|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
655 messages sorted by: [ author ] [ date ] [ thread ]
Starting: Tue Jun 06 2006 - 10:48:45 CDT
Ending: Fri Jun 30 2006 - 14:49:26 CDT
- # MHG Security Team --- MyBloggie 2.1.1 version Remote File Include Vulnerabilit
- # MHG Security Team --- PHORUM 5.1.13 Remote File Inc.
- # MHG Security Team --- PHPAskIt v2.0.1 Remote File Inc.
- 'Multiple Sql injection and XSS in integramod portal
- 0verkill 0.6, Remote integer overflow
- 43things.com - XSS with cookie disclosure
- 5 Star Review - review-script.com - XSS w/ cookie output
- [ GLSA 200606-01 ] Opera: Buffer overflow
- [ GLSA 200606-02 ] shadow: Privilege escalation
- [ GLSA 200606-03 ] Dia: Format string vulnerabilities
- [ GLSA 200606-04 ] Tor: Several vulnerabilities
- [ GLSA 200606-05 ] Pound: HTTP request smuggling
- [ GLSA 200606-06 ] AWStats: Remote execution of arbitrary code
- [ GLSA 200606-07 ] Vixie Cron: Privilege Escalation
- [ GLSA 200606-08 ] WordPress: Arbitrary command execution
- [ GLSA 200606-09 ] SpamAssassin: Execution of arbitrary code
- [ GLSA 200606-10 ] Cscope: Many buffer overflows
- [ GLSA 200606-11 ] JPEG library: Denial of Service
- [ GLSA 200606-12 ] Mozilla Firefox: Multiple vulnerabilities
- [ GLSA 200606-13 ] MySQL: SQL Injection
- [ GLSA 200606-14 ] GDM: Privilege escalation
- [ GLSA 200606-15 ] Asterisk: IAX2 video frame buffer overflow
- [ GLSA 200606-16 ] DokuWiki: PHP code injection
- [ GLSA 200606-17 ] OpenLDAP: Buffer overflow
- [ GLSA 200606-18 ] PAM-MySQL: Multiple vulnerabilities
- [ GLSA 200606-19 ] Sendmail: Denial of Service
- [ GLSA 200606-20 ] Typespeed: Remote execution of arbitrary code
- [ GLSA 200606-21 ] Mozilla Thunderbird: Multiple vulnerabilities
- [ GLSA 200606-22 ] aRts: Privilege escalation
- [ GLSA 200606-23 ] KDM: Symlink vulnerability
- [ GLSA 200606-24 ] wv2: Integer overflow
- [ GLSA 200606-25 ] Hashcash: Possible heap overflow
- [ GLSA 200606-26 ] EnergyMech: Denial of Service
- [ GLSA 200606-27 ] Mutt: Buffer overflow
- [ GLSA 200606-28 ] Horde Web Application Framework: XSS vulnerability
- [ GLSA 200606-29 ] Tikiwiki: SQL injection and multiple XSS vulnerabilities
- [ GLSA 200606-30 ] Kiax: Arbitrary code execution
- [ MDKSA-2006:095 ] - Updated libtiff packages fixes tiffsplit vulnerability
- [ MDKSA-2006:096 ] - Updated openldap packages fixes buffer overflow vulnerability.
- [ MDKSA-2006:097 ] - Updated MySQL packages fixes SQL injection vulnerability.
- [ MDKSA-2006:098 ] - Updated postgresql packages fixes SQL injection vulnerabilities.
- [ MDKSA-2006:099 ] - Updated freetype2 packages fixes multiple vulnerabilities.
- [ MDKSA-2006:099-1 ] - Updated freetype2 packages fixes multiple vulnerabilities.
- [ MDKSA-2006:100 ] - Updated gdm packages fix vulnerability
- [ MDKSA-2006:101 ] - Updated squirrelmail packages fix vulnerabilities
- [ MDKSA-2006:102 ] - Updated libtiff packages fixes tiff2pdf vulnerability
- [ MDKSA-2006:103 ] - Updated spamassassin packages fix vulnerability
- [ MDKSA-2006:104 ] - Updated sendmail packages fix remotely exploitable vulnerability
- [ MDKSA-2006:105 ] - Updated kdebase packages fix local vulnerability in kdm
- [ MDKSA-2006:106 ] - Updated mdkkdm packages fix local vulnerability
- [ MDKSA-2006:107 ] - Updated arts packages fix vulnerability in artswrapper
- [ MDKSA-2006:108 ] - Updated xine-lib packages fix buffer overflow vulnerabilities
- [ MDKSA-2006:109 ] - Updated wv2 packages fix vulnerability
- [ MDKSA-2006:110 ] - Updated gnupg packages fix vulnerability
- [ MDKSA-2006:111 ] - Updated MySQL packages fixes authorized user DoS(crash) vulnerability.
- [ MDKSA-2006:112 ] - Updated gd packages fix DoS vulnerability.
- [ MDKSA-2006:113 ] - Updated tetex packages fix embedded GD vulnerabilities
- [ MDKSA-2006:114 ] - Updated libwmf packages fixes embedded GD vulnerability
- [ MDKSA-2006:115 ] - Updated mutt packages fix buffer overflow vulnerability
- [Bugtraq ID: 17909] ISPConfig Session.INC.PHP Remote File Include Vulnerability
- [ECHO_ADV_33$2006] CMS Faethon 1.3.2 mainpath Remote File Inclusion
- [ECHO_ADV_34$2006] W-Agora (Web-Agora) <= 4.2.0 (inc_dir) Remote File Inclusion
- [EEYEB-20060524] Symantec Remote Management Stack Buffer Overflow
- [FLSA-2006:189137-1] Updated mozilla packages fix security issues
- [FLSA-2006:189137-2] Updated firefox package fixes security issues
- [FLSA-2006:190777] Updated X.org packages fix security issue
- [FLSA-2006:190884] Updated squirrelmail package fixes security issues
- [FLSA-2006:190941] Updated ipsec-tools package fixes security issue
- [FSA013] phpCMS 1.2.1pl2, Remote command execution
- [FSA016] ISPConfig 2.2.3, File inclusion vulnerability
- [Full-disclosure] Browser bugs hit IE, Firefox today (SANS)
- [Full-disclosure] RealVNC 4.1.1 Remote Compromise
- [Full-disclosure] Windows Software Restriction Policy Protection Bypass
- [funsec] Microsoft's Real Test with Vista is Vulnerabilities
- [HV-LOW] Microsoft NetMeeting memory corruption (Brief)
- [Info Disclosure] Diesel PHP Job Site Latest Version
- [KAPDA::#47] - Snitz Forum <= 3.4.05 SQL-Injection Vulnerability
- [KAPDA::48]CopperminePhotoGallery1.4.8~ addhit() function~ SQLinjection attack
- [KAPDA]Coppermine 1.4.8~Parameter Cleanup System ByPass~Registering Global Varables
- [KAPDA]http://myimei.com/security/2006-06-24/mybb104archive-modelight-parameter-extractionvarable-overwriting.html
- [KAPDA]MyBB 1.1.4~function_post.php~XSS Attack In URL tag
- [KAPDA]MyBB1.1.3~Option update for code buttons~Sql Injection Admin Access
- [KDE Security Advisory] KDM symlink attack vulnerability
- [Kil13r-SA-20060609-1] Daum Search Cross-Site Scripting Vulnerability
- [Kil13r-SA-20060609-2] DaNaWa Search Cross-Site Scripting Vulnerability
- [Kil13r-SA-20060609-3] DreamWiz Search Cross-Site Scripting Vulnerability
- [Kil13r-SA-20060622-1] NetSoft SmartNet 2.0 Cross-Site Scripting Vulnerability
- [Kil13r-SA-20060622-2] Namo DeepSearch 4.5 Cross-Site Scripting Vulnerability
- [Kil13r-SA-20060628] Hanaro Search Cross-Site Scripting Vulnerability
- [Kil13r-SA-20060701-1] Ahnlab Search Cross-Site Scripting Vulnerability
- [Kil13r-SA-20060701-2] MoniWiki 1.1.1 Cross-Site Scripting Vulnerability
- [Kil13r-SA-20060701-3] Massting Cross-Site Scripting Vulnerability
- [Kurdish Security # 10 ] MF Piadas 1.0 Remote File Include Vulnerability
- [Kurdish Security # 11] SiteBar Cross-Site Scripting
- [Kurdish Security # 8] DCP-Portal Remote File Include Vulnerability [Editor DHTML]
- [Kurdish Security # 9] MyMail Directory Traversal And XSS Attacking Vulnerability
- [MajorSecurity #10]i.List <= 1.5 - XSS
- [MajorSecurity #11]OpenCMS<= 6.2.1 - XSS
- [MajorSecurity #12]ZMS<= 2.9 - XSS
- [MajorSecurity #13]Cabacos Web CMS<= 3.8 - XSS
- [MajorSecurity #14]CFXe-CMS <= 2.0 - XSS
- [MajorSecurity #17] SixCMS <= 6 - Multiple XSS and directory traversal vulnerabilities
- [MajorSecurity #18] Ralf Image Gallery <=0.7.4 - Multiple XSS, Remote File Include and directory traversal vulnerabilities
- [MajorSecurity #8]DreamAccount <= 3.1 - Remote File Include Vulnerability
- [NOBYTES.COM: #12] ViArt Shop v2.5.5 - XSS Vulnerability
- [OpenPKG-SA-2006.010] OpenPKG Security Advisory (gnupg)
- [OpenPKG-SA-2006.011] OpenPKG Security Advisory (png)
- [REVERSEMODE ADVISORY] MS06-030 - Microsoft Mrxsmb.sys privilege escalation advisory
- [REVERSEMODE ADVISORY] MS06-030 NtClose DeadLock.
- [security bulletin] HPSBMA02121 SSRT061157 rev.2 - HP OpenView Storage Data Protector Remote Arbitrary Command Execution
- [security bulletin] HPSBTU02116 SSRT061135 rev.2 - HP Tru64 UNIX and HP Internet Express for Tru64 UNIX Running sendmail, Remote Execution of Arbitrary Code or Denial of Service (DoS)
- [security bulletin] HPSBTU02125 SSRT061105 rev.1 - HP Tru64 UNIX Running Perl 5.8.2 and earlier, Local Unauthorized Code Execution
- [security bulletin] HPSBUX02090 SSRT051058 rev.2 - HP-UX Secure Shell Remote Denial of Service (DoS)
- [security bulletin] HPSBUX02115 SSRT061077 rev.1 - HP-UX running Support Tools Manager (xstm, cstm, stm) Local Denial of Service (DoS)
- [security bulletin] HPSBUX02122 SSRT061158 rev.2 - HP-UX Mozilla Remote Execution of Arbitrary Code, Denial of Service (DoS)
- [security bulletin] HPSBUX02127 SSRT051056 - rev.1 HP-UX Kernel Local Denial of Service (DoS)
- [SECURITY] [DSA 1090-1] New spamassassin packages fix remote command execution
- [SECURITY] [DSA 1091-1] New TIFF packages fix arbitrary code execution
- [SECURITY] [DSA 1092-1] New MySQL 4.1 packages fix SQL injection
- [SECURITY] [DSA 1093-1] New xine-ui packages fix denial of service
- [SECURITY] [DSA 1094-1] New gforge packages fix cross-site scripting
- [SECURITY] [DSA 1095-1] New freetype packages fix several vulnerabilities
- [SECURITY] [DSA 1096-1] New webcalendar packages fix arbitrary code execution
- [SECURITY] [DSA 1097-1] New Kernel 2.4.27 packages fix several vulnerabilities
- [SECURITY] [DSA 1098-1] New horde3 packages fix cross-site scripting
- [SECURITY] [DSA 1099-1] New horde2 packages fix cross-site scripting
- [SECURITY] [DSA 1100-1] New wv2 packages fix integer overflow
- [SECURITY] [DSA 1101-1] New courier packages fix denial of service
- [SECURITY] [DSA 1102-1] New pinball packages fix privilege escalation
- [SECURITY] [DSA 1103-1] New Linux kernel 2.6.8 packages fix several vulnerabilities
- [SECURITY] [DSA 1104-1] New OpenOffice.org packages fix several vulnerabilities
- [SNS Advisory No.88] Webmin Directory Traversal Vulnerability
- [USN-288-2] PostgreSQL server/client vulnerabilities
- [USN-288-3] PostgreSQL client vulnerabilities
- [USN-288-4] dovecot regression fix
- [USN-289-1] tiff vulnerabilities
- [USN-291-1] FreeType vulnerabilities
- [USN-292-1] binutils vulnerability
- [USN-293-1] gdm vulnerability
- [USN-294-1] courier vulnerability
- [USN-295-1] xine-lib vulnerability
- [USN-296-1] firefox vulnerabilities
- [USN-297-1] Thunderbird vulnerabilities
- [USN-297-2] Thunderbird extensions update for recent security update
- [USN-298-1] libgd2 vulnerability
- [USN-299-1] dhcdbd vulnerability
- [USN-300-1] wv2 vulnerability
- [USN-301-1] kdm vulnerability
- [USN-303-1] MySQL vulnerability
- [USN-304-1] gnupg vulnerability
- [USN-305-1] OpenLDAP vulnerability
- [USN-306-1] MySQL 4.1 vulnerability
- [USN-307-1] mutt vulnerability
- About.com - XSS with cookie disclosure
- ADVISORY - D-Link Wireless Access-Point
- Advisory: Authentication bypass in phpBannerExchange
- Advisory: Unauthorized password recovery in phpBannerExchange
- aeDating 4.1 XSS
- alipager xss attack
- Amazon and Msn vulnerabilities
- Amazon, MSN vulns and.. Yes, we know! Most sites have vulnerabilities
- Amr Talkbox talkbox.PHP - Remote File Include Vulnerabilities
- Andys Chat 4.5 (action) Remote File Inclusion
- animesuki XSS
- APBoard 2.2-r3 <= SQL Injections
- Apnaspace.com - XSS with cookie disclosure
- Ashop Search Module SQL injection
- AsianXO.com - XSS with cookie data include
- Asterisk 1.2.9 and Asterisk 1.0.11 Released - Security Fix
- aWebNews <= 1.0 (login.php) Remote DocumentRoot file disclosure
- aXentForum II XSS vuLLn
- AzDGDatingPlatinum<<--v1.1.0 "view.php" SQL Injection
- B3ta.com - XSS with cookie disclosure
- Babykatmedia.com scripts - vSCAL & vREAL - XSS Vulns
- Back-end = 0.7.2.1 (jpcache.php) Remote command execution
- bbrss PhpBB (phpbb_root_path) Remote File Inclusion
- Biblenet.net - XSS
- Bingbox.com - XSS & cookie disclosure
- bitweaver <= v1.3 multiple vulnerabilities
- Black Hat Speakers + 2005 Content on-line
- Blackplanet.com - XSS & cookie disclosure vuln.
- Blacksingles.com - XSS & cookie disclosure
- BLOG:CMS <= 4.0.0k sql injection
- BloggIT <= 1.01 (admin.php) Arbitrary code execution
- Blogspot.com - XSS with cookie disclosure
- blur6ex <= 0.3.462 'ID' blind sql injection
- Boardhost.com - XSS
- Browser bugs hit IE, Firefox today (SANS)
- Buffer-overflow and crash in Fenice OMS 1.10
- bug of script injection in shoutcast servers
- bug on showwich.asp
- BUGTRAQ:20060611 ThWboard 3.0 <= SQL Injection
- Bypassing of web filters by using ASCII
- CAID 34325 - CA ITM, eAV, ePP scan job description field format string vulnerability
- Calendar ( Provided by Codewalkers ) - SQL Injection
- Calendar Express 2 SQL injection
- Calendarix 0.7.20060401, SQL Injection Vulnerabilities
- Call For Papers - No cON Name 2006 Edition Spain
- Carspace.com - XSS with cookie disclosure
- CDJ<<--V NITKID 2.0 "category.php" SQL Injection
- cescripts.com - XSS
- Chatizens.com - XSS with cookie disclosure
- Chemical Directory - XSS
- Chipmailer <= 1.09 Multiple Vulnerabilities
- Cisco Secure ACS Cross Site Scripting Vulnerability.
- Cisco Secure ACS Weak Session Management Vulnerability
- Cisco Security Advisory: Access Point Web-Browser Interface Vulnerability
- Cisco Security Advisory: Multiple Vulnerabilities in Wireless Control System
- cjGuestbook v1.3 - XSS
- Claroline Cross-Site Scripting Vulnerabilities
- Cline Communications Sql injection
- cms-bandits 2.5, Remote command execution
- Confixx <= 3
- Contensis CMS XSS vunerability
- Content-Builder (CMS) 0.7.5, Remote command execution
- CORE-2006-0327: IAXclient truncated frames vulnerabilities
- CORE-2006-0330: Asterisk PBX truncated video frame vulnerability
- CrisoftRicette<<--1.0pre15b Remote File Inclusion
- CS-Forum <= 0.81 Cross Site Scripting, SQL Injection, Full Path Disclosure
- CSRF in Nuked Klan 1.7 SP4.2
- Cybersocieties.com - XSS & cookie disclosure
- Dating Agent PRO 4.7.1 Vulnerability
- Dating biz<img src="/imgs/at.gif" border=0 align=middle> dating script v1.0 - XSS
- DCP-Portal 6.1.x, Remote command execution
- Dealgates.com - XSS with cookie disclosure
- Dell Openmanage CD Vulnerability
- DeluxeBB 1.07 Create admin Exploit
- Develooping Flash Chat (banned_file) Remote File Inclusion
- DGbook v1.0 - XSS
- Diaryland.com - XSS
- Digital Armaments July-August Hacking Challange: Microsoft
- Digital Armaments Security Advisory 29.06.2006: Siemens Speedstream Wireless Router Password Protection Bypass Vulnerability
- display.cgi
- DMA[2006-0628a] - 'Apple OSX launchd unformatted syslog() vulnerability'
- Docebo CMS 3.0.3, Remote command execution
- Docebo Core 3.0.3, Remote command execution
- Docebo Kms 3.0.3, Remote command execution
- Docebo Lms 3.0.3, Remote command execution
- Dragons Kingdom v1.0 - XSS & cookie disclosure
- DREAMACCOUNT V3.1 Remote Command Execution Exploit
- dvdwolf SQL injection/XSS
- E-Dating System from scriptsez.net - XSS
- e107 v0.7.5 XSS
- Easy Ad-Manager
- Easy CMS 0.1.2 Php Shell Upload Vulnerabilities
- EC2ND - Call for Papers
- Eduha Meeting php shell upload Vulnerabilities
- Emllabs.com - XSS
- ePrayver v.Alpha - XSS
- ERNW Security Advisory 01/2006
- ERRATA: [ GLSA 200604-10 ] zgv: Heap overflow
- error_log() Safe Mode Bypass PHP 5.1.4 and 4.4.2
- Excel 0-day FAQ updated with Microsoft advisory information
- Ez Ringtone Manager from scriptez.net - XSS
- ezWaiter v3.0 - XSS
- Facerave.com - XSS & sessions disclosure
- Facetherating.com - XSS & session disclosure
- file include exploits in dotwidgeta Version 2
- file include exploits in mcGuestbook 1.3
- file include exploits in nucleus 3.23
- file include in Xtreme Downloads v.1.0
- Files and cvars overwriting in Quake 3 engine (1.32c / rev 803 / ...)
- Fire fox dos exploit
- Flipper Poll (root_path) Remote File Inclusion
- flock d0s exploit remote. beta 1 (v0.7)
- Flork.com
- Foing (manage_songs.php) Remote File Inclusion[phpBB]
- FreeBSD Security Advisory FreeBSD-SA-06:17.sendmail
- FreeHost "misc.php & news.php" SQL Injection
- Freeze Greetings Cards PWD.txt
- Fusion Polls (xtrphome) Remote File Inclusion
- fx-APP Version 0.0.8.1
- G Shout 1.3.1 Version - Remote File Include Vulnerability
- GamePlay.co.uk XSS
- GANTTy v1.0.3
- GlobeTrotter Mobility Manager - security issue
- GreatDomains.com - XSS with cookie disclosure
- GUESTEX guestbook code execution
- hi5.com - XSS with cookie disclosure
- High Risk Vulnerability in Microsoft Windows RASMAN Service
- Hobbit monitor: Security issue with Hobbit 4.2-beta client
- Hotbot.com - XSS vulnerability in search engine
- HotPlugCMS 1.0, Cross-Site Scripting Vulnerabilities
- HotPlugCMS_1.0 - SQL Injection Vulnerability
- Hotscripts.com - XSS with cookie disclosure
- Housecarers.com - XSS & cookie disclosure
- iDefense Security Advisory 06.13.06: Microsoft Internet Explorer ART File Heap Corruption Vulnerability
- iDefense Security Advisory 06.13.06: Windows Media Player PNG Chunk Decoding Stack-Based Buffer Overflow
- iDefense Security Advisory 06.13.06: Windows MRXSMB.SYS MrxSmbCscIoctlCloseForCopyChunk DoS
- iDefense Security Advisory 06.13.06: Windows MRXSMB.SYS MRxSmbCscIoctlOpenForCopyChunk Overflow
- Ie opera dos exploit
- iFoto v0.20-06/06/06
- igloo DoubleSpeak v 0.1 Multiple remote file inclusion
- Indexu v 5.0.01 Multiple Remote File Include Vulnerabilities
- Input Validation/Output Encoding Vulnerabilities in Cisco CallManager Allow Script Injection Attacks
- internet explorer vulnerability based on MarjinZ & Mr.Niega discovered
- Internet Explorer vulnerbility
- Invision Power Board XSS
- IRM 019: MailMarshal 6.1 SMTP MTA Content Filter Bypass
- Is Windows TCP/IP source routing PoC code available?
- ISC: Firefox immune to outerHTML flaw in MSIE [Was: Browser bugs hit IE, Firefox]
- ISO.org - XSS vulnerability
- Janus Contact
- Jaws <= 0.6.2 'Search gadget' SQL injection
- JEdit ActiveX Control Information Disclosure vulnerability
- Ji-takz Chat (mycfg) Remote File Inclusion
- Jobline 1 1 1 Version - Remote File Include Vulnerability
- Joomla! 1.0 Remote File Inclusion
- Layered Defense Advisory: Format String Vuln in CA eTrust
- libgd 2.0.33 infinite loop in GIF decoding ?
- libwmf integer/heap overflow
- Linux VNC evil client patch - BID 17978
- Ltwcalendar 4.1.3 version - Remote File Include Vulnerabilities
- Lycos.com - XSS vulnerability
- Macworld.com - XSS vulnerability
- Mafia Moblog Full Path Disclosure / SQL injection
- Mailenable SMTP Service DoS
- Mambo <= 4.6rc1 sql injection
- Mathcad Area Lock Vulnerability
- MAXDEV CMS Multiple vulnerabilities
- Meefo.com - XSS with cookie include
- Microsoft Excel 0-day Vulnerability FAQ document written
- Microsoft's Real Test with Vista is Vulnerabilities
- MiraksGalerie <= 2.62 Multiple Remote command execution
- MKPortal 1.0.1 Final ($ind) File Include Vulnerability (perl)
- MobeSpace v2.0 - XSS
- Module's Name "Classifieds" SQL Injection
- Module's Name Content<<--V1.0 SQL injection
- Module's Name Downloads <<--V 7 SQL injection
- mole.com.ua Booking Script
- mole.com.ua Ticket Booking Script - XSS
- MP3 Search/Archive v1.2 - XSS
- mp3.com - Cross site scripting vulnerability
- MPCS v0.2 - XSS
- MS Excel Remote Code Execution POC Exploit
- Msie 7.0 beta Crash
- Multiple Bypass and Integrity Lost Vulnerabilities
- Multiple file include exploits in Xtreme Downloads v.1.0
- Multiple Vendor NTFS Data Stream Malware Stealth Technique
- Multiple Vulnerabilities in PatchLink Update Server 6
- multiple Xss exploits in 35mmslidegallery V6
- My smiles "browse.php" SQL Injection
- MyBB 1.1.2 New XSS
- Mydeardiary.com - XSS
- MyNewsGroups<<--v. 0.6 "tree.php" SQL Injection
- myPHP Guestbook 2.0.2 XSS Vulnerabilitie
- Myscrapbook v3.1 - XSS
- MySQL DoS
- Netscape.com - Cross site scripting vulnerability
- Novell Security Announcement NOVELL-SA:2006:001
- Novell Security contact address change
- Nowtalking.com - XSS
- NPDS <= 5.10 Local Inclusion, XSS, Full path disclosure
- okscripts.com - XSS Vulns
- onedotoh xss atack
- Onlinenode.com - XSS
- Opengaia.com - XSS Vuln & Session Include
- OpenGuestbook Cross Site Scripting & SQL Injection
- Opera 9 DoS PoC
- Oracle DBMS_STANDARD security problem
- P.A.I.D v2.2
- PaintedOver.com, Inc. 2004-2006 Xss Vulnerabilities
- Palm.com - XSS vulnerability
- Partial Links v1.2.2
- Particle Gallery v1.0.0
- ParticleSoft Whois v1.0.3
- ParticleSoft Wiki v1.0.2
- PBL Guestbook v1.31 - XSS
- phazizGuestbook v2.0 - XSS
- PHP Advanced Transfer Manager Download users password hashes
- PHP iCalendar Cross Site Scripting
- PHP Live Helper <=([abs_path]) Remote File Include Vulnerabilities
- PHP MESSENGER 1.0 Version - Remote File Include Vulnerability
- PHP security (or the lack thereof)
- PHP-Nuke <= 7.9 Search XSS Vulnerability
- PHP-Nuke Download Module Remote SQL Injection
- PHP-Nuke Module's Name Sections<<--V3 SQL Injection
- phpBannerExchange 2.0 Directory Traversal Vulnerability
- phpBB2 (template.php) Remote File Inclusion
- phpBlueDragon CMS 2.9.1 multiple remote file inclusion vuln
- PhpBlueDragon CMS 2.9.1, File inclusion vulnerability
- PHPClassifieds General
- PhpMyFactures 1.0 Cross Site Scripting, SQL Injection, Full Path Disclosure and others
- phpvillage "funshow.php" SQL Injection
- PictureDis Products "lang" Parameter File Inclusion Vulnerability
- Planetnews Authecnication Admin ByPass
- possible SQL injection in Subdreamer
- Presentation: AT&T ISNN - "Case Studies in Finding Previously Unknown Vulnerabilities in Web Applications."
- productcart soltan_defacer
- Proof of concept: mybb 1.1.2 remote code execution
- PTT.yu Guestbook Vulnebility
- QaTraq 6.5 RC: Multiple XSS Vulnerabilities
- qtofilemanager xss attack !
- RahnemaCo "page.php" Remote File Inclusion[2]
- RahnemaCo Remote File Inclusion Exploit
- Ratemylook.co.uk - XSS with session disclosure
- Ratescene.co.uk - XSS with session disclosure
- RCblog 1.03 Directory Traversal [index.php]
- Regarding "SMB Invalid Handle Value" - MS06-030. Vulnerability not fixed.
- REMOTE FILE INCLUSION ( ALL )
- Ringlink v3.2 - XSS
- rPSA-2006-0096-1 spamassassin
- rPSA-2006-0098-1 gdm
- rPSA-2006-0099-1 openldap openldap-clients openldap-servers
- rPSA-2006-0100-1 freetype
- rPSA-2006-0105-1 arts
- rPSA-2006-0106-1 kdebase
- rPSA-2006-0110-1 kernel
- rPSA-2006-0116-1 mutt
- rPSA-2006-0120-1 gnupg
- S H O U T B O X (v1.5) Version - Remote File Include Vulnerability
- SaphpLesson<<--1.1 "misc.php" SQL injection
- SEC Consult SA-20060613-0 :: Outlook Web Access Cross Site Scripting Vulnerability
- Secunia Resaerch: Internet Explorer Exception Handling Memory Corruption Vulnerability
- Secunia Research: AutoMate unacev2.dll Buffer Overflow Vulnerability
- Secunia Research: CMS Mundo SQL Injection and File Upload Vulnerabilities
- Secunia Research: DeluxeBB SQL Injection and File Inclusion Vulnerabilities
- Secunia Research: MyBB "domecode()" PHP Code Execution Vulnerability
- Secunia Research: Opera SSL Certificate "Stealing" Weakness
- Secunia Research: phpRaid SQL Injection and File Inclusion Vulnerabilities
- Secunia Research: PicoZip "zipinfo.dll" Multiple Archives Buffer Overflow
- Secunia Research: PicoZip "zipinfo.dll" Multiple Archives BufferOverflow
- Secunia Research: SelectaPix Cross-Site Scripting and SQL Injection Vulnerabilities
- Sendmail MIME DoS vulnerability
- Several flaws in e-business designer (eBD)
- Shoutpro 1.0 Version - Remote File Include Vulnerability
- Simple PHP Poll Authecnication Admin ByPass
- Simpleshout 1.6.0 Version - Remote File Include Vulnerability
- Simpnews <= All version - Remote File Include Vulnerabilities
- SinFP 2.00 - a major release with many new features
- singapore gallery <= 0.10.0 Multiple Vulnerabilities
- smartsite cms v1.0 Remote File include
- Softbiz Banner Exchange 1.0 XSS
- Softbiz Dating 1.0 SQL injection
- Somechess v1.5 rc1 - XSS
- sorry i wrong something, this is original AWF CMS 1.11 adv
- Squirrelmail local file inclusion
- SSL VPNs and security
- ST AdManager Lite v1
- Stargazer.org - XSS with Session output
- SUSE Security Announcement: freetype2 (SUSE-SA:2006:037)
- SYMSA-2006-004: Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution
- SYMSA-2006-005
- SYMSA-2006-006: Lotus Domino SMTP Based Denial of Service
- SyScan'06 Highlight - Is Phone Banking Safe?
- Taking Over Laptops by Fuzzing Wireless Drivers
- Technorati.com - XSS with cookie disclosure
- Tempinbox.com
- tempnam() Bypass unique file name PHP 5.1.4
- ThWboard 3.0 <= SQL Injection
- Tikiwiki 1.9.3.2 security release
- TikiWiki Sql injection & XSS Vulnerabilities
- Tiny Web Gallery <= 1.4 XSS
- TinyMuw v1.0 - XSS
- TinyPHP forum <= 3.6 Remote Command Execution Exploit
- Trend Micro Control Manager (TMCM) Persistent XSS Vulnerability
- trifinite Security Advisory: Buffer Overrun in Toshiba Bluetooth Stack for Windows
- TSLSA-2006-0034 - multi
- TSLSA-2006-0036 - multi
- TSLSA-2006-0037 - multi
- ULtimate PHP Board <= 1.96 GOLD Code Execution (exploit code)
- Undisclosed cross site scripting vulnerabilities in domaintools.com - requesting contacts
- Uninformed Journal Release Announcement: Volume 4
- Universal Hooker - Tool release
- Usenet Script v0.5
- V3Chat Instant Messenger - XSS
- Vacation Retal Script v1.0
- VampireFreaks journal XSS
- Vampirefreaks.com - XSS with cookie disclosure
- vbulletin.com Multiple XSS Vulnerabilities
- vBulletin<<--v3.5.X "member.php" Cross Site Scripting
- VBZooM <<-- V1.11 "show.php" SQL injection
- VBZooM <<--V1.00 "lng.php" SQL injection
- VBZooM <<--V1.00 "rank.php" SQL injection
- VBZooM <<--V1.01 "language.php" SQL injection
- VBZooM <<--V1.02 "meaning.php" SQL injection
- VBZooM <<--V1.11 "message.php" SQL injection
- VBZooM <<--V1.11 "subject.php" SQL injection
- vbzoom V1.11 forum.php SQL Injection Vulnerabilities
- vCard PRO SQL Injection
- Vice Stats 0.5b SQL injection
- VigilantMinds Advisory: Opera JPEG Processing Integer Overflow Vulnerability (VMSA-20060621-01)
- Virtualtourist.com - XSS with cookie disclosure
- vlbook 1.2 XSS Bug
- Vm ware 0day dos exploit by n00b.
- vuBB <= 0.2.1 [BFA] SQL Injection Exploit + Advisory link
- Wanderlist.com - XSS vuln with sessions disclosure
- WBB<<---v1.2 "showmods.php" SQL Injection
- WBB<<---v2.0 RC2 "newthread.php" SQL Injection
- WBB<<---v2.3.1"report.php" SQL Injection
- wbb<<--v 2.1.6 "profile.php" SQL injection
- wbb<<--v 2.2.1 "studienplatztausch.php" SQL injection
- wbb<<--v 2.2.2 "thread.php" SQL injection
- Web-CMS <<--1.0 "print.php" SQL injection
- WeBBoA Hosting Script SQL Injection
- WebCalendar-1.0.3 reading of any files
- webcrawler.com - Cross site scripting vulnerability
- webcrawler.com - XSS vulnerability in search-engine
- Windows Live Messenger 8.0 ( Contact List *.ctt ) Heap Overflow
- Windows Software Restriction Policy Protection Bypass
- Windows XP Task Scheduler Local Privilege Escalation (Advisory)
- Windowsitpro.com - XSS with cookie disclosure
- Winged Gallery v1.0
- WinSCP - URI Handler Command Switch Parsing
- Wireclub.com - XSS & cookie disclosure
- XSS in Cpanel 10
- XSS in GardenWeb
- XSS in http://www.newscientist.com/ - Search
- XSS in ICQ.com
- XSS on LarkinWEB & Company
- XSS Vulnerability in Maximus SchoolMAX
- Yourfacesucks.com - XSS & cookie disclosure
- Youtube.com - XSS & cookie disclosure
- ZDI-06-017: Microsoft Internet Explorer UTF-8 Decoding Heap Overflow Vulnerability
- ZDI-06-018: Microsoft Internet Explorer DXImageTransform ActiveX Memory Corruption Vulnerability
- ZDI-06-020: Apple iTunes AAC File Parsing Integer Overflow Vulnerability
- Zen-Cart 1.3.0.2 Full Path Disclosure
- Zeroboard File Upload & extension bypass Vulnerability
Last message date: Fri Jun 30 2006 - 14:49:26 CDT
Archived on: Fri Jun 30 2006 - 14:49:27 CDT
655 messages sorted by: [ author ] [ date ] [ thread ]
phorum.org