Mail Index
- [ GLSA 200712-23 ] Wireshark: Multiple vulnerabilities
- [ GLSA 200712-24 ] AMD64 x86 emulation GTK+ library: User-assisted execution of arbitrary code
- [ GLSA 200712-25 ] OpenOffice.org: User-assisted arbitrary code execution
- Bitweaver source code disclosure, arbitrary file upload
- Fingerprints in Astaro Security Gateway v7.1
- [ GLSA 200712-22 ] Opera: Multiple vulnerabilities
- Re: Re: Cryptome: NSA has real-time access to Hushmail servers
- milliscripts (dir.php) Cross-Site Scripting Vulnerability
- LiveCart Multiple Cross-Site Scripting Vulnerabilities
- RE: Cryptome: NSA has real-time access to Hushmail servers
- Instant Softwares DatingSite SQL Injection
- Re: Cryptome: NSA has real-time access to Hushmail servers
- Re: TalkBack 2.2.7 Multiple Remote File Inclusion Vulnerabilities
- RE: Cryptome: NSA has real-time access to Hushmail servers
- Re: Cryptome: NSA has real-time access to Hushmail servers
- From: mark seiden-via mac
- Re: Cryptome: NSA has real-time access to Hushmail servers
- [HSC Security Group] Multiple CSRF in Joomla all versions - Complete compromise
- RE: Cryptome: NSA has real-time access to Hushmail servers
- RE: Cryptome: NSA has real-time access to Hushmail servers
- From: Thor (Hammer of God)
- Re: Cryptome: NSA has real-time access to Hushmail servers
- Re: Cryptome: NSA has real-time access to Hushmail servers
- Cross-Site Scripting (XSS) in phpWebSite 1.4.0 search
- MODx CMS Source code disclosure, local file inclusion
- XSS Vulnerabilities in Common Shockwave Flash Files
- Buffer-overflow and format string in White_Dune 0.29beta791
- phpBB2 2.0.22 Cross Site Scripting Vulnerability
- Multiple vulnerabilities in Georgia SoftWorks SSH2 Server 7.01.0003
- AST-2008-001: Crash from transfer using BYE with Also header
- From: Asterisk Security Team
- Yet another Dialog Spoofing Vulnerability - Firefox Basic Authentication
- [security bulletin] HPSBGN02301 SSRT071508 rev.2 - HP Software Update Running on Windows, Remote Execution of Arbitrary Code, Gain Privileged Access
- Re: [Full-disclosure] Yet another Dialog Spoofing Vulnerability - Firefox Basic Authentication
- Re: [Full-disclosure] Yet another Dialog Spoofing Vulnerability - Firefox Basic Authentication
- xss in w3-msql error page
- [ MDVSA-2008:1 ] - Updated wireshark packages fix multiple vulnerabilities
- Re: phpBB2 2.0.22 Cross Site Scripting Vulnerability
- Re: Cryptome: NSA has real-time access to Hushmail servers
- Re: Cryptome: NSA has real-time access to Hushmail servers
- RE: Latest round of web hacking incidents for 2007 & Project news
- RE: Re: Cryptome: NSA has real-time access to Hushmail servers
- RE: Latest round of web hacking incidents for 2007 & Project news
- [SECURITY] [DSA 1443-1] New tcpreen packages fix denial of service
- Re: Latest round of web hacking incidents for 2007 & Project news
- rPSA-2008-0001-1 dovecot
- From: rPath Update Announcements
- multiple CAPTCHA automation test bypass digest
- Re: Re: phpBB2 2.0.22 Cross Site Scripting Vulnerability
- Re: rPSA-2008-0001-1 dovecot
- [SECURITY] [DSA 1444-1] New php5 packages fix several vulnerabilities
- securityvulns.com russian vulnerabilities digest
- [SECURITY] [DSA 1446-1] New wireshark packages fix denial of service
- [SECURITY] [DSA 1445-1] New maradns packages fix denial of service
- [SECURITY] [DSA 1447-1] New tomcat5.5 packages fix several vulnerabilities
- Re: phpBB2 2.0.22 Cross Site Scripting Vulnerability
- rPSA-2008-0004-1 tshark wireshark
- From: rPath Update Announcements
- FortiGuard: URL Filtering Application Bypass Vulnerability
- Re: rPSA-2008-0001-1 dovecot
- Re: Latest round of web hacking incidents for 2007 & Project news
- AW: phpBB2 2.0.22 Cross Site Scripting Vulnerability
- Re: rPSA-2008-0001-1 dovecot
- Re: rPSA-2008-0001-1 dovecot
- Multiple vulnerabilities in yaSSL 1.7.5
- Some DoS in some telnet servers
- Pre-auth buffer-overflow in mySQL through yaSSL
- Re: FortiGuard: URL Filtering Application Bypass Vulnerability
- iDefense Security Advisory 12.24.07: Novell ZENworks Endpoint Security Management Local Privilege Escalation Vulnerability
- rPSA-2008-0006-1 libexif
- From: rPath Update Announcements
- NetRisk 1.9.7 Remote File Inclusion Vulnerability
- INVISION POWER BOARD 2.1.7 ACTIVE XSS/SQL INJECTION EXPLOIT
- [ MDVSA-2008:002 ] - Updated squid package fixes remote denial of service
- [SECURITY] [DSA 1449-1] New loop-aes-utils packages fix programming error
- rPSA-2008-0007-1 tetex tetex-afm tetex-dvips tetex-fonts tetex-latex tetex-xdvi
- From: rPath Update Announcements
- [SECURITY] [DSA 1450-1] New util-linux packages fix programming error
- [SECURITY] [DSA 1448-1] New eggdrop packages fix execution of arbitrary code
- rPSA-2008-0008-1 cups
- From: rPath Update Announcements
- [SECURITY] [DSA 1448-1] New eggdrop packages fix arbitrary code execution
- Aruba Mobility Controller User Authentication Vulnerability - Aruba Advisory ID: AID-122207
- vBulletin 3.6.8 XSRF/XSS Vulnerability
- eTicket 1.5.5.2 Multiple Vulnerabilities
- [HSC] Snitz Forums Multiple Vulnerabilities
- netrisk 1.9.7 Multiple Remote Vulnerabilities (sql injection/xss)
- From: hadihadi_zedehal_2006
- OneCMS Vulnerabilities
- New Web Hacking Incidents at WHID
- [Reversemode Paper] Exploiting WDM Audio Drivers
- [SECURITY] [DSA 1451-1] New mysql-dfsg-5.0 packages fix several vulnerabilities
- Linksys WRT54 GL - Session riding (CSRF)
- SocialURL Login Page Cross-Site Scripting
- Re: vBulletin 3.6.8 XSRF/XSS Vulnerability
- PostgreSQL 2007-01-07 Cumulative Security Release
- [SECURITY] [DSA 1452-1] New wzdftpd packages fix denial of service
- [SECURITY] [DSA 1453-1] New tomcat5 packages fix several vulnerabilities
- LayerOne 2008 - CFP Released
- Million Dollar Script 2.0.14 Remote File Disclosure Vulnerability.
- CORE-2007-1106: SynCE Remote Command Injection
- From: CORE Security Technologies Advisories
- [SECURITY] [DSA 1454-1] New freetype packages fix arbitrary code execution
- Re: Linksys WRT54 GL - Session riding (CSRF)
- Re: Linksys WRT54 GL - Session riding (CSRF)
- PWDumpX v1.4 - Dumps domain password cache, LSA secrets, password hashes, and password history hashes.
- PWDumpX v1.0 and PWDumpX v1.1 updated - bug fixes
- RE: [HSC] Snitz Forums Multiple Vulnerabilities
- iDefense Security Advisory 01.07.08: Motorola netOctopus Agent MSR Write Privilege Escalation Vulnerability
- VMSA-2008-0001 Moderate OpenPegasus PAM Authentication Buffer Overflow and updated service console packages
- From: VMware Security team
- [ MDVSA-2008:001-1 ] - Updated wireshark packages fix multiple vulnerabilities
- [USN-560-1] Tomboy vulnerability
- sysHotel On Line Remote File Disclosure Vulnerability.
- VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1
- From: VMware Security team
- Corsaire Security Advisory: Sun J2RE DoS issue
- HPSBUX02153 SSRT061181 rev.7 - HP-UX Running Firefox, Remote Unauthorized Access or Elevation of Privileges or Denial of Service (DoS)
- HPSBUX02156 SSRT061236 rev.4 - HP-UX Running Thunderbird, Remote Unauthorized Access or Elevation of Privileges or Denial of Service (DoS)
- Level-One WBR-3460A Grants Root Access
- Joomla 1.0.13 CSRF
- Re: Joomla 1.0.13 CSRF
- [SECURITY] [DSA 1455-1] New libarchive1 packages fix several problems
- ERRATA: [ GLSA 200709-07 ] Eggdrop: Buffer overflow
- LFI in Tuned Studios Templates
- From: Digital Security Research Group [DSecRG]
- [security bulletin] HPSBMA02239 SSRT061260 rev.3 - HP OpenView Operations (OVO) Agents Running Shared Trace Service, Remote Arbitrary Code Execution
- First (Major) web hacking incidents for 2008. Sign of the year to come?
- [INFIGO 2008-01-06]: McAfee E-Business Server Remote Preauth Code Execution / DoS
- Re: First (Major) web hacking incidents for 2008. Sign of the year to come?
- [USN-562-1] opal vulnerability
- [ MDVSA-2008:004 ] - Updated postgresql packages fix denial of service and privilege escalation issues
- Privileg escalation in Omegasoft Insel 7
- [ GLSA 200801-01 ] unp: Arbitrary command execution
- [ MDVSA-2008:003 ] - Updated clamav packages fix multiple vulnerabilities
- Pre-auth remote commands execution in SAP MaxDB 7.6.03.07
- [INFIGO-2008-01-06]: McAfee E-Business Server Remote Preauth Code Execution / DoS - Corrected
- [USN-561-1] pwlib vulnerability
- [USN-564-1] Net-SNMP vulnerability
- [ GLSA 200801-02 ] R: Multiple vulnerabilities
- [USN-563-1] CUPS vulnerabilities
- [ MDVSA-2008:004 ] - Updated postgresql packages fix denial of service and privilege escalation issues
- iDefense Security Advisory 01.09.08: Novell NetWare Client nicm.sys Local Privilege Escalation Vulnerability
- [ GLSA 200801-03 ] Claws Mail: Insecure temporary file creation
- [SECURITY] [DSA 1456-1] New fail2ban packages fix denial of service
- [ GLSA 200801-05 ] Squid: Denial of Service
- [USN-565-1] Squid vulnerability
- [ GLSA 200801-04 ] OpenAFS: Denial of Service
- [ MDVSA-2008:005 ] - Updated libexif packages fix multiple vulnerabilities
- [SECURITY] [DSA 1457-1] New dovecot packages fix information disclosure
- uCon 2008 call for participation - Recife, Brazil
- Simple Machines Forum Cross-Site Scripting Vulnerabilities
- PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager
- From: ProCheckUp Research
- [USN-566-1] OpenSSH vulnerability
- Digital Armaments January-February Hacking Challenge: Special 20.000$ Prize - Windows Vulnerabilities and Exploit
- [ GLSA 200801-06 ] Xfce: Multiple vulnerabilities
- BT Home Flub: Pwnin the BT Home Hub (5) - exploiting IGDs remotely via UPnP
- Word 2007 Email as PDF path disclosure flaw
- Buffer-overflow in Quicktime Player 7.3.1.70
- MTCMS <=2.0 SQL Injection Vulnerbility
- From: hadihadi_zedehal_2006
- [SECURITY] [DSA 1458-1] New openafs packages fix denial of service vulnerability
- [ MDVSA-2008:006 ] - Updated exiv2 packages fix vulnerability
- Re: Buffer-overflow in Quicktime Player 7.3.1.70
- From: Marcello Barnaba (void)
- [USN-567-1] Dovecot vulnerability
- Re: Re: Buffer-overflow in Quicktime Player 7.3.1.70
- re-resting of zzuf results
- At long last -- Extra Outlooks!
- From: Thor (Hammer of God)
- [ MDVSA-2008:007 ] - Updated madwifi-source, wpa_supplicant packages fix vulnerabilities
- SecurityReason - Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability
- Re: Linksys WRT54 GL - Session riding (CSRF)
- SecurityReason - Apache2 CSRF, XSS, Memory Corruption and Denial of Service Vulnerability
- ImageAlbum Remote SQL Injection Vulnerabilities
- Re: Buffer-overflow in Quicktime Player 7.3.1.70
- CFP: EuroSec Workshop (March 31st, 2008)
- Member Area System (MAS) Remote File Include Vulnerability (view_func.php)
- Naymz multiple XSS
- Re: At long last -- Extra Outlooks!
- Re: Buffer-overflow in Quicktime Player 7.3.1.70
- Cross site scripting (XSS) in Moodle 1.8.3
- [ MDVSA-2008:010 ] - Updated libxml2 packages fix DoS vulnerability
- [ MDVSA-2008:011 ] - Updated rsync packages fix restrictions bypass vulnerabilities
- Safari 2 Denial of Service
- [ MDVSA-2008:009 ] - Updated autofs packages fix insecure hosts configuration
- [ MDVSA-2008:008 ] - Updated kernel packages fix multiple vulnerabilities and bugs
- Garment Center (index.cgi) Local File Inclusion
- [SECURITY] [DSA 1462-1] New hplip packages fix privilege escalation
- what is this?
- From: crazy frog crazy frog
- Re: what is this?
- From: crazy frog crazy frog
- F5 BIG-IP Web Management List Search XSS
- [ MDVSA-2008:009-1 ] - Updated autofs packages fix insecure hosts configuration
- RE: Linksys WRT54 GL - Session riding (CSRF)
- [SECURITY] [DSA 1460-1] New postgresql-8.1 packages fix several vulnerabilities
- Re: [Full-disclosure] what is this?
- Re: [Full-disclosure] what is this?
- Re: [Full-disclosure] what is this?
- From: crazy frog crazy frog
- SQID v0.3 - SQL Injection Digger.
- Re: [Full-disclosure] Buffer-overflow in Quicktime Player 7.3.1.70
- Re: At long last -- Extra Outlooks!
- RE: At long last - Extra Outlooks!
- From: Thor (Hammer of God)
- RE: At long last -- Extra Outlooks!
- From: Thor (Hammer of God)
- Re: At long last -- Extra Outlooks!
- Re: Re: Buffer-overflow in Quicktime Player 7.3.1.70
- Re: what is this?
- [SECURITY] [DSA 1459-1] New gforge packages fix SQL injection
- Re: what is this?
- Re: what is this?
- From: crazy frog crazy frog
- Re: what is this?
- Re: what is this?
- Re: Buffer-overflow in Quicktime Player 7.3.1.70
- Re: Linksys WRT54 GL - Session riding (CSRF)
- ZDI-08-001: IBM Tivoli Storage Manager Express Backup Server Heap Overflow Vulnerability
- RE: what is this?
- Binn SBuilder (nid) Remote Blind Sql Injection Vulnerabily
- Re: Garment Center (index.cgi) Local File Inclusion
- Re: Buffer-overflow in Quicktime Player 7.3.1.70
- From: Marcello Barnaba (void)
- Hacking The Interwebs
- [SECURITY] [DSA 1463-1] New postgresql-7.4 packages fix several vulnerabilities
- Re[2]: [Full-disclosure] what is this?
- Re: what is this?
- [USN-568-1] PostgreSQL vulnerabilities
- [SECURITY] [DSA 1461-1] New libxml2 packages fix denial of service
- [security bulletin] HPSBUX02303 SSRT071468 rev.1 - HP-UX Running X Font Server (xfs) Software, Remote Execution of Arbitrary Code
- [security bulletin] HPSBST02304 SSRT080003 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-001 to MS08-002
- [ MDVSA-2008:012 ] - Updated python packages fix vulnerabilities
- [ MDVSA-2008:013 ] - Updated python packages fix vulnerability in imageop module
- FreeBSD Security Advisory FreeBSD-SA-08:01.pty
- From: FreeBSD Security Advisories
- FreeBSD Security Advisory FreeBSD-SA-08:02.libc
- From: FreeBSD Security Advisories
- [USN-569-1] libxml2 vulnerability
- Re: what is this?
- Defeating audio captcha systems
- From: "José M. Palazón Romero"
- Country by Country ISA Computer Sets
- From: Thor (Hammer of God)
- Exploiting the SpamBam plugin for wordpress
- From: "José M. Palazón Romero"
- Re: Linksys WRT54 GL - Session riding (CSRF)
- Re: what is this?
- From: crazy frog crazy frog
- Re: [Full-disclosure] what is this?
- Re[2]: what is this?
- Re: [Full-disclosure] what is this?
- From: crazy frog crazy frog
- Re[2]: what is this?
- SecurityReason - Apache (mod_status) Refresh Header - Open Redirector (XSS)
- Article DashBoard all version SQL Injection Vulnerability
- Max's File Uploader File Upload Vulnerability
- MicroNews Admin Direct Access vulnerability
- Pipe to FOR Crashes CMD
- Re: what is this?
- RE: what is this?
- Re: [Full-disclosure] what is this?
- Re: [Full-disclosure] what is this?
- From: crazy frog crazy frog
- Re[2]: what is this?
- Re: Linksys WRT54 GL - Session riding (CSRF)
- Re: Linksys WRT54 GL - Session riding (CSRF)
- iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTserver Heap Overflow Vulnerability
- iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTServer Multiple Untrusted Pointer Vulnerabilities
- iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTserver Multiple Untrusted Pointer Offset Vulnerabilities
- iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTServer Multiple Untrusted Loop Bounds Vulnerabilities
- Re: Defeating audio captcha systems
- Re: what is this?
- [SECURITY] [DSA 1464-1] New syslog-ng packages fix denial of service
- [DSECRG-08-003] blogcms 4.2.1b Multiple Security Vulnerabilities
- From: Digital Security Research Group [DSecRG]
- RichStrong CMS (showproduct.asp?cat=) Remote SQL Injection Exploit
- rPSA-2008-0015-1 cairo
- From: rPath Update Announcements
- cPanel Hosting Manager (dohtaccess.html)
- rPSA-2008-0016-1 postgresql postgresql-server
- From: rPath Update Announcements
- [DSECRG-08-002] Local File Include in arias 0.99-6
- From: Digital Security Research Group [DSecRG]
- rPSA-2008-0017-1 libxml2
- From: rPath Update Announcements
- 8e6 Technologies R3000 Internet Filter Bypass by Request Split
- TPTI-08-01: Apple Quicktime Image File IDSC Atom Memory Corruption Vulnerability
- [Aria-Security.Net] Real Estate Web SQL Injection
- iDefense Security Advisory 01.15.08: Apple QuickTime Macintosh Resource Processing Heap Corruption Vulnerability
- Cisco Security Advisory: Cisco Unified Communications Manager CTL Provider Heap Overflow
- From: Cisco Systems Product Security Incident Response Team
- mcGuestbook v1.2 Remote File Inc.
- Peers static overflow in BitTorrent 6.0 and uTorrent 1.7.5
- Country by Country Computer Sets now available for ISA 2004
- From: Thor (Hammer of God)
- [waraxe-2008-SA#062] - Multiple Sql Injections in MyBB 1.2.10
- TPTI-08-02: Cisco Call Manager CTLProvider Heap Overflow Vulnerability
- SQL scalar function to convert big int to dot notation
- From: Thor (Hammer of God)
- [waraxe-2008-SA#061] - Remote Code Execution in MyBB 1.2.10
- Gradman <= 0.1.3 (agregar_info.php?tabla=) Local File Inclusion Exploit
- [ MDVSA-2008:014 ] - Updated apache 1.3.x packages fix multiple vulnerabilities
- [USN-570-1] boost vulnerabilities
- [ MDVSA-2008:015 ] - Updated apache 2.0.x packages fix multiple vulnerabilities
- [security bulletin] HPSBMA02133 SSRT061201 rev.7 - HP Oracle for OpenView (OfO) Critical Patch Update
- [SECURITY] [DSA 1465-1] New apt-listchanges packages fix arbitrary code execution
- JoomlaFlash Component Multiple Remote File Inclusion
- PHPEchoCMS Multible remote vulnerabilitis
- rPSA-2008-0018-1 mysql mysql-bench mysql-server
- From: rPath Update Announcements
- Re: [CVE-2007-2449] Apache Tomcat XSS vulnerabilities in the JSP examples
- [ MDVSA-2008:016 ] - Updated apache 2.2.x packages fix multiple vulnerabilities
- rPSA-2008-0021-1 kernel
- From: rPath Update Announcements
- [SECURITY] [DSA 1465-2] New apt-listchanges packages fix arbitrary code execution
- Re: Utimaco Safeguard Easy vulnerability
- Clever Copy <=3.0 Multiple Remote Vulnerabilities
- From: hadihadi_zedehal_2006
- [CSNC] OKI C5510MFP Printer Password Disclosure
- RE: Skype videomood XSS
- CORE-2007-1119: CORE FORCE Kernel Buffer Overflow
- From: CORE Security Technologies Advisories
- iDefense Security Advisory 01.17.08: Multiple Vendor X Server XInput Extension Multiple Memory Corruption Vulnerabilities
- iDefense Security Advisory 01.17.08: Multiple Vendor X Server TOG-CUP Extension Information Disclosure Vulnerability
- iDefense Security Advisory 01.17.08: Multiple Vendor X Server EVI and MIT-SHM Extensions Integer Overflow Vulnerabilities
- iDefense Security Advisory 01.17.08: Multiple Vendor X Server XFree86-Misc Extension Invalid Array Index Vulnerability
- ZDI-08-002: Citrix Presentation Server IMA Service Heap Overflow Vulnerability
- IMF 2008 - Call for Papers
- [FIXED] Remote Denial of Service for SSH service at Dell DRAC4 (maybe Mocana SSH)
- [USN-571-1] X.org vulnerabilities
- Agares PhpAutoVideo 2.21(XSS/RFI) Multiple Remote Vulnerabilities
- New search engine for exploits
- common dns misconfiguration can lead to "same site" scripting
- Re: Member Area System (MAS) Remote File Include Vulnerability (view_func.php)
- SocksCap Stack Overflow (<= 2.40-051231)
- Making big money...
- Re: Country by Country ISA Computer Sets
- Re: Country by Country ISA Computer Sets
- SinFP fingerprinting tool online demo
- RE: Country by Country ISA Computer Sets
- From: Thor (Hammer of God)
- Re: mcGuestbook v1.2 Remote File Inc.
- Re: Article DashBoard all version SQL Injection Vulnerability
- RE: Country by Country ISA Computer Sets
- From: Thor (Hammer of God)
- Re: Country by Country ISA Computer Sets
- Re: Tiger Team: New TV series about pen testers airing on CourtTV Dec 25 11 pm
- MyBB 1.2.11 Multiple XSRF Vulnerabilities
- Re: Re: Utimaco Safeguard Easy vulnerability
- From: joachim . schneider
- RE: Country by Country ISA Computer Sets
- From: Thor (Hammer of God)
- [USN-572-1] apt-listchanges vulnerability
- [USN-571-2] X.org regression
- [SECURITY] [DSA 1466-2] New xorg-server packages fix regression
- BitDefender Update Server - Unauthorized Remote File Access Vulnerability
- [SECURITY] [DSA 1467-1] New mantis packages fix several vulnerabilities
- Re: common dns misconfiguration can lead to "same site" scripting
- RE: Country by Country ISA Computer Sets
- From: Thor (Hammer of God)
- Bloofox CMS SQL Injection (Authentication bypass) , Source code disclosure
- [SECURITY] [DSA 1468-1] New tomcat5.5 packages fix several vulnerabilities
- Php Search Remote Inclusion
- AXIGEN 5.0.x AXIMilter Format String Exploit
- MegaBBS ASP Forum Cross-Site Scripting
- Re: common dns misconfiguration can lead to "same site" scripting
- WifiZoo v1.3 released (minor release)
- Flaw in Alice gate2 pluswifi adsl modem
- boastMachine <=3.1 SQL Injection Vulnerbility
- From: hadihadi_zedehal_2006
- [ GLSA 200801-09 ] X.Org X server and Xfont library: Multiple vulnerabilities
- Pass-The-Hash Toolkit v1.2 released.
- Call Jacking: Phreaking the BT Home Hub
- [ GLSA 200801-08 ] libcdio: User-assisted execution of arbitrary code
- BLOG:CMS 4.2.1.c (DIR_PLUGINS) Multiple Remote File Include
- [SECURITY] [DSA 1470-1] New horde3 packages fix denial of service
- [SECURITY] [DSA 1469-1] New flac packages fix arbitrary code execution
- Belkin Wireless G Plus MIMO Router F5D9230-4 Authentication Bypass Vulnerability
- [ GLSA 200801-07 ] Adobe Flash Player: Multiple vulnerabilities
- [waraxe-2008-SA#063] - Information Leakage in Kayako SupportSuite 3.11.01
- [ MDVSA-2008:017 ] - Updated MySQL packages fix multiple vulnerabilities
- [waraxe-2008-SA#064] - Sql Injection in MyBB 1.2.11
- [SECURITY] [DSA 1471-1] New libvorbis packages fix several vulnerabilities
- [SECURITY] [DSA 1472-1] New xine-lib packages fix arbitrary code execution
- Re: 8e6 Technologies R3000 Internet Filter Bypass by Request Split
- PR07-38: XSS on sIFR
- From: ProCheckUp Research
- [ MDVSA-2008:019 ] - Updated cairo packages fix vulnerability
- Some hashes for the record
- From: Sergio 'shadown' Alvarez
- Troopers 08 Security Conference, Call for Papers
- RE: Country by Country ISA Computer Sets
- Re: common dns misconfiguration can lead to "same site" scripting
- [SECURITY] [DSA 1473-1] New scponly packages fix arbitrary code execution
- [ MDVSA-2008:018 ] - Updated gFTP packages fix vulnerabilities
- Re: common dns misconfiguration can lead to "same site" scripting
- PacerCMS Multiple Vulnerabilities (XSS/SQL)
- Belong Site Builder 0.1b Bypass Admincp
- DeluxeBB 1.1 XSS Vulnerabilitie
- Re: PR07-38: XSS on sIFR
- XSRF under Dean’s Permalinks Migration 1.0
- Apache mod_negotiation Xss and Http Response Splitting
- From: Minded Security Research Labs
- SDL_Image 1.2.6 and prior GIF handling buffer overflow
- PHP 5.2.5 cURL safe_mode bypass
- [security bulletin] HPSBUX02306 SSRT071463 rev.1 - HP-UX Running ARPA Transport, Remote Denial of Service (DoS)
- UPDATED VMSA-2008-0001.1 Moderate OpenPegasus PAM Authentication Buffer Overflow and updated service console packages
- From: VMware Security team
- Web Wiz Forums Directory traversal
- Web Wiz Rich Text Editor Directory traversal + HTM/HTML file creation on the server
- Web Wiz NewsPad Directory traversal
- [ MDVSA-2008:020 ] - Updated xine-lib packages fix remote code execution vulnerabilities
- Cisco Security Advisory: Cisco PIX and ASA Time-to-Live Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- Cisco Security Advisory: Default Passwords in the Application Velocity System
- From: Cisco Systems Product Security Incident Response Team
- Syhunt: HFS (HTTP File Server) Template Cross-Site Scripting and Information Disclosure Vulnerabilities
- Syhunt: HFS (HTTP File Server) Log Arbitrary File/Directory Manipulation and Denial-of-Service Vulnerabilities
- Syhunt: HFS (HTTP File Server) Username Spoofing and Log Forging/Injection Vulnerability
- RE: Cisco Security Advisory: Cisco PIX and ASA Time-to-Live Vulnerability
- Woltlab Burning Board 2.3.6 PL2 Remote Delete Thread XSRF Vulnerability
- [SECURITY] [DSA 1474-1] New exiv2 packages fix arbitrary code execution
- [ GLSA 200801-10 ] TikiWiki: Multiple vulnerabilities
- [SECURITY] [DSA 1444-2] New php5 packages fix regression
- PIX Privilege Escalation Vulnerability
- [ MDVSA-2008:025 ] - Updated x11-server-xgl packages fix multiple vulnerabilities
- ImageShack Toolbar FileUploader Class insecurities
- [ MDVSA-2008:021 ] - Updated XFree86 packages fix multiple vulnerabilities
- [ MDVSA-2008:022 ] - Updated xorg-x11 packages fix multiple vulnerabilities
- [ MDVSA-2008:023 ] - Updated x11-server packages fix multiple vulnerabilities
- [ MDVSA-2008:024 ] - Updated libxfont packages fix font handling vulnerability
- Re: PIX Privilege Escalation Vulnerability
- Tiger PHP News System SQL Injection
- iDefense Security Advisory 01.23.08: IBM AIX pioout BSS Buffer Overflow Vulnerability
- rPSA-2008-0029-1 bind bind-utils
- From: rPath Update Announcements
- rPSA-2008-0030-1 CherryPy
- From: rPath Update Announcements
- iDefense Security Advisory 01.22.08: IBM Tivoli PMfOSD HTTP Request Method Buffer Overflow Vulnerability
- phpBB 2.0.22 Remote PM Delete XSRF Vulnerability
- Re: Re: PIX Privilege Escalation Vulnerability
- Pre Hotel and Resorts reservation portal login bypass
- E-SMART CART bypass
- Pre Dynamic Institution bypass
- [CandyPress] eCommerce suite (SQL Injection + XSS + Path Disclosure)
- gdb bug
- C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Authentication Vulnerability
- C4 Security Advisory - GE Fanuc Cimplicity 6.1 Heap Overflow
- C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Arbitrary File Upload and Execution
- Re: Peers static overflow in BitTorrent 6.0 and uTorrent 1.7.5
- [ MDVSA-2008:026 ] - Updated icu packages fix vulnerabilities
- Re: PIX Privilege Escalation Vulnerability
- Two vulnerabilities for PatchLink Update Client for Unix.
- [ MDVSA-2008:027 ] - Updated pulseaudio packages fix local root vulnerability
- [SECURITY] [DSA 1475-1] new gforge packages fix cross site scripting
- Tool availability - browser DOM Checker
- F5 BIG-IP Web Management ASM Security Report XSS
- PhPress-0.3.0 Read All Sql Information For Config
- phpIP 4.3.2 - Numerous SQL Injection Vulnerablities
- Metasploit Framework v3.1 Released
- [SECURITY] [DSA 1476-1] New pulseaudio packages fix privilege escalation
- Mambo 4.6.3 Path Disclosure, XSS , XSRF, DOS
- [ GLSA 200801-14 ] Blam: User-assisted execution of arbitrary code
- [ GLSA 200801-11 ] CherryPy: Directory traversal vulnerability
- Facebook security contact
- ClanSphere 2007.4.4 Remote File Disclosure Vulnerability.
- [SECURITY] [DSA 1477-1] New yarssr packages fix arbitrary shell command execution
- eTicket 'index.php' Cross Site Scripting Path Vulnerability
- Re: Simple Machines Forum Cross-Site Scripting Vulnerabilities
- Re: OneCMS Vulnerabilities
- [ GLSA 200801-13 ] ngIRCd: Denial of Service
- [ GLSA 200801-12 ] xine-lib: User-assisted execution of arbitrary code
- ASPired2Protect bypass
- WoltLab Burning Board 3.x.x Private Message Delete XSRF Vulnerability
- CORE-2007-1219: Firebird Remote Memory Corruption
- From: Core Security Technologies Advisories
- VB Marketing "tseekdir.cgi" Local File Inclusion
- Uninformed Journal Release Announcement: Volume 9
- [SECURITY] [DSA 1478-1] New mysql-dfsg-5.0 packages fix several vulnerabilities
- Re: Exploit in IE6,7
- Advisory: Tripwire Enterprise/Server XSS Vulnerability
- From: Liquidmatrix Security Digest
- Re: C4 Security Advisory - GE Fanuc Cimplicity 6.1 Heap Overflow
- Re: C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Arbitrary File Upload and Execution
- Re: C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Authentication Vulnerability
- [ GLSA 200801-15 ] PostgreSQL: Multiple vulnerabilities
- CSRF/XSS in Sungard Banner
- Remote File Disclosure in phpCMS 1.2.2
- From: Digital Security Research Group
- Nucleus 3.31 XSS in path
- From: Digital Security Research Group
- PHPKIT 1.6.4 PL1 2 XSRF Vulnerabilities
- [!!FIX Information ] Nucleus 3.31 XSS in path
- From: Digital Security Research Group
- Re: Remote File Disclosure in phpCMS 1.2.2
- AmpJuke-0.7.0 (index.php) Xss VuLn.
- Insecure Use of RC4 in LSrunasE and Supercrypt (CVE-2007-6340)
- From: Daniel Roethlisberger
- Recent Web Hacks: WHID update for Janury 30th 2008
- tinyBB v0.2 Message Board Remote File Inc.
- [waraxe-2008-SA#065] - Remote Shell Command Execution in Coppermine 1.4.14
- Webspell 4.01.02 2 Vulnerabilites
- [ GLSA 200801-16 ] MaraDNS: CNAME Denial of Service
- [ GLSA 200801-17 ] Netkit FTP Server: Denial of Service
- [ MDVSA-2008:028 ] - Updated MySQL packages fix multiple vulnerabilities
- Yeşil Koridor Ziyareti Defteri (index.php) SqL. inj.
- RE: Recent Web Hacks: WHID update for Janury 30th 2008
- Cisco Security Advisory: Cisco Wireless Control System Tomcat mod_jk.so Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- PeteFinnigan.com Limited advisory for Oracle January 2008 CPU
- rPSA-2008-0032-1 xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs
- From: rPath Update Announcements
- [ GLSA 200801-20 ] libxml2: Denial of Service
- [ GLSA 200801-19 ] GOffice: Multiple vulnerabilities
- [ GLSA 200801-18 ] Kazehakase: Multiple vulnerabilities
- [ GLSA 200801-21 ] Xdg-Utils: Arbitrary command execution
- [ GLSA 200801-22 ] PeerCast: Buffer overflow
- contactforms "cforms-css.php" Remote File Inclusion
Mail converted by MHonArc