2.0.3 SQL Error and Full Path Disclosure
- [SECURITY] Plain text password in Finjan Appliance 5100/8100 NG backup file
- From: finde_schwachstelle
- Re: Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit
- Phorum 5.1.14 XSS SQL injection Vulnerability
- Re: WordPress 2.0.3 SQL Error and Full Path Disclosure
- MiniBB Forum <= 1.5a Remote File Include Vulnerabilities
- VBZooM "sendmail.php" SQL Injection
- Re: [Full-disclosure] ERNW Security Advisory 02/2006 - Buffer Overflow in sipXtapi (used in AOL Triton)
- Re: LAMP vs Microsoft
- SubberZ[Lite] - Remote File Include
- From: ChironeX . FleckeriX
- RE: MIMESweeper For Web 5.X Cross Site Scripting
- VBZooM <=V1.11 " reply.php" SQL Injection
- VBZooM <=V1.11 " ignore-pm.php" SQL Injection
- Microsoft PowerPoint 0-day Vulnerability FAQ document written
- Re: [ GLSA 200607-05 ] SHOUTcast server: Multiple vulnerabilities
- Re: Securing PHP or finding PHP alternatives
- Re: phpbb 3.x sql injection (with global moderator rights)
- Crtical Shockwave Embeded XSS Execution
- Re: Securing PHP or finding PHP alternatives (was: PHP security (or the lack thereof))
- From: Matthias Kestenholz
- VBZooM <=V1.11 "sub-join.php" SQL Injection
- [OpenPKG-SA-2006.013] OpenPKG Security Advisory (mutt)
- Re: LAMP vs Microsoft
- Fantastic Guestbook v2.0.1 Advisory
- Re: LAMP vs Microsoft
- Re: Buddy Zone Version 1.0.1 - XSS
- Re: LAMP vs Microsoft
- Re: LAMP vs Microsoft
- Re: Linux Kernel 2.6.x PRCTL Core Dump Handling -- Simple workaround
- Invision Power Board 2.1 <= 2.1.6 sql injection
- Re: Securing PHP or finding PHP alternatives (was: PHP security (or the lack thereof))
- From: Meet Myself on the Internet
- Re: Linux Kernel 2.6.x PRCTL Core Dump Handling -- Simple workaround
- Re: [Full-disclosure] Re: Linux Kernel 2.6.x PRCTL Core Dump Handling - Local r00t Exploit ( BID 18874 / CVE-2006-2451 )
- Gracenote buffer overflow
- MyBulletinBoard (MyBB) 1.1.5 'CLIENT-IP' sql injection
- Mercury Messenger
- Re: Bybass HTTP ( extension files ) in ISA 2004
- From: Thor (Hammer of God)
- Several updates in MS PowerPoint 0-day Vulnerability FAQ at SecuriTeam Blogs
- PHP Event Calendar versi 1.4 (path_to_calendar) Remote File Inclusion
- Calendar Module <= 1.5.7 Remote File Include Vulnerabilities
- Plesk Control Panel <= 8.0.0 XSS vulnerability
- Re: Phorum 5.1.14 XSS SQL injection Vulnerability
- Secunia Research: IceWarp Web Mail Two File Inclusion Vulnerabilities
- [SECURITY] [DSA 1109-1] New rssh packages fix privilege escalation
- RE: Bybass HTTP ( extension files ) in ISA 2004
- rPSA-2006-0130-1 kernel
- [EEYEB-20060227] D-Link Router UPNP Stack Overflow
- Secunia Research: VisNetic Mail Server Two File Inclusion Vulnerabilities
- [SECURITY] [DSA 1110-1] New samba packages fix denial of service
- Secunia Research: BitZipper unacev2.dll Buffer Overflow Vulnerability
- PacSec 2006 CALL FOR PAPERS (Deadline Aug. 4; Event Nov. 27-30)
- boastMachine <= 3.1 SQL Injection Exploit
- ListMessenger v0.9.3 Remote File Inclusion Vulnerability
- Multiple vulnerabilities in UFO2000 svn 1057
- [SECURITY] [DSA 1111-1] New Linux kernel 2.6.8 packages fix privilege escalation
- About the latest three Powerpoint vulnerabilities: exploitable?
- [SECURITY] [DSA 1112-1] New mysql-dfsg-4.1 packages fix denial of service
- Re: Invision Power Board 2.1 <= 2.1.6 sql injection
- ToorCon 2006 Call for Papers
- RUXCON 2006 Final Call For Papers
- Re: Securing PHP or finding PHP alternatives
- [USN-319-1] Linux kernel vulnerability
- Re: Linux Kernel 2.6.x PRCTL Core Dump Handling -- Simple workaround
- Re: LAMP vs Microsoft
- Re: LAMP vs Microsoft
- Unauthenticated access to BT Voyager config file and PPP credentials embedded in HTML form
- New Article Mambo Component <= 1.0 (com_articles.php) Remote File Include Vulnerabilities
- 23rd Chaos Communication Congress 2006: Call for Participation
- Calendar Mambo Module <= 1.5.7 Remote File Include Vulnerabilities
- Re: Invision Power Board 2.1 <= 2.1.6 sql injection
- Re: WebEx Downloader Plug-in Multiple Vulnerabilities + rant
- Cross Site Scripting Vulnerability in Zoho Virtual Office
- Professional PHP Tools Guestbook Multiple Vulnerabilities
- [ MDKSA-2006:124 ] - Updated kernel packages fix privilege escalation vulnerability
- ToendaCMS <= 1.0.0 arbitrary file upload
- Keyif Portal v2.0 - Microsoft Access Driver ( MDB ) Download
- Outpost Firewall Pro secrately fixing security flaws?
- Re: Invision Power Board 2.1 <= 2.1.6 sql injection
- DeluxeBB mutiple vulnerabilities
- [KAPDA::#52] - PHP-Post 1.0 Cookie Modification Privilege Escalation Vulnerability
- $100 plus several of my books if you can crack my Windows password hashes.
- Oracle Database - SQL Injection in SYS.KUPW$WORKER [DB03]
- Oracle Database - SQL Injection in SYS.DBMS_CDC_IMPDP [DB01]
- WebScarab <= 20060621-0003 cross site scripting
- [SECURITY] [DSA 1113-1] New zope2.7 packages fix information disclosure
- RE: [lists] Re: PHP security (or the lack thereof)
- Re: Bybass HTTP ( extension files ) in ISA 2004
- PcAnywhere > 12 Local Privilege Escalation
- Re: Bybass HTTP ( extension files ) in ISA 2004
- Consumers of Broadband Providers (ISP) may be open to hijack attacks
- ExtCalendar Mambo Module <= v2( extcalendar.php ) Remote File Include Vulnerabilities
- Invision Power Board v2.1 <= 2.1.6 sql injection exploit
- Oracle Database - SQL Injection in SYS.DBMS_STATS [DB21]
- [security bulletin] HPSBTU02132 SSRT061154 rev.1 - HP Tru64 UNIX running NIS ypserv, Remote Denial of Service (DoS)
- Oracle Database - SQL Injection in SYS.DBMS_UPGRADE [DB22]
- hdweGUEST <= 2.1.1 Cross Site Scripting Vulnerabilities
- ASP.DLL Include File Buffer Overflow
- Escalation of privileges in Outpost and Lavasoft Firewalls -Unusual ShellExecute behavior
- Re: Re: Invision Power Board 2.1 <= 2.1.6 sql injection
- Re: LAMP vs Microsoft
- Re: XSS phpBB 2.0.21 in administration
- Re: LAMP vs Microsoft
- Re: Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit
- osDate 1.1.7 multiple vulnerabilities
- Webmin / Usermin Arbitrary File Disclosure Vulnerability Perl
- Re: crashing firefox <= 1.5.0.4
- New PowerPoint Trojan installs itself as LSP
- [USN-320-1] PHP vulnerabilities
- [ MDKSA-2006:125 ] - Updated webmin packages fix arbitray file read vulnerability.
- [ MDKSA-2006:127 ] - Updated gimp packages fix buffer overflow vulnerability.
- [ MDKSA-2006:126 ] - Updated libtunepimp packages fixes buffer overflow vulnerabilities.
- [ MDKSA-2006:128 ] - Updated wireshark packages fix numerous vulnerabilities
- Re: Bybass HTTP ( extension files ) in ISA 2004
- From: Thor (Hammer of God)
- rPSA-2006-0132-1 tshark wireshark
- Cisco Security Advisory: Multiple Vulnerabilities in Cisco Security Monitoring, Analysis and Response System (CS-MARS)
- From: Cisco Systems Product Security Incident Response Team
- VMSA-2006-0003 VMware possible incorrect permissions on SSL key files
- From: VMware Security Team
- [ GLSA 200607-06 ] libpng: Buffer overflow
- [USN-319-2] Linux kernel vulnerability
- [USN-313-2] OpenOffice.org vulnerabilities
- Re: imageVue16.1 upload vulnerability
- AFCommerce Shopping Cart
- Security point-of-contact for Ameritrade?
- Re: osDate 1.1.7 multiple vulnerabilities
- rPSA-2006-0133-1 libpng
- Cisco MARS < 4.2.1 remote compromise
- [ECHO_ADV_40$2006] iManage CMS <= 4.0.12 (absolute_path) Remote File Inclusion
- Advisory: Remote command execution in planetGallery
- [MajorSecurity #20]SiteDepth CMS <= 3.01 - Remote File Include Vulnerability
- [MajorSecurity #21] phpFaber TopSites <=2.0.9 - SQL Injection Vulnerability
- [MajorSecurity #22] Top XL <=1.1 - XSS and cookie disclosure
- [ MDKSA-2006:129 ] - Updated freetype2 packages fixes overflow vulnerability.
- [security bulletin] HPSBUX02108 SSRT061133 rev.12 - HP-UX Running Sendmail, Remote Execution of Arbitrary Code
- rPSA-2006-0134-1 sendmail sendmail-cf
- [USN-321-1] mysql-dfsg-4.1 vulnerability
- [SECURITY] [DSA 1117-1] New libgd2 packages fix denial of service
- [security bulletin] HPSBMA02133 SSRT061201 rev.1 - HP Oracle for OpenView (OfO) Critical Patch Update July 2006
- SECURITY UPDATE::Farsinews release FarsiNewsPro3.0Stable1SecurityPath1
- [ GLSA 200607-07 ] xine-lib: Buffer overflow
- [SECURITY] [DSA 1115-1] New GnuPG2 packages fix denial of service
- LoudBlog <=0.5 Sql injection
- TSLSA-2006-0042 - multi
- From: Trustix Security Advisor
- Unidomedia Chameleon LE/Pro Directory Traversal
- Samba Internal Data Structures DOS Vulnerability Exploit
- [ MDKSA-2006:130 ] - Updated kdelibs packages fix konqueror crash vulnerability.
- [SECURITY] [DSA 1114-1] New hashcash packages fix arbitrary code execution
- SolpotCrew Advisory #2 - Advanced Poll ver 2.02 (base_path) Remote File Inclusion
- [SECURITY] [DSA 1116-1] New gimp packages fix arbitrary code execution
- Re: Samba Internal Data Structures DOS Vulnerability Exploit
- From: Gerald (Jerry) Carter
- Re: Securing PHP or finding PHP alternatives
- MiniBB Forum <= 1.5a Remote File Include (search.php-whosOnline.php)
- iDefense Security Advisory 07.20.06: Sun Microsystems Solaris sysinfo() Kernel Memory Disclosure Vulnerability
- [Kurdish Security # 13] Savant2 Remote File Include Vulnerability [For Mambo, Joomla]
- Re: [EEYEB-20060227] D-Link Router UPNP Stack Overflow
- RE: $100 plus several of my books if you can crack my Windows password hashes.
- Re: LAMP vs Microsoft
- Re: ATutor 1.5.3 Cross Site Scripting
- Re: Securing PHP or finding PHP alternatives
- RE: XSS phpBB 2.0.21 in administration
- Re: [Full-disclosure] iDefense Security Advisory 07.20.06: Sun Microsystems Solaris sysinfo() Kernel Memory Disclosure Vulnerability
- Microsoft Internet Explorer DOS Vulnerability
- MicroGuestBook Remote XSS Attack
- [MajorSecurity #25] Advanced Guestbook 2.4 for phpBB - Multiple XSS and SQL-Injection Vulnerabilities
- RE: [EEYEB-20060227] D-Link Router UPNP Stack Overflow
- [MajorSecurity #24] Fire-Mouse TopList <=v1.1 - Cross Site Scripting
- Low security hole affecting IPCalc's CGI wrapper
- [SECURITY] [DSA 1118-1] New Mozilla packages fix several vulnerabilities
- about bid 17404
- [SECURITY] [DSA 1119-1] New hiki packages fix denial of service
- Re: XSS phpBB 2.0.21 in administration
- Re: SubberZ[Lite] - Remote File Include
- RE: $100 plus several of my books if you can crack my Windows password hashes.
- New CVE identifiers for separate PowerPoint 0-day issues assigned
- RE: $100 plus several of my books if you can crack my Windows password hashes.
- Re: [EEYEB-20060227] D-Link Router UPNP Stack Overflow
- new shell bypass safe mode
- SolpotCrew Advisory #3 - com_trade Remote File Inclusion (mosConfig_absolute_path)
- Re: XSS phpBB 2.0.21 in administration
- Re: AFCommerce Shopping Cart
- Re: ExtCalendar Mambo Module <= v2( extcalendar.php ) Remote File Include Vulnerabilities
- Re: New PowerPoint Trojan installs itself as LSP
- MiniBB Forum <= 1.5a Remote File Include (news.php)
- [MajorSecurity #23] BLOG:CMS <= 4.0.0j - XSS and cookie disclosure
- Com Multibanners Remote File Inclusion (mosConfig_absolute_path)
- Blackboard Academic Suite 6.2.23 +/-: Persistent cross-site scripting vulnerability
- Re: [MajorSecurity #22] Top XL <=1.1 - XSS and cookie disclosure
- Re: [Full-disclosure] Re: New PowerPoint Trojan installs itself as LSP
- Re: Digital Armaments Security Advisory 10.07.2006: Flexwath Authorization Bypassing and XSS Vulnerability
- Map MS Security Bulletins to MS KB numbers
- DotClear : Multiples Full Path Disclosure
- [SECURITY] [DSA 1120-1] New Mozilla Firefox packages fix several vulnerabilities
- [Kurdish Security # 14] MoSpray [base_dir] Remote Command Execution [ Mambo & Joomla]
- Vanilla CMS <= 1.0.1 (RootDirectory) Remote file inclusion Vuln.
- [ GLSA 200607-08 ] GIMP: Buffer overflow
- From: Sune Kloppenborg Jeppesen
- [CYBSEC] TippingPoint detection bypass
- Buffer-overflow in the XM loader of Cheese Tracker 0.9.9
- [SECURITY] [DSA 1121-1] New postgrey packages fix denial of service
- PHP Live! v3.2 (header.php) Remote File Include Vulnerabilities
- Re: Re: [Full-disclosure] iDefense Security Advisory 07.20.06: Sun Microsystems Solaris sysinfo() Kernel Memory Disclosure Vulnerability
- Re: [ GLSA 200607-08 ] GIMP: Buffer overflow
- Check Point R55W Directory Traversal
- [USN-322-1] Konqueror vulnerability
- MusicBox <= 2.3.4 XSS SQL injection Vulnerability
- [SECURITY] [DSA 1124-1] New fbi packages fix potential deletion of user data
- Windows XP/NT/SMB2003/2000 Denial of Service attack
- ERRATA: [ GLSA 200607-08 ] GIMP: Buffer overflow
- From: Sune Kloppenborg Jeppesen
- Write-up by Amit Klein: "Forging HTTP request headers with Flash"
- From: Amit Klein (AKsecurity)
- [MajorSecurity #26] Woltlab Burning Board - Multiple Cookie manipulation and session fixation vulnerabilities
- SQuery v.x (devi.php) (armygame.php) Remote File Inclusion
- [SECURITY] [DSA 1123-1] New libdumb packages fix arbitrary code execution
- Heap overflow in the GT2 loader of libmikmod 3.2.2
- rPSA-2006-0135-1 gimp
- Digital Armaments Security Advisory 24.07.2006: Siemens Speedstream Wireless/Router Denial of Service Vulnerability
- SYMSA-2006-008:Password Safe - Lock Password Database Configuration Not Enforced
- Opsware NAS 6.0 reveals MySQL 'root' password
- Buffer-overflow in recvTextMessage and NETrecvFile in Warzone Resurrection 2.0.3 (SVN 127)
- [SECURITY] [DSA 1122-1] New Net::Server packages fix denial of service
- Two crash vulnerabilities in Freeciv 2.1.0-beta1 (SVN 15 Jul 2006)
- [ GLSA 200607-09 ] Wireshark: Multiple vulnerabilities
- From: Sune Kloppenborg Jeppesen
- [USN-296-2] Firefox vulnerabilities
- Advisory: VMware Possible Incorrect Permissions On SSL Key Files
- [vuln.sg] DynaZip DZIP32.DLL/DZIPS32.DLL Buffer Overflow Vulnerabilities
- [vuln.sg] TurboZIP ZIP Repair Buffer Overflow Vulnerability
- [vuln.sg] AGEphone "sipd.dll" SIP Packet Handling Buffer Overflow
- LinksCaffe 3.0 SQL injection/Command Execution Vulnerabilties
- [ GLSA 200607-10 ] Samba: Denial of Service vulnerability
- From: Sune Kloppenborg Jeppesen
- [security bulletin] HPSBUX02087 SSRT4728 rev.2 - HP-UX running TCP/IP Remote Denial of Service (DoS)
- Re: Ashop Search Module SQL injection
- From: security curmudgeon
- [ MDKSA-2006:131 ] - Updated perl-Net-Server packages fix format string vulnerability
- Full Path Disclosure xGuestBook v1.02
- MS06-034 lies? IIS 6 can still be owned?
- Secunia Research: AutoVue SolidModel Professional Buffer Overflow Vulnerability
- [USN-297-3] Thunderbird vulnerabilities
- [USN-320-2] php4 regression
- EzUpload multi file vulnerabilities
- Multiple vulnerabilities in OpenCMS
- [SECURITY] [DSA 1111-2] New Linux kernel 2.6.8 packages fix privilege escalation
- Re: Write-up by Amit Klein: "Forging HTTP request headers with Flash"
- From: Amit Klein (AKsecurity)
- wwwThreads XSS
- Professional Home Page Tools Login Script Cross Site Scripting Vulnerabilities
- Zyxel Prestige 660H-61 Cross-Site Scripting
- PHP-Auction SQL injection
- TP-Book <= 1.00 Cross Site Scripting Vulnerabilities
- ZDI-06-024: eIQNetworks Enterprise Security Analyzer License Manager Buffer Overflow Vulnerability
- ZDI-06-023: eIQNetworks Enterprise Security Analyzer Syslog Server Buffer Overflow Vulnerability
- TSRT-06-04: eIQnetworks Enterprise Security Analyzer Topology Server Buffer Overflow Vulnerability
- TSRT-06-03: eIQnetworks Enterprise Security Analyzer Syslog Server Buffer Overflow Vulnerabilities
- [SECURITY] [DSA 1125-1] New drupal packages fix execution of arbitrary web script code
- Cisco VPN Concentrator IKE resource exhaustion DoS Advisory
- Etomite CMS <= 0.6.1 'rfiles.php' remote command execution
- [USN-323-1] mozilla vulnerabilities
- [ECHO_ADV_41$2006] BufferOverflow in Midirecord2
- [vuln.sg] PowerArchiver DZIPS32.DLL Buffer Overflow Vulnerability
- [OpenPKG-SA-2006.014] OpenPKG Security Advisory (shiela)
- Secunia Research: FileCOPA Directory Argument Handling Buffer Overflow
- Phpprobid <= 5.24 XSS SQL injection Vulnerability
- Re: new shell bypass safe mode
- Re: Write-up by Amit Klein: "Forging HTTP request headers with Flash"
- NSFOCUS SA2006-07 : ISS RealSecure/BlackICE MailSlot Heap Overflow Detection Remote DoS Vulnerability
- From: NSFOCUS Security Team
- a6mambohelpdesk Mambo Component <= 18RC1 Remote Include Vulnerability
- Re: Write-up by Amit Klein: "Forging HTTP request headers with Flash"
- From: Amit Klein (AKsecurity)
- GeoClassifieds Enterprise <= 2.0.5.2 Cross Site Scripting
- Re: Opsware NAS 6.0 reveals MySQL 'root' password
- [SECURITY] [DSA 1126-1] New Asterisk packages fix denial of service
- Cross-Site Scripting and Local File Inclusion in Phorum
- Buffer Overflow Vulnerability in Winlpd
- Re: Low security hole affecting IPCalc's CGI wrapper
- [USN-324-1] freetype vulnerability
- [USN-325-1] ruby1.8 vulnerability
- [USN-326-1] heartbeat vulnerability
- [SECURITY] [DSA 1125-2] New drupal packages fix execution of arbitrary web script code (revised packages)
- Secunia Research: Mozilla Firefox XPCOM Event Handling Memory Corruption
- Bypassing Oracle dbms_assert
- ZDI-06-025: Mozilla Firefox Javascript navigator Object Vulnerability
- rPSA-2006-0137-1 firefox
- Xss in MttKe-php v2.6
- AIM Triton 1.0.4 (SipXtapi) Remote Buffer Overflow Exploit (PoC)
- Oracle 10g R2 and, probably, all previous versions
- Re: HYSA-2006-008 myBloggie 2.1.3 CRLF & SQL Injection
- [USN-327-1] firefox vulnerabilities
- Cisco Security Advisory: Windows VPN Client Local Privilege Escalation Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- [USN-328-1] Apache vulnerability
- [FLSA-2006:175040] Updated php packages fix security issues
- Re: Bypassing Oracle dbms_assert
- [SECURITY] [DSA 1127-1] New ethereal packages fix several vulnerabilities
- [OpenPKG-SA-2006.015] OpenPKG Security Advisory (apache)
- [SECURITY] [DSA 1128-1] New heartbeat packages fix local denial of service
- Portail PHP v1.7 Remote File Include
- [ MDKSA-2006:132 ] - Updated libwmf packages fixes integer overflow vulnerability
- [OpenPKG-SA-2006.016] OpenPKG Security Advisory (ruby)
- [OpenPKG-SA-2006.017] OpenPKG Security Advisory (freetype)
- Remote Include Vulnerability ====> in Dr.Jr7 Gallery 3.2 RC1
- RE: Bypassing Oracle dbms_assert
- From: Alexander Kornbrust
- Re: Bypassing Oracle dbms_assert
- Oracle 10g R2 and, probably, all previous versions
- [Announcement] Apache HTTP Server 2.2.3 (2.0.59, 1.3.37) Released
- From: William A. Rowe, Jr.
- Apache mod_rewrite Buffer Overflow Vulnerability
- [SECURITY] [DSA 1129-1] New osiris packages fix arbitrary code execution
- PHP-Nuke INP XSS
- Guestbook Mambo Module <== v1.3.0 Multiple Remote File Include Vulnerabilities
- Re: Fusion Polls (xtrphome) Remote File Inclusion
- From: security curmudgeon
- Lan-Aces Office Logic
- Re: Check Point R55W Directory Traversal
- cpanel login problem
- Hustle -- Tumbleweed Email Firewall Remote Vulnerability
- PrinceClan Chess Mambo Com <= 0.8 Remote Inclusion Vulnerability
- rPSA-2006-0139-1 httpd mod_ssl
- [USN-329-1] Thunderbird vulnerabilities
- PHP ip2long() function circumvention
- Coppermine Photo Gallery v1.2.2b-Nuke Remote File Inclusion Vulnerabilities
- XSS vulnerability on AWBS
- RE: TSRT-06-04: eIQnetworks Enterprise Security Analyzer Topology Server Buffer Overflow Vulnerability
- Re: Cisco VPN Concentrator IKE resource exhaustion DoS Advisory
- [KAPDA::#53] MYBB XSS and Dir Traversal in usercp.php
- Mambo Gallery Manager v095.r3 Remote File Inclusion Vulnerabilities
- [ MDKSA-2006:133 ] - Updated apache packages fix mod_rewrite vulnerability
- mambatstaff Mambo Component <= Remote Include Vulnerability
- [ GLSA 200607-12 ] OpenOffice.org: Multiple vulnerabilities
- artlinks Mambo Component <= Remote Include Vulnerability
- [ MDKSA-2006:134 ] - Updated ruby packages fix safe-level vulnerabilities
- Gdiplus.dll division by 0
- Re: cpanel login problem
- [ GLSA 200607-13 ] Audacious: Multiple heap and buffer overflows
- [ GLSA 200607-11 ] TunePimp: Buffer overflow
Mail converted by MHonArc