Mail Index
- UPDATE: [ GLSA 200605-08 ] PHP: Multiple vulnerabilities
- From: Sune Kloppenborg Jeppesen
- Re: cpanel login problem
- RE: cpanel login problem
- Re: Portail PHP v1.7 Remote File Include
- Re: PHP ip2long() function circumvention
- Re: cpanel login problem
- com_moskool (admin.moskool.php) Remote File Include Vulnerabilities
- ATutor <= 1.5.3.1 'links' blind SQL injection / admin credentials disclosure
- PHPAuction 2.1 (maybe higher) with phpAdsNew 2.0.5 RFI
- From: philipp . niedziela
- SQL injection Seir Anphin v666 Community Management System
- Re: Cisco VPN Concentrator IKE resource exhaustion DoS Advisory
- Re: Gdiplus.dll division by 0
- Re: Check Point R55W Directory Traversal
- Oracle and Apache mod_rewrite Vulnerability
- Corsaire Security Advisory - VMware ESX Server Password Cross Site Request Forgery issue
- Corsaire Security Advisory - VMware ESX Server Password Disclosure in Log issue
- Corsaire Security Advisory - VMware ESX Server Password Disclosure in Cookie issue
- Re: [EEYEB-20060227] D-Link Router UPNP Stack Overflow
- Multiple vulnerabilities in Open Cubic Player 2.6.0pre6 / 0.1.10_rc5
- RE: cpanel login problem
- MyNewsGroups <= 0.6b (myng_root) Remote Inclusion Vulnerability
- From: philipp . niedziela
- Re: Do world's famous companies take care of their security?
- Re: Xss in MttKe-php v2.6
- [ GLSA 200608-01 ] Apache: Off-by-one flaw in mod_rewrite
- NewsLetter v3.5 <= (NL_PATH) Remote File Inclusion Exploit
- [Kurdish Security # 16 ] newsReporter v1.0 Remote Command Execution
- [Kurdish Security # 17 ] GuestBook 3.5 Remote Command Execution
- [Kurdish Security # 18 ] FAQ Script Remote Command Execution
- [Kurdish Security # 19 ] FileManager Remote Command Execution
- [Kurdish Security # 20 ] Quickie Remote Command Execution
- [Kurdish Security # 21] ShoutBox v4.4 Remote Command Execution
- [SECURITY] [DSA 1130-1] New sitebar packages fix cross-site scripting
- WoW Roster <= 1.5.x Remote File Include (hsList.php)
- Re: Gdiplus.dll division by 0
- [vuln.sg] Lhaplus LHA Extended Header Handling Buffer Overflow Vulnerability
- [ MDKSA-2006:135 ] - Updated freeciv packages fix DoS vulnerabilities
- VMSA-2006-0004 Cross site scripting vulnerability and other fixes
- From: VMware Security Team
- [USN-327-2] firefox regression
- TSEP 0.9.4.2 <= Remote File Inclusion
- From: philipp . niedziela
- ISS BlackICE PC Protection DLL faking of run-time linked libraries Vulnerability
- WoW Roster <= 1.5.x Remote File Include (hsList.php)
- [SECURITY] [DSA 1132-1] New apache2 packages fix buffer overflow
- [SECURITY] [DSA 1131-1] New apache package fix buffer overflow
- SUSE Security Announcement: freetype2 (SUSE-SA:2006:045)
- SUSE Security Announcement: libtiff (SUSE-SA:2006:044)
- [ MDKSA-2006:136 ] - Updated kdegraphics packages fix multiple libtiff vulnerabilities
- SYM06-013 Symantec On-Demand Protection Encrypted Data Exposure
- Barracuda Vulnerability: Hardcoded Password [NNL-20060801-01]
- Barracuda Vulnerability: Arbitrary File Disclosure [NNL-20060801-02]
- DMA[2006-0801a] - 'Apple OSX fetchmail buffer overflow'
- Re: Gdiplus.dll division by 0
- [ MDKSA-2006:137 ] - Updated libtiff packages fix multiple vulnerabilities
- [SECURITY] [DSA 1133-1] New mantis packages fix execution of arbitrary web script code
- JavaScript port scanning
- rPSA-2006-0142-1 libtiff
- EEYE: research.eeye.com
- [SECURITY] [DSA 1134-1] New Mozilla Thunderbird packages fix several vulnerabilities
- Secunia Research: Jetbox Multiple Vulnerabilities
- Re: Cisco VPN Concentrator IKE resource exhaustion DoS Advisory
- Re: SYM06-013 Symantec On-Demand Protection Encrypted Data Exposure
- SaveWeb Portal 3.4 <- (SITE_Path) Remote File Inclusion Vulnerability
- Content Management Framework "G3" - XSS Vulnerability in Search Function
- rPSA-2006-0143-1 gnupg
- [USN-330-1] tiff vulnerabilities
- [eVuln] MyBB 'Avatar URL' XSS Vulnerability
- Re: Barracuda Vulnerability: Hardcoded Password [NNL-20060801-01]
- [security bulletin] HPSBUX02108 SSRT061133 rev.13 - HP-UX Running Sendmail, Remote Execution of Arbitrary Code
- [SECURITY] [DSA 1136-1] New gpdf packages fix denial of service
- [security bulletin] HPSBUX02124 SSRT061159 rev.1 - HP-UX Sendmail MIME Remote Denial of Service (DoS)
- OZJournal v1.5 - XSS
- [SECURITY] [DSA 1137-1] New tiff packages fix several vulnerabilities
- [security bulletin] HPSBGN02136 SSRT061173 rev.1 - ProCurve Series 3500yl, 6200yl, and 5400zl Switches Running Software Prior to K.11.33 Remote Denial of Service (DoS)
- Hobbit monitor security bugfix release - 4.1.2p2
- [SECURITY] [DSA 1138-1] New cfs packages fix denial of service
- [SECURITY] [DSA 1135-1] New libtunepimp packages fix arbitrary code execution
- [security bulletin] HPSBUX02087 SSRT4728 rev.3 - HP-UX running TCP/IP Remote Denial of Service (DoS)
- Simpliciti Locked Browser Jail Breakout Vulnerability
- RE: Barracuda Vulnerability: Hardcoded Password [NNL-20060801-01]
- TSEP <= 0.942 Remote File Include
- Vwar v1.5.0 <= Sql Injection and XSS vuln.
- Secunia Research: PC Tools AntiVirus Insecure Default Directory Permissions
- CMSimple Cross Site Scripting
- [USN-331-1] Linux kernel vulnerabilities
- [USN-332-1] gnupg vulnerability
- Re: [Announcement] Apache HTTP Server 2.2.3 (2.0.59, 1.3.37) Released
- [SECURITY] [DSA 1139-1] New ruby1.6 packages fix privilege escalation
- Re: [Announcement] Apache HTTP Server 2.2.3 (2.0.59, 1.3.37) Released
- From: William A. Rowe, Jr.
- Javascript software authentication brute force attack
- [MajorSecurity Advisory #27]ToendaCMS - Cross Site Scripting Issue
- SendCard <= 3.4.0 unauthorized administrative access / remote commands execution
- [SECURITY] [DSA 1140-1] New GnuPG packages fix denial of service
- [ GLSA 200608-02 ] Mozilla SeaMonkey: Multiple vulnerabilities
- SolpotCrew Advisory #5 - modernbill ver 1.6 (DIR) Remote File Inclusion
- [DRUPAL-SA-2006-011] Drupal 4.7.3 / 4.6.9 fixes XSS issue
- Re: Barracuda Vulnerability: Arbitrary File Disclosure [NNL-20060801-02]
- [ GLSA 200608-03 ] Mozilla Firefox: Multiple vulnerabilities
- vbulletin 3.5.4 IE exploit xss
- ME Download System 1.3 Remote File Inclusion
- From: philipp . niedziela
- [ GLSA 200608-04 ] Mozilla Thunderbird: Multiple vulnerabilities
- ZoneX 1.0.3 - Publishers Gold Edition Remote File Inclusion Vulnerability
- [security bulletin] HPSBUX02137 SSRT051024 rev.1 - HP-UX Running Xserver Local Execution of Arbitrary Code, Privilege Elevation
- GaesteChaos <= 0.2 Multiple Vulnerabilities
- CounterChaos <= 0.48c SQL Injection Vulnerability
- GeheimChaos <= 0.5 Multiple SQL Injection Vulnerabilities
- XSS in Vbulletin 3.6.0 in IE 0nly
- [SECURITY] [DSA 1141-1] New GnuPG2 packages fix denial of service
- [ GLSA 200608-05 ] LibVNCServer: Authentication bypass
- From: Sune Kloppenborg Jeppesen
- [ GLSA 200608-06 ] Courier MTA: Denial of Service vulnerability
- From: Sune Kloppenborg Jeppesen
- [ECHO_ADV_42$2006] BufferOverflow in Eremove Client
- [SECURITY] [DSA 1142-1] New freeciv packages fix arbitrary code execution
- [ECHO_ADV_42$2006] PHP Live Helper <= 2.0 (abs_path) Remote File Inclusion
- [SECURITY] [DSA 1143-1] New dhcp packages fix denial of service
- TSLSA-2006-0044 - multi
- From: Trustix Security Advisor
- CAID 34509 - CA eTrust Antivirus WebScan vulnerabilities
- phpAutoMembersArea 3.2.5 ($installed_config_file) Remote File Inclusion
- From: philipp . niedziela
- Barracuda Spam Firewall: Administrator Level Remote Command Execution [ID-20060804-01]
- [ GLSA 200608-07 ] libTIFF: Multiple vulnerabilities
- From: Sune Kloppenborg Jeppesen
- vBulletin 3.0.14 ~ init.php~ registerring global arbitary variable~ XSS exploit
- Tinyportal Shoutbox
- [ GLSA 200608-08 ] GnuPG: Integer overflow vulnerability
- From: Sune Kloppenborg Jeppesen
- MyBloggie <= 2.1.4 trackback.php SQL injection / admin credentials disclosure
- XSS Vulnerability in FTD v3.7.3
- Re: flatnuke <= 2.5.7 arbitrary php file upload
- [ECHO_ADV_44$2006] PHP Simple Shop <= 2.0 (abs_path) Remote File Inclusion
- XennoBB <= 2.1.0 "birthday" SQL injection
- SAPID CMS remote File Inclusion vulnerabilities
- 0-day XP SP2 wmf exploit
- SolpotCrew Advisory #6 - phpCC - Beta 4.2 (base_dir) Remote File Inclusion
- 0-day XP SP2 wmf exploit (some details)
- NEWSolved Lite v1.9.2 (abs_path) Remote File Inclusion
- From: philipp . niedziela
- when will AV vendors fix this???
- blur6ex 0.3 Comment title HTML inyection vuln.
- From: piiiiiii pppiiiiiiii
- PHP: Zend_Hash_Del_Key_Or_Index Vulnerability
- IMENDIO PLANNER REMOTE FILENAME FORMAT STRING VULNERABILITY
- Multiple vulnerabilities in DConnect Daemon 0.7.0 (CVS 30 Jul 2006)
- php local buffer underflow could lead to arbitary code execution
- [ GLSA 200608-10 ] pike: SQL injection vulnerability
- From: Sune Kloppenborg Jeppesen
- Re: when will AV vendors fix this???
- [ GLSA 200608-11 ] Webmin, Usermin: File Disclosure
- From: Sune Kloppenborg Jeppesen
- Virtual War v1.5.0 Remote File Include (vwar_root)
- [vuln.sg] Lhaz LHA Long Filename Buffer Overflow Vulnerability
- Will Microsoft patch remarkable old Msjet40.dll issue?
- Re: Vanilla CMS <= 1.0.1 (RootDirectory) Remote file inclusion Vuln.
- [SECURITY] [DSA 1144-1] New chmlib packages fix denial of service
- linksys WRT54g authentication bypass
- [ GLSA 200608-12 ] x11vnc: Authentication bypass in included LibVNCServer code
- From: Sune Kloppenborg Jeppesen
- DeluxeBB Multiple Vulnerabilities
- RE: linksys WRT54g authentication bypass
- simplog 0.9.3 and prior XSS
- From: piiiiiii pppiiiiiiii
- Visual Events Calendar v1.1 (cfg_dir) Remote Inclusion Vulnerability
- TSRT-06-06: Computer Associates eTrust AntiVirus WebScan Manifest Processing Buffer Overflow Vulnerability
- TSRT-06-05: Computer Associates eTrust AntiVirus WebScan Automatic Update Code Execution Vulnerability
- Re: [Announcement] Apache HTTP Server 2.2.3 (2.0.59, 1.3.37) Released
- Re: SolpotCrew Advisory #5 - modernbill ver 1.6 (DIR) Remote File Inclusion
- From: Mailinglists Address
- ARES 2007: Call for workshop proposals, deadline Sept 10, 2006
- Attacking the local LAN via XSS
- Re: [Full-disclosure] Attacking the local LAN via XSS
- Re: [Full-disclosure] Attacking the local LAN via XSS
- Re: [Full-disclosure] Attacking the local LAN via XSS
- Re: Re[2]: [Full-disclosure] Attacking the local LAN via XSS
- Re[2]: [Full-disclosure] Attacking the local LAN via XSS
- Re: vbulletin 3.5.4 IE exploit xss
- AUTODAFE: an Act of Software Torture [FUZZER]
- phpPrintAnalyzer <= 1.1 (rep_par_rapport_racine) Remote File Inclusion Vulnerability
- [EEYEB-20060719] McAfee Subscription Manager Stack Buffer Overflow
- Announcement: Feed Injection in Web 2.0: Hacking RSS and Atom Feed Implementations [Whitepaper]
- [ GLSA 200608-13 ] ClamAV: Heap buffer overflow
- ZDI-06-026: Microsoft Internet Explorer Multiple CSS Imports Memory Corruption Vulnerability
- ZDI-06-027: Microsoft Internet Explorer CSS Class Ordering Memory Corruption Vulnerability
- [SECURITY] [DSA 1145-1] New freeradius packages fix several vulnerabilities
- Archangel Weblog 0.90.02 and prior Multiple HTML injections
- From: piiiiiii pppiiiiiiii
- docpile:we v0.2.2 (INIT_PATH) Remote File Inclusion Vulnerability
- rPSA-2006-0147-1 mysql mysql-bench mysql-server
- phNNTP <= 1.3 (article-raw.php) Remote File Include Vulnerability
- Microsoft PowerPoint Malformed Record Memory Corruption
- [ GLSA 200608-14 ] DUMB: Heap buffer overflow
- From: Sune Kloppenborg Jeppesen
- TSRT-06-07: eIQnetworks Enterprise Security Analyzer Monitoring Agent Buffer Overflow Vulnerabilities
- unwrapping PL/SQL
- MojoScripts' xss vulnerable
- MITKRB-SA-2006-001: multiple local privilege escalation vulnerabilities
- Re: Will Microsoft patch remarkable old Msjet40.dll issue?
- AW: Virtual War v1.5.0 Remote File Include (vwar_root)
- ERRATA: [ GLSA 200608-08 ] GnuPG: Integer overflow vulnerability
- From: Sune Kloppenborg Jeppesen
- rPSA-2006-0150-1 krb5 krb5-server krb5-services krb5-test krb5-workstation
- [Overflow.pl] Clam AntiVirus Win32-UPX Heap Overflow
- SUSE Security Announcement: clamav (SUSE-SA:2006:046)
- PgMarket 2.2.3 (CFG[libdir]) Remote File Inclusion Vulnerabilities
- [USN-333-1] libwmf vulnerability
- Latinchat Denial Of Service
- Assessment of Vista Kernel Mode Security
- [SECURITY] [DSA 1146-1] New krb5 packages fix privilege escalation
- [ MDKSA-2006:138 ] - Updated clamav packages fix vulnerability
- CivicSpace Version 0.8.5 HTML injection
- BlogHoster v2.2 Post Comment Html Injection
- From: piiiiiii pppiiiiiiii
- [ MDKSA-2006:139 ] - Updated krb5 packages fix local privilege escalation vulnerability
- Cwfm <= 0.9.1 (Language) Remote File Inclusion Vulnerability
- From: philipp . niedziela
- [ISR] - Novell Groupwise Webaccess (Cross-Site Scripting)
- TSRT-06-10: Microsoft HLINK.DLL Hyperlink Object Library Buffer Overflow Vulnerability
- Multiple buffer-overflows in AlsaPlayer 0.99.76
- TSRT-06-09: Microsoft DirectAnimation COM Object Memory Corruption Vulnerability
- Stack and heap overflows in MODPlug Tracker/OpenMPT 1.17.02.43 and libmodplug 0.8
- TSRT-06-08: Microsoft Internet Help COM Object Memory Corruption Vulnerability
- [SECURITY] [DSA 1148-1] New gallery packages fix several vulnerabilities
- [SECURITY] [DSA 1147-1] New drupal packages fix cross-site scripting
- [ MDKSA-2006:140 ] - Updated ncompress packages fix vulnerability
- XChat <= 2.6.4-1 (win version) Remote Denial of Service Exploit (php)
- PHPMyRing <= 4.2.0 (view_com.php) Remote SQL Injection
- Yabb XSS
- TinyWebGallery v1.5 ( image ) Remote Include Vulnerability
- [SECURITY] [DSA 1149-1] New ncompress packages fix potential code execution
- Sending multipart/form-data requests from Flash (with arbitrary headers)
- From: Amit Klein (AKsecurity)
- Directory Traversal vulnerability in IPCheck Monitor Server
- CYBSEC - Security Pre-Advisory: SAP Internet Graphics Service (IGS) Remote Denial of Service
- From: Mariano Nuñez Di Croce
- CYBSEC - Security Pre-Advisory: SAP Internet Graphics Service (IGS) Remote Buffer Overflow
- From: Mariano Nuñez Di Croce
- PocketPC MMS - Remote Code Injection/Execution Vulnerability and Denial-of-Service
- [ GLSA 200608-15 ] MIT Kerberos 5: Multiple local privilege escalation (test Falco for security@)
- [ GLSA 200608-17 ] libwmf: Buffer overflow vulnerability
- From: Sune Kloppenborg Jeppesen
- [ GLSA 200608-18 ] Net::Server: Format string vulnerability
- From: Sune Kloppenborg Jeppesen
- [ GLSA 200608-16 ] Warzone 2100 Resurrection: Multiple buffer overflows
- From: Sune Kloppenborg Jeppesen
- Re: SYM06-013 Symantec On-Demand Protection Encrypted Data Exposure
- Mambo/Joomla Component Remository v3.25 (mosConfig_absolute_path) Remote File Inclusion Vulnerability
- Netgear FVG318 is vunerable to DOS attack
- Mafia Moblog <= 6 (pathtotemplate) Remote File Inclusion Vulnerability
- InfanView 3.98 (with plugins) - Access violation at processing images ANI files
- myBloggie <= 2.1.3 (mybloggie_root_path) Remote File Inclusion Vulnerability
- Compersus ASP shopping cart <= DataBase Downloading vuln.
- Virtual War v1.5.0 <= Sql Injection vuln.
- XennoBB <= "avatar gallery" Directory Transversal
- CGI Script Source Code Disclosure Vulnerability in Apache for Windows
- Simple one-file GuestBook 1.0
- Dragonfly CMS 9.0.6.1 and prior XSS
- Security Contact
- Re: when will AV vendors fix this???
- From: Marius Huse Jacobsen
- RE: when will AV vendors fix this???
- Re: when will AV vendors fix this???
- RE: [Full-disclosure] RE: when will AV vendors fix this???
- Re: Re: Cisco VPN Concentrator IKE resource exhaustion DoS Advisory
- Re: [Full-disclosure] Attacking the local LAN via XSS
- Re: linksys WRT54g authentication bypass
- Re: linksys WRT54g authentication bypass
- Re: linksys WRT54g authentication bypass
- RE: linksys WRT54g authentication bypass
- RE: linksys WRT54g authentication bypass
- Re: when will AV vendors fix this???
- Bypassing script filters with variable-width encodings
- Re: linksys WRT54g authentication bypass
- XSSing the Lan 3 (web trojans.. not a new idea)
- Re: linksys WRT54g authentication bypass
- Security Vulnerability in Ruby on Rails 1.1.x
- [security bulletin] HPSBUX02108 SSRT061133 rev.14 - HP-UX Running Sendmail, Remote Execution of Arbitrary Code
- [security bulletin] HPSBUX02124 SSRT061159 rev.2 - HP-UX Sendmail MIME Remote Denial of Service (DoS)
- TSLSA-2006-0046 - multi
- From: Trustix Security Advisor
- Re: Re: Cisco VPN Concentrator IKE resource exhaustion DoS Advisory
- miniBloggie <= 1.0 (fname) Remote File Inclusion Vulnerability
- [ GLSA 200608-19 ] WordPress: Privilege escalation
- Startpage <= 1.0 (cfgLanguage) Remote File Inclusion Vulnerability
- rPSA-2006-0152-1 squirrelmail
- WEBInsta Mailing list manager (cabsolute_path) 1.3e RFI
- From: philipp . niedziela
- Re: [ GLSA 200608-12 ] x11vnc: Authentication bypass in included LibVNCServer code
- wheatblog ُSession.php Remote File Inclusion
- UPDATE: [ GLSA 200511-12 ] Scorched 3D: Multiple vulnerabilities
- VWar <= 1.50 R14 (n) Remote SQL Injection
- Nokia Browser Crash
- SquirrelMail 1.4.8 released - fixes variable overwriting attack
- Re: [SM-ANNOUNCE] SquirrelMail 1.4.8 released - fixes variable overwriting attack
- Calendarix <= 0.7 (calpath) Remote File Inclusion Vulnerability
- myEvent <= 1.4 Multiple Remote File Include Vulnerabilities
- Concurrency-related vulnerabilities in browsers - expect problems
- [SECURITY] [DSA 1150-1] New shadow packages fix privilege escalation
- Microsoft Help (WINHLP32.EXE) - Multiple Remote Code Execution and Denial Of Service Vulnerabilities
- From: Benjamin Tobias Franz
- Re: myBloggie <= 2.1.3 (mybloggie_root_path) Remote File Inclusion Vulnerability
- Forum Software ASPPlayground.NET Advanced Edition 2.4.5 Unicode Xss
- (Security Advisory) SYM06-014 Symantec Backup Exec Internal RPC Overflow
- ScatterChat Advisory 2006-01: Cryptanalytic Attack Vulnerability
- From: ScatterChat Advisories
- Re: Microsoft Help (WINHLP32.EXE) - Multiple Remote Code Execution and Denial Of Service Vulnerabilities
- Re: TSRT-06-02: Microsoft SRV.SYS Mailslot Ring0 Memory Corruption Vulnerability
- Informix - Discovery, Attack and Defense
- Informix Long Username Buffer Overflow Vulnerability
- From: NGSSoftware Insight Security Research
- Error logging buffer overflow in Informix
- From: NGSSoftware Insight Security Research
- Re: myEvent <= 1.4 Multiple Remote File Include Vulnerabilities
- Re: Calendarix <= 0.7 (calpath) Remote File Inclusion Vulnerability
- Re: Mafia Moblog <= 6 (pathtotemplate) Remote File Inclusion Vulnerability
- [ECHO_ADV_45$2006] WEBinsta CMS 0.3.1 (templates_dir) Remote File Inclusion Vulnerability
- RE: [Full-disclosure] RE: when will AV vendors fix this???
- From: Dmitry Yu. Bolkhovityanov
- Re: miniBloggie <= 1.0 (fname) Remote File Inclusion Vulnerability
- Google Picasa Listening on Port 80?
- SQLIDEBUG envariable overflow on Informix
- From: NGSSoftware Insight Security Research
- XMB <= 1.9.6 Final basename()/'langfilenew' arbitrary local inclusion / remote commands execution
- Re: Yabb XSS - or NOT
- BlaBla 4U XSS Vulnerabilite
- Virtual War v1.5.0 SQL injection and XSS
- Re: [SM-ANNOUNCE] SquirrelMail 1.4.8 released - fixes variable overwriting attack
- JavaScript get Internal Address (thanks to DanBUK)
- RE: Re: Cisco VPN Concentrator IKE resource exhaustion DoS Advisory
- Re: Startpage <= 1.0 (cfgLanguage) Remote File Inclusion Vulnerability
- HPSBMA02138 SSRT061184 rev.1 - HP OpenView Storage Data Protector, Remote Arbitrary Command Execution
- Kaspersky Anti-Hacker personal firewall unstealthy stealth mode
- Wordpress WP-DB Backup Plugin Directory Traversal Vulnerability
- Arbitrary Library Loading in Informix
- From: NGSSoftware Insight Security Research
- Multiple Arbitrary Command Execution Vulnerabilities
- From: NGSSoftware Insight Security Research
- InfanView 3.98 (with plugins) - Access violation at processing images CUR files
- Re: [SM-ANNOUNCE] SquirrelMail 1.4.8 released - fixes variable overwriting attack
- Technical note: under some conditions, it's possible to steal HTTP credentials using Flash
- From: Amit Klein (AKsecurity)
- Unauthorized Database Creation Privilege on Informix
- From: NGSSoftware Insight Security Research
- Local privilege Escalation in SmartLine DeviceLock 5.73
- Multiple Password Exposures Flaws
- From: NGSSoftware Insight Security Research
- Re: Re: TSRT-06-02: Microsoft SRV.SYS Mailslot Ring0 Memory Corruption Vulnerability
- osDate 1.1.8 - Multiple HTML Injection Vulnerability - fixed
- RE: ANNOUNCING: 3rd Annual US OWASP AppSec Conference - Oct 16-18 2006 - Seattle, WA
- Re: Startpage <= 1.0 (cfgLanguage) Remote File Inclusion Vulnerability
- Peoplebook Mambo Component <= v1.0 Remote File Include Vulnerabilities
- Multiple buffer-overflows in libmusicbrainz 2.1.2
- [Overflow.pl] ImageMagick ReadSGIImage() Heap Overflow
- (somewhat) breaking the same-origin policy by undermining dns-pinning
- Multiple Buffer Overflow Vulnerabilities in Informix
- From: NGSSoftware Insight Security Research
- Joomla Webring Component (component_dir) Remote File Inclusion Vulnerabilities
- [ GLSA 200608-20 ] Ruby on Rails: Several vulnerabilities
- RE: linksys WRT54g authentication bypass
- From: TeamXMM Consulting, Inc.
- Multiple Arbitrary File Access (Write/Read) Vulnerabilities
- From: NGSSoftware Insight Security Research
- Opera 9 Remote Denial of Service
- Re: TSRT-06-02: Microsoft SRV.SYS Mailslot Ring0 Memory Corruption Vulnerability
- From: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
- Re: RE: linksys WRT54g authentication bypass
- Re: Re: myBloggie <= 2.1.3 (mybloggie_root_path) Remote File Inclusion Vulnerability
- Security contact from Critical Path Inc
- Re: Calendarix <= 0.7 (calpath) Remote File Inclusion Vulnerability
- [ MDKSA-2006:142 ] - Updated heartbeat packages fix vulnerability
- [ MDKSA-2006:141 ] - Updated gnupg packages fix vulnerability
- Re: phpPrintAnalyzer <= 1.1 (rep_par_rapport_racine) Remote File Inclusion Vulnerability
- local file include in PHP-Nuke (autohtml.php)
- Mailslot bug (MS06-035) vs non-Mailslot bug (CVE-2006-3942)
- [XSec-06-02]: Internet Explorer (IMSKDIC.DLL) COM Object Instantiation Vulnerability
- Re: Calendarix <= 0.7 (calpath) Remote File Inclusion Vulnerability
- Koobi Pro CMS 5.6 SQL injection & XSS
- [XSec-06-03]: Internet Explorer (CHTSKDIC.DLL) COM Object Instantiation Vulnerability
- [XSec-06-04]: Internet Explorer (msoe.dll) COM Object Instantiation Vulnerability
- [SECURITY] [DSA 1151-1] New heartbeat packages fix denial of service
- [security bulletin] HPSBUX02141 SSRT51153 rev.1 - HP-UX in Trusted mode, Local Denial of Service (DoS)
- Re: Concurrency-related vulnerabilities in browsers - expect problems
- Lizge V.20 Web Portal File Include Vulnerability
- otopholder 1.8 suffers from a local file inclusion,XSS and directory listing vuln
- fusionnews 3,7 Remote File Inclusion
- CORE-2006-0714: Microsoft SRV.SYS SMB_COM_TRANSACTION Denial of Service
- From: Core Security Technologies advisories
- [USN-334-1] krb5 vulnerabilities
- [XSec-06-05]: VMware 5.5.1 for Windows arbitrary partition table delete issue.
- Re: CGI Script Source Code Disclosure Vulnerability in Apache for Windows
- Re: TinyWebGallery v1.5 ( image ) Remote Include Vulnerability
- Mambo com_lm component (archive.php) Remote File Include Vulnerabilities
- [USN-335-1] heartbeat vulnerability
- [scip_Advisory 2456] Horde Framework and Horde IMP /index.php cross site referencing
- [scip_Advisory 2457] Horde Framework and Horde IMP /horde/imp/search.php cross site scripting
- MS Terminal Server application session breakout
- ShockwaveFlash 9 (Stack overflow)
- [security bulletin] HPSBUX02115 SSRT061077 rev.2 - HP-UX running Support Tools Manager (xstm, cstm, stm) Local Denial of Service (DoS)
- Technical note by Amit Klein: "Sending arbitrary HTTP requests with Flash 7/8 (+IE 6.0)"
- From: Amit Klein (AKsecurity)
- [ MDKSA-2006:143 ] - Updated Firefox packages fix multiple vulnerabilities
- Re: MS Terminal Server application session breakout
- From: Thor (Hammer of God)
- SYM06-16 Symantec NetBackup PureDisk Remote Office Edition Elevation of Privilege
- Reporter Mambo Component Remote File İnclude
- Re: [Overflow.pl] ImageMagick ReadSGIImage() Heap Overflow
- discloser 0.0.4 Remote File Inclusion (with Exploit)
- [USN-337-1] imagemagick vulnerability
- [EEYEB-20060703] IBM eGatherer ActiveX Code Execution Vulnerability
- Registration Now Open!: Security OPUS Infosec Conference - Oct 2-5 2006 - San Francisco, CA
- [USN-336-1] binutils vulnerability
- CubeCart <= 3.0.11 SQL injection & cross site scripting
- Re: Re: CGI Script Source Code Disclosure Vulnerability in Apache for Windows
- [XSec-06-06]: Windows 2003 (tsuserex.dll) COM Object Instantiation Vulnerability
- Re: [VulnWatch] Re: Concurrency-related vulnerabilities in browsers - expect problems
- World Summit on Intrusion Prevention
- UPDATED: MITKRB5-SA-2006-001: multiple local privilege escalation vulnerabilities
- Re: discloser 0.0.4 Remote File Inclusion (with Exploit)
- RE: [VulnWatch] Re: Concurrency-related vulnerabilities in browsers - expect problems
- powergap <= (s0x.php) Remote File Inclusion
- Re: SYM06-16 Symantec NetBackup PureDisk Remote Office Edition Elevation of Privilege
- [security bulletin] HPSBUX02139 SSRT5981 rev.1 - HP-UX Running the LP Subsystem, remote Denial of Service (DoS)
- [ MDKSA-2006:143-1 ] - Updated Firefox packages fix multiple vulnerabilities
- [XSec-06-07]: Visual Studio 6.0 Multiple COM Object Instantiation Vulnerability
- RE: Mailslot bug (MS06-035) vs non-Mailslot bug (CVE-2006-3942)
- ToorCon 8 Call for Papers Closing Tomorrow & Workshops/Seminars Added
- Secunia Research: AOL Insecure Default Directory Permissions
- mtg_myhomepage Component For Mambo R.F.I
- Joomla x-shop <= 1.7 Remote File Include Vulnerability
- anjel Mambo Component Remote File Include
- Joomla Rssxt <= 1.0 Remote File Include Vulnerability
- [SECURITY] [DSA 1152-1] New trac packages fix information disclosure
- mambo-phphop Product Scroller Module R.F.I
- Norton DLL faking via 'SuiteOwners' protection bypass Vulnerability
- Mambo jim Component Remote Include Vulnerability
- Re: when will AV vendors fix this???
- Re: [Full-disclosure] RE: when will AV vendors fix this???
- Multiple xxs cPanel 10
- Re: [Full-disclosure] Re: when will AV vendors fix this???
- Re: [VulnWatch] Re: Concurrency-related vulnerabilities in browsers - expect problems
- RE: Google Picasa Listening on Port 80?
- UPDATE vBulletin Version 3.5.4 exploit
- RE: Security contact from Critical Path Inc
- Registration Now Open!: 3rd Annual US OWASP AppSec Conference - Oct 16-18 2006 - Seattle, WA
- OneOrZero Helpdesk V1.6.4.1 susceptible to SQL injection and XSS
- Re: [Full-disclosure] RE: when will AV vendors fix this???
- JavaScript Lazy Authorization Forcer and Visited Link Scaner
- contentpublisher Mambo Component Remote File Include Vulnerabilities
- Re: Mailslot bug (MS06-035) vs non-Mailslot bug (CVE-2006-3942)
- Mambo mambelfish Component <= 1.1 Remote File Include Vulnerability
- [SECURITY] [DSA 1153-1] New ClamAV packages fix arbitrary code execution
- Re: UPDATE vBulletin Version 3.5.4 exploit
- Re: Concurrency-related vulnerabilities in browsers - expect problems
- Joomla Kochsuite Component <= 0.9.4 (config.kochsuite.php) Remote File Inclusion Vulnerability
- Joomla MamboWiki Component <= 0.9.4 (MamboLogin.php) Remote File Inclusion Vulnerability
- [KAPDA::#55] - Joomla poll component vulnerability
- Joomla RFİ ( ERNE )
- Sonium Enterprise Adressbook Version 0.2 (folder) RFI
- From: philipp . niedziela
- Re: Concurrency-related vulnerabilities in browsers - expect problems
- Re: Re: discloser 0.0.4 Remote File Inclusion (with Exploit)
- Re: JavaScript Lazy Authorization Forcer and Visited Link Scaner
- Modification For OpenSEF Remote file Inclusion
- Ako Comments (mod) Remote File Inclusion
- [Kurdish Security # 23] Spaw Editor Remote Include Vulnerability
- Mambo CatalogShop Remote File Inclusion
- Mambo com_cropimage 1.0 Component Remote Include Vulnerability
- XennoBB <= 2.2.1 "icon_topic" SQL Injection
- POC & exploit for Apache mod_rewrite off-by-one
- LBlog <= "comments.asp" SQL Injection Exploit
- From: ChironeX . FleckeriX
- WoltLab Burning Board 2.3.5(WBB) in XSS
- [SECURITY] [DSA 1154-1] New squirrelmail packages fix information disclosure
- New PowerPoint 0-day and Trojan - FAQ document ready
- Re: [SECURITY] [DSA 1150-1] New shadow packages fix privilege escalation
- [XSec-06-08]: Windows 2000 Multiple COM Object Instantiation Vulnerability
- Mambo Component - Display MOSBot Manager Remote File Inclusion Vuln
- Mambo Component - Display MOSBot Manager Remote File Inclusion Vuln
- DoS 2wire Gateway
- Mambo Component - EstateAgent Remote File Inclusion
- [XSec-06-09]: Internet Explorer Multiple COM Objects Color Property DoS Vulnerability
- ToendaCMS <= 1.0.3 -(tcms_administer_site) Remote File Include
- Re: Startpage <= 1.0 (cfgLanguage) Remote File Inclusion Vulnerability
- SimpleBlog 2.0 <= "comments.asp" SQL Injection Exploit
- From: ChironeX . FleckeriX
- Diesel Job Site forgot.php Cross-Site Scripting
- Diesel Paid Mail getad.php Cross-Site Scripting Vulnerability
- Smart Traffic Remote File Include Vulnerability
- DieselPay İndex.php Cross-Site Scripting Vulnerability
- [ MDKSA-2006:144 ] - Updated php packages fix vulnerability
- [ MDKSA-2006:145 ] - Updated Firefox packages fix multiple vulnerabilities
- MDaemon POP3 server remote buffer overflow (preauth)
- [ MDKSA-2006:146 ] - Updated Thunderbird packages fix multiple vulnerabilities
- TTG0601 - Alt-N WebAdmin Multiple Vulnerabilities
- Vendor Statement: fixed Mobotix IP Network Cameras Multiple XSS bug
- Simpliciti Locked Browser Jail Breakout Vulnerability
- EEYE:ALERT: MS06-042 Related Internet Explorer 'Crash' is Exploitable
- Major updates in PowerPoint FAQ document - not a 0-day issue
- Simple Machines Forum <=1.1RC2 unset() vulnerabilities
- Re: Joomla x-shop <= 1.7 Remote File Include Vulnerability
- Re: Joomla Rssxt <= 1.0 Remote File Include Vulnerability
- unauthorized VNC access in AK-Systems Windows Terminals
- Re: Mambo Component - Display MOSBot Manager Remote File Inclusion Vuln
- Re: mtg_myhomepage Component For Mambo R.F.I
- (exploit) firefox 1.5.0.6 linux DoS
- Linux Kernel SCTP Privilege Elevation Vulnerability
- Tons of SQL-injections and XSS in Eichhorn Portal and vendor page
- Symantec Enterprise Security Manager Denial-of-Service Vulnerability
- Re: mambo-phphop Product Scroller Module R.F.I
- PHlyMail Lite [PM_[path][lib]=] Remote File Include Vulnerability
- PHProjekt v0.6.1 Remote File Inclusion Vulnerability (2)
- BlackBoard Multiple Vulnerabilities (XSS)
- Re: discloser 0.0.4 Remote File Inclusion (with Exploit)
- Re: anjel Mambo Component Remote File Include
- [ MDKSA-2006:147 ] - Updated squirrelmail packages fix vulnerabilities
- faille include in "VeriTECH" isreal
- Re: BlackBoard Multiple Vulnerabilities (XSS)
- Symantec Gateway Security DNS exploit
- Re: BlackBoard Multiple Vulnerabilities (XSS)
- Cisco Security Advisory: Cisco VPN 3000 Concentrator FTP Management Vulnerabilities
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Unintentional Password Modification in Cisco Firewall Products
- From: Cisco Systems Product Security Incident Response Team
- AW: Symantec Gateway Security DNS exploit
- RE: Symantec Gateway Security DNS exploit
- From: Pretorius, Wynand (ZA - Johannesburg)
- Bugtraq ID: 18402
- New malware names and updates to PowerPoint FAQ document
- [ GLSA 200608-21 ] Heimdal: Multiple local privilege escalation vulnerabilities
- [ GLSA 200608-22 ] fbida: Arbitrary command execution
- FreeBSD Security Advisory FreeBSD-SA-06:18.ppp
- From: FreeBSD Security Advisories
- Advisory: VistaBB <= 2.x Multiple File Inclusion Vulnerabilities
- From: Mustafa Can Bjorn IPEKCI
- Advisory: Integramod Portal <= 2.x File Inclusion Vulnerability
- From: Mustafa Can Bjorn IPEKCI
- Re: Modification For OpenSEF Remote file Inclusion
- Re: Joomla RFİ ( ERNE )
- Re: Opsware NAS 6.0 reveals MySQL 'root' password
- [SECURITY] [DSA 1155-1] New sendmail packages fix denial of service
- Re: Directory Traversal vulnerability in IPCheck Monitor Server
- Re: PHProjekt v0.6.1 Remote File Inclusion Vulnerability (2)
- Re: PHlyMail Lite [PM_[path][lib]=] Remote File Include Vulnerability
- Re: Mambo Component - EstateAgent Remote File Inclusion
- [ GLSA 200608-23 ] Heartbeat: Denial of Service
- From: Sune Kloppenborg Jeppesen
- [SECURITY] [DSA 1155-2] New sendmail packages fix denial of service
- Re: ToendaCMS <= 1.0.3 -(tcms_administer_site) Remote File Include
- EEYE: Internet Explorer Compressed Content URL Heap Overflow Vulnerability
- [ MDKSA-2006:149 ] - Updated MySQL packages fix user privilege vulnerabilities
- [ MDKSA-2006:148 ] - Updated xorg-x11 packages fix vulnerabilities
- Advisory 05/2006: Zend Platform Multiple Remote Vulnerabilities
- pSlash v0.7 (lvc_include_dir) Remote Include Vulnerability
- Re: contentpublisher Mambo Component Remote File Include Vulnerabilities
- Re: [eVuln] B-net Software Multiple XSS Vulnerabilities
- rPSA-2006-0157-1 xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs
- Multiple Vulnerabilities in Asterisk 1.2.10 (Fixed in 1.2.11)
- NSFOCUS SA2006-08 : Microsoft IE6 urlmon.dll Long URL Buffer Overflow Vulnerability
- From: NSFOCUS Security Team
- rPSA-2006-0158-1 tshark wireshark
- TSLSA-2006-0048 - multi
- From: Trustix Security Advisor
- FreeBSD Security Advisory FreeBSD-SA-06:18.ppp [REVISED]
- From: FreeBSD Security Advisories
- Indiana University Security Advisory: Fuji Xerox Printing Systems (FXPS) print engine vulnerabilities
- YaPiG thanks_comment.php Cross-Site Scripting Vulnerability
- From: Kuon_at_Armorize_dot_com
- Re: Symantec Gateway Security DNS exploit
- [ MDKSA-2006:150 ] - Updated kernel packages fix multiple vulnerabilities
- [ MDKSA-2006:151 ] - Updated kernel packages fix multiple vulnerabilities
- CuteNews 1.3.* Remote File Include Vulnerability
- [ MDKSA-2006:152 ] - Updated wireshark packages fix multiple vulnerabilities
- MyBB Html Injection ( XSS )
- AlstraSoft Video Share Enterprise Remote File Include Vulnerability
- [ GLSA 200608-24 ] AlsaPlayer: Multiple buffer overflows
- Sql injection in Mambo & Joomla
- Bigace 1.8.2 (GLOBALS) Remote File Inclusion
- Sql injection in Xoops
- Jupiter CMS 1.1.5 index.php Remote File Include
- Jetbox CMS search_function.php Remote File
- Suggested Fix for CVE-2006-4299
- Cisco NAC Appliance Agent Installation Bypass Vulnerability
- Mambo/Joomla com_comprofiler Components <== v1.0 RC 2 Multiple Remote File Include Vulnerabilities
- Re: Cisco NAC Appliance Agent Installation Bypass Vulnerability
- [SECURITY] [DSA 1156-1] New kdebase packages fix information disclosure
- [XSec-06-10]: Internet Explorer (daxctle.ocx) Heap Overflow Vulnerability
- [SECURITY] [DSA 1159-1] New Mozilla Thunderbird packages fix several problems
- [SECURITY] [DSA 1158-1] New streamripper packages fix arbitrary code execution
- [SECURITY] [DSA 1157-1] New ruby1.8 packages fix several vulnerabilities
- [ GLSA 200608-25 ] X.org and some X.org libraries: Local privilege escalations
- interact <= 2.2 (CONFIG[BASE_PATH]) Remote File Include Vulnerability
- JetBox cms (search_function.php) Remote File Include
- Re: Another YabbSE Remote Code Execution Vulnerability
- Possible Myspace Worm
- Re: Cisco NAC Appliance Agent Installation Bypass Vulnerability
- SYMSA-2006-009
- [ GLSA 200608-27 ] Motor: Execution of arbitrary code
- [ GLSA 200608-26 ] Wireshark: Multiple vulnerabilities
- [ GLSA 200608-28 ] PHP: Arbitary code execution
- rPSA-2006-0159-1 ImageMagick
- [ MDKSA-2006:155 ] - Updated ImageMagick packages fix vulnerabilities
- [ MDKSA-2006:153 ] - Updated binutils packages fix multiple vulnerabilities
- [ MDKSA-2006:154 ] - Updated lesstif packages fix potential local root vulnerability
- LinksCaffe no checker at admin
- CYBSEC - Security Advisory: Microsoft Windows DHCP Client Service Remote Buffer Overflow
- From: Mariano Nuñez Di Croce
- [SECURITY] [DSA 1160-1] New Mozilla packages fix several vulnerabilities
- AW: JetBox cms (search_function.php) Remote File Include
- e107 <= 0.75 GLOBALS[] overwrite/Zend_Hash_Del_Key_Or_Index remote commands execution
- Submit ( b2evolution<= 1.8 Remote File Include Vulnerabilities )
- Submit ( ToendaCMS<= ( Remote File Include Vulnerabilities )
- JS ASP Faq Manager v1.10 sql injection
- [SECURITY] [DSA 1161-1] New Mozilla Firefox packages fix several vulnerabilities
- DUpoll 3.1 security alert
- Portail PHP mod_phpalbum 2.15 Modules Remote File Inclusion
- Re: Jupiter CMS 1.1.5 index.php Remote File Include
- Re: CuteNews 1.3.* Remote File Include Vulnerability
- InfoSec Paper: Creating Business Through Virtual Trust
- Re: Cisco NAC Appliance Agent Installation Bypass Vulnerability
- Re: AW: JetBox cms (search_function.php) Remote File Include
- SQL-Ledger serious security vulnerability and workaround
- [SECURITY] [DSA 1162-1] New libmusicbrainz packages fix arbitrary code execution
- Ezportal/Ztml v1.0 Multiple vulnerabilities
- IwebNegar v1.1 Multiple vulnerabilities
- Nuked Klan 1.7 SP4.3 : Function Anti-XSS Bypassed
- XSS in HLstats 1.34
- [KAPDA::#56] - FREEKOT SQL Injection Vulnerability
- [SECURITY] [DSA 1163-1] New gtetrinet packages fix arbitrary code execution
- Re: JetBox cms (search_function.php) Remote File Include
- ezContents Version 2.0.3 Remote/Local File Inclusion, SQL Injection, XSS
- osCommerce < 2.2 Milestone 2 060817 POC Exploit
- [KAPDA]MyBB 1.1.7 ~ admin/global.php ~ XSS Attack
- feedsplitter considered harmful
- Hackers to Hackers Conference III - Call for Papers
- From: Rodrigo Rubira Branco (BSDaemon)
- [KAPDA]MyBB 1.1.7~ htmlspeacialchar_uni(), fixjavascript(), functions_post.php ~[url]XSS attack
Mail converted by MHonArc