|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
565 messages sorted by: [ author ] [ date ] [ thread ]
Starting: Sat Jul 01 2006 - 14:37:23 CDT
Ending: Mon Jul 31 2006 - 18:58:53 CDT
- # MHG Security Team --- PHPAskIt v2.0.1 Remote File Inc.
- $100 plus several of my books if you can crack my Windows password hashes.
- 23rd Chaos Communication Congress 2006: Call for Participation
- 5 php scripts remote database password disclosure
- [ GLSA 200607-01 ] mpg123: Heap overflow
- [ GLSA 200607-02 ] FreeType: Multiple integer overflows
- [ GLSA 200607-03 ] libTIFF: Multiple buffer overflows
- [ GLSA 200607-04 ] PostgreSQL: SQL injection
- [ GLSA 200607-05 ] SHOUTcast server: Multiple vulnerabilities
- [ GLSA 200607-06 ] libpng: Buffer overflow
- [ GLSA 200607-07 ] xine-lib: Buffer overflow
- [ GLSA 200607-08 ] GIMP: Buffer overflow
- [ GLSA 200607-09 ] Wireshark: Multiple vulnerabilities
- [ GLSA 200607-10 ] Samba: Denial of Service vulnerability
- [ GLSA 200607-11 ] TunePimp: Buffer overflow
- [ GLSA 200607-12 ] OpenOffice.org: Multiple vulnerabilities
- [ GLSA 200607-13 ] Audacious: Multiple heap and buffer overflows
- [ MDKA-2006:119 ] - Updated ppp packages fix plugin vulnerability
- [ MDKSA-2006:116 ] - Updated kernel packages fixes multiple vulnerabilities
- [ MDKSA-2006:117 ] - Updated libmms packages fix buffer overflow vulnerability
- [ MDKSA-2006:117-1 ] - Updated libmms packages fix buffer overflow vulnerability
- [ MDKSA-2006:118 ] - Updated OpenOffice.org packages fix various vulnerabilities
- [ MDKSA-2006:120 ] - Updated samba packages fix DoS vulnerability
- [ MDKSA-2006:121 ] - Updated xine-lib packages fix buffer overflow vulnerability
- [ MDKSA-2006:122 ] - Updated php packages fix multiple vulnerabilities
- [ MDKSA-2006:123 ] - Updated kernel packages fixes multiple vulnerabilities
- [ MDKSA-2006:124 ] - Updated kernel packages fix privilege escalation vulnerability
- [ MDKSA-2006:125 ] - Updated webmin packages fix arbitray file read vulnerability.
- [ MDKSA-2006:126 ] - Updated libtunepimp packages fixes buffer overflow vulnerabilities.
- [ MDKSA-2006:127 ] - Updated gimp packages fix buffer overflow vulnerability.
- [ MDKSA-2006:128 ] - Updated wireshark packages fix numerous vulnerabilities
- [ MDKSA-2006:129 ] - Updated freetype2 packages fixes overflow vulnerability.
- [ MDKSA-2006:130 ] - Updated kdelibs packages fix konqueror crash vulnerability.
- [ MDKSA-2006:131 ] - Updated perl-Net-Server packages fix format string vulnerability
- [ MDKSA-2006:132 ] - Updated libwmf packages fixes integer overflow vulnerability
- [ MDKSA-2006:133 ] - Updated apache packages fix mod_rewrite vulnerability
- [ MDKSA-2006:134 ] - Updated ruby packages fix safe-level vulnerabilities
- [Announcement] Apache HTTP Server 2.2.3 (2.0.59, 1.3.37) Released
- [ANNOUNCEMENT] Samba 3.0.1 - 3.0.22: memory exhaustion DoS against smbd
- [CYBSEC] TippingPoint detection bypass
- [ECHO_ADV_36$2006] ExtCalendar <== v2.0 Remote File Include Vulnerabilities
- [ECHO_ADV_37$2006] pc_cookbook Mambo/Joomla Component <= v0.3 Remote File Include Vulnerabilities
- [ECHO_ADV_38$2006] Multiple Mambo/Joomla Component Remote File Include Vulnerabilities
- [ECHO_ADV_40$2006] iManage CMS <= 4.0.12 (absolute_path) Remote File Inclusion
- [ECHO_ADV_41$2006] BufferOverflow in Midirecord2
- [EEYEB-20060227] D-Link Router UPNP Stack Overflow
- [FLSA-2006:175040] Updated php packages fix security issues
- [Full Disclosure] [Kil13r-SA-20060701-2] MoniWiki 1.1.1 Cross-Site Scripting Vulnerability
- [Full-disclosure] [USN-314-1] samba vulnerability
- [Full-disclosure] Browser bugs hit IE, Firefox today (SANS)
- [Full-disclosure] ERNW Security Advisory 02/2006 - Buffer Overflow in sipXtapi (used in AOL Triton)
- [Full-disclosure] iDefense Security Advisory 07.20.06: Sun Microsystems Solaris sysinfo() Kernel Memory Disclosure Vulnerability
- [KAPDA::#46] - AjaxPortal Authentication Bypass
- [KAPDA::#52] - PHP-Post 1.0 Cookie Modification Privilege Escalation Vulnerability
- [KAPDA::#53] MYBB XSS and Dir Traversal in usercp.php
- [Kurdish Security # 13] Savant2 Remote File Include Vulnerability [For Mambo, Joomla]
- [Kurdish Security # 14] MoSpray [base_dir] Remote Command Execution [ Mambo & Joomla]
- [MajorSecurity #19] AutoRank <= 5.01 - Multiple XSS and cookie disclosure
- [MajorSecurity #20]SiteDepth CMS <= 3.01 - Remote File Include Vulnerability
- [MajorSecurity #21] phpFaber TopSites <=2.0.9 - SQL Injection Vulnerability
- [MajorSecurity #22] Top XL <=1.1 - XSS and cookie disclosure
- [MajorSecurity #23] BLOG:CMS <= 4.0.0j - XSS and cookie disclosure
- [MajorSecurity #24] Fire-Mouse TopList <=v1.1 - Cross Site Scripting
- [MajorSecurity #25] Advanced Guestbook 2.4 for phpBB - Multiple XSS and SQL-Injection Vulnerabilities
- [MajorSecurity #26] Woltlab Burning Board - Multiple Cookie manipulation and session fixation vulnerabilities
- [OpenPKG-SA-2006.013] OpenPKG Security Advisory (mutt)
- [OpenPKG-SA-2006.014] OpenPKG Security Advisory (shiela)
- [OpenPKG-SA-2006.015] OpenPKG Security Advisory (apache)
- [OpenPKG-SA-2006.016] OpenPKG Security Advisory (ruby)
- [OpenPKG-SA-2006.017] OpenPKG Security Advisory (freetype)
- [scip_Advisory 2351] Kyberna AG ky2help various form fields SQL Injection
- [scip_Advisory 2352] F5 FirePass 4100 prior 6.x multiple Cross Site Scripting
- [security bulletin] HPSBMA02133 SSRT061201 rev.1 - HP Oracle for OpenView (OfO) Critical Patch Update July 2006
- [security bulletin] HPSBTU02132 SSRT061154 rev.1 - HP Tru64 UNIX running NIS ypserv, Remote Denial of Service (DoS)
- [security bulletin] HPSBUX02087 SSRT4728 rev.2 - HP-UX running TCP/IP Remote Denial of Service (DoS)
- [security bulletin] HPSBUX02103 SSRT5953 rev.3 - HP-UX passwd(1) Local Denial of Service (DoS)
- [security bulletin] HPSBUX02108 SSRT061133 rev.12 - HP-UX Running Sendmail, Remote Execution of Arbitrary Code
- [security bulletin] HPSBUX02120 SSRT051057 rev.2 - HP-UX Local Denial of Service (DoS)
- [security bulletin] HPSBUX02128 SSRT5996 - rev.1 HP-UX mkdir(1) Local Unauthorized Access
- [SECURITY] [DSA 1104-2] New OpenOffice.org packages fix arbitrary code execution
- [SECURITY] [DSA 1105-1] New xine-lib packages fix denial of service
- [SECURITY] [DSA 1106-1] New ppp packages fix privilege escalation
- [SECURITY] [DSA 1107-1] New GnuPG packages fix denial of service
- [SECURITY] [DSA 1108-1] New mutt packages fix arbitrary code execution
- [SECURITY] [DSA 1109-1] New rssh packages fix privilege escalation
- [SECURITY] [DSA 1110-1] New samba packages fix denial of service
- [SECURITY] [DSA 1111-1] New Linux kernel 2.6.8 packages fix privilege escalation
- [SECURITY] [DSA 1111-2] New Linux kernel 2.6.8 packages fix privilege escalation
- [SECURITY] [DSA 1112-1] New mysql-dfsg-4.1 packages fix denial of service
- [SECURITY] [DSA 1113-1] New zope2.7 packages fix information disclosure
- [SECURITY] [DSA 1114-1] New hashcash packages fix arbitrary code execution
- [SECURITY] [DSA 1115-1] New GnuPG2 packages fix denial of service
- [SECURITY] [DSA 1116-1] New gimp packages fix arbitrary code execution
- [SECURITY] [DSA 1117-1] New libgd2 packages fix denial of service
- [SECURITY] [DSA 1118-1] New Mozilla packages fix several vulnerabilities
- [SECURITY] [DSA 1119-1] New hiki packages fix denial of service
- [SECURITY] [DSA 1120-1] New Mozilla Firefox packages fix several vulnerabilities
- [SECURITY] [DSA 1121-1] New postgrey packages fix denial of service
- [SECURITY] [DSA 1122-1] New Net::Server packages fix denial of service
- [SECURITY] [DSA 1123-1] New libdumb packages fix arbitrary code execution
- [SECURITY] [DSA 1124-1] New fbi packages fix potential deletion of user data
- [SECURITY] [DSA 1125-1] New drupal packages fix execution of arbitrary web script code
- [SECURITY] [DSA 1125-2] New drupal packages fix execution of arbitrary web script code (revised packages)
- [SECURITY] [DSA 1126-1] New Asterisk packages fix denial of service
- [SECURITY] [DSA 1127-1] New ethereal packages fix several vulnerabilities
- [SECURITY] [DSA 1128-1] New heartbeat packages fix local denial of service
- [SECURITY] [DSA 1129-1] New osiris packages fix arbitrary code execution
- [SECURITY] Plain text password in Finjan Appliance 5100/8100 NG backup file
- [USN-296-2] Firefox vulnerabilities
- [USN-297-3] Thunderbird vulnerabilities
- [USN-308-1] shadow vulnerability
- [USN-309-1] libmms vulnerability
- [USN-310-1] ppp vulnerability
- [USN-312-1] gimp vulnerability
- [USN-313-1] OpenOffice.org vulnerabilities
- [USN-313-2] OpenOffice.org vulnerabilities
- [USN-314-1] samba vulnerability
- [USN-315-1] libmms, xine-lib vulnerabilities
- [USN-316-1] installer vulnerability
- [USN-317-1] zope2.8 vulnerability
- [USN-318-1] libtunepimp vulnerability
- [USN-319-1] Linux kernel vulnerability
- [USN-319-2] Linux kernel vulnerability
- [USN-320-1] PHP vulnerabilities
- [USN-320-2] php4 regression
- [USN-321-1] mysql-dfsg-4.1 vulnerability
- [USN-322-1] Konqueror vulnerability
- [USN-323-1] mozilla vulnerabilities
- [USN-324-1] freetype vulnerability
- [USN-325-1] ruby1.8 vulnerability
- [USN-326-1] heartbeat vulnerability
- [USN-327-1] firefox vulnerabilities
- [USN-328-1] Apache vulnerability
- [USN-329-1] Thunderbird vulnerabilities
- [vuln.sg] AGEphone "sipd.dll" SIP Packet Handling Buffer Overflow
- [vuln.sg] DynaZip DZIP32.DLL/DZIPS32.DLL Buffer Overflow Vulnerabilities
- [vuln.sg] PowerArchiver DZIPS32.DLL Buffer Overflow Vulnerability
- [vuln.sg] TurboZIP ZIP Repair Buffer Overflow Vulnerability
- a6mambohelpdesk Mambo Component <= 18RC1 Remote Include Vulnerability
- about bid 17404
- About the latest three Powerpoint vulnerabilities: exploitable?
- Advisory: Remote command execution in planetGallery
- Advisory: VMware Possible Incorrect Permissions On SSL Key Files
- AFCommerce Shopping Cart
- AIM Triton 1.0.4 (SipXtapi) Remote Buffer Overflow Exploit (PoC)
- Apache mod_rewrite Buffer Overflow Vulnerability
- artlinks Mambo Component <= Remote Include Vulnerability
- Ashop Search Module SQL injection
- ASP.DLL Include File Buffer Overflow
- ATutor 1.5.3 Cross Site Scripting
- ATutor : Cross-Site Scripting Vulnerabilities
- ATutor <= 1.5.3.1 'links' blind SQL injection / admin credentials disclosure
- Blackboard Academic Suite 6.2.23 +/-: Persistent cross-site scripting vulnerability
- BLOG:CMS 4.1.0 SQL injection File Include Vulnerability
- boastMachine <= 3.1 SQL Injection Exploit
- Browser bugs hit IE, Firefox today (SANS)
- Buddy Zone Version 1.0.1 - XSS
- Buffer Overflow Vulnerability in Winlpd
- Buffer-overflow in recvTextMessage and NETrecvFile in Warzone Resurrection 2.0.3 (SVN 127)
- Buffer-overflow in the XM loader of Cheese Tracker 0.9.9
- Bybass HTTP ( extension files ) in ISA 2004
- Bypassing Oracle dbms_assert
- Calendar Mambo Module <= 1.5.7 Remote File Include Vulnerabilities
- Calendar Module <= 1.5.7 Remote File Include Vulnerabilities
- call for papers - IT Underground, Italy 2006
- Call For Papers - No cON Name 2006 Edition Spain
- CC announces new Rootkit help forum insync with Book
- Check Point R55W Directory Traversal
- Cisco MARS < 4.2.1 remote compromise
- Cisco Security Advisory: Cisco Intrusion Prevention System Malformed Packet Denial of Service
- Cisco Security Advisory: Cisco Router Web Setup Ships with Insecure Default IOS Configuration
- Cisco Security Advisory: Multiple Cisco Unified CallManager Vulnerabilities
- Cisco Security Advisory: Multiple Vulnerabilities in Cisco Security Monitoring, Analysis and Response System (CS-MARS)
- Cisco Security Advisory: Windows VPN Client Local Privilege Escalation Vulnerability
- Cisco VPN Concentrator IKE resource exhaustion DoS Advisory
- Com Multibanners Remote File Inclusion (mosConfig_absolute_path)
- com_moskool (admin.moskool.php) Remote File Include Vulnerabilities
- Consumers of Broadband Providers (ISP) may be open to hijack attacks
- Contact for nhl.com
- Coppermine Photo Gallery v1.2.2b-Nuke Remote File Inclusion Vulnerabilities
- Corsaire Security Advisory - VMware ESX Server Password Cross Site Request Forgery issue
- Corsaire Security Advisory - VMware ESX Server Password Disclosure in Cookie issue
- Corsaire Security Advisory - VMware ESX Server Password Disclosure in Log issue
- cpanel login problem
- crashing firefox <= 1.5.0.4
- Cross Site Scripting Vulnerability in Zoho Virtual Office
- Cross-Site Scripting and Local File Inclusion in Phorum
- Crtical Shockwave Embeded XSS Execution
- CYBSEC - Security Pre-Advisory: Microsoft Windows DHCP Client Service Remote Buffer Overflow
- DEF CON 14: Speakers Selected and more.
- DeluxeBB mutiple vulnerabilities
- Digital Armaments Security Advisory 10.07.2006: Flexwath Authorization Bypassing and XSS Vulnerability
- Digital Armaments Security Advisory 24.07.2006: Siemens Speedstream Wireless/Router Denial of Service Vulnerability
- Do world's famous companies take care of their security?
- DotClear : Multiples Full Path Disclosure
- EEYE: McAfee ePolicy Orchestrator Remote Compromise
- ERNW Security Advisory 02/2006 - Buffer Overflow in sipXtapi (used in AOL Triton)
- ERRATA: [ GLSA 200607-08 ] GIMP: Buffer overflow
- Escalation of privileges in Outpost and Lavasoft Firewalls -Unusual ShellExecute behavior
- Etomite CMS <= 0.6.1 'rfiles.php' remote command execution
- Excel 2000/XP/2003 Style 0day POC
- ExtCalendar Mambo Module <= v2( extcalendar.php ) Remote File Include Vulnerabilities
- EzUpload multi file vulnerabilities
- Fantastic Guestbook v2.0.1 Advisory
- file include exploits in randshop v1.2
- flatnuke <= 2.5.7 arbitrary php file upload
- Flipper Poll <= 1.1.0 Remote File Inclusion Vulnerability
- flock d0s exploit remote. beta 1 (v0.7)
- FLV Players Multiple Input Validation Vulnerabilities
- Format string bug in Sparklet 0.9.4try3
- free QBoard v1.1 Multiple Remote File include
- Full Path Disclosure xGuestBook v1.02
- Fusion Polls (xtrphome) Remote File Inclusion
- Fuzzing Microsoft Office
- galleria <= 1.0 Remote File Inclusion Vulnerability
- Gdiplus.dll division by 0
- GeoClassifieds Enterprise <= 2.0.5.2 Cross Site Scripting
- Glossaire<<--v1.7 Remote File Include
- Gracenote buffer overflow
- Graffiti Forums v1.0 SQL Injection Vulnerabilities
- Guestbook Mambo Module <== v1.3.0 Multiple Remote File Include Vulnerabilities
- hdweGUEST <= 2.1.1 Cross Site Scripting Vulnerabilities
- Heap overflow in the GT2 loader of libmikmod 3.2.2
- HostingController: An attacker can gain reseller privileges and after that can gain admin privileges
- Hustle -- Tumbleweed Email Firewall Remote Vulnerability
- HYSA-2006-008 myBloggie 2.1.3 CRLF & SQL Injection
- IBM AIX Security contact?
- iDefense Security Advisory 07.20.06: Sun Microsystems Solaris sysinfo() Kernel Memory Disclosure Vulnerability
- IE <= 6 DoS vulnerability
- imageVue16.1 upload vulnerability
- imgsvr dos exploit by n00b
- Internet Crna Gora SQL Injection
- Invision Power Board "v1.X & 2.X" SQL Injection
- Invision Power Board 2.1 <= 2.1.6 sql injection
- Invision Power Board v1.3 Final SQL Injection
- Invision Power Board v2.1 <= 2.1.6 sql injection exploit
- Invision Vulnerabilities, including remote code execution
- Is Windows TCP/IP source routing PoC code available?
- Juniper Networks DX Web Administration Persistent System Log XSS Vulnerability
- Kerio Terminating 'kpf4ss.exe' using internal runtime error Vulnerability
- Keyif Portal v2.0 - Microsoft Access Driver ( MDB ) Download
- LAMP vs Microsoft
- Lan-Aces Office Logic
- Lazarus Guestbook Cross Site Scripting Vulnerabilities
- LinksCaffe 3.0 SQL injection/Command Execution Vulnerabilties
- lintah_|adv|_01<img src="/imgs/at.gif" border=0 align=middle>2006>=========<[Aura-CMS v1.62]<===>[XSS vulnerable]&[bug]
- Linux Kernel 2.6.x PRCTL Core Dump Handling - Local r00t Exploit ( BID 18874 / CVE-2006-2451 )
- Linux Kernel 2.6.x PRCTL Core Dump Handling -- Simple workaround
- Linux sys_prctl LKM based hotfix
- ListMessenger v0.9.3 Remote File Inclusion Vulnerability
- Local file inclusion in Farsinews3.0BETA1
- LoudBlog <=0.5 Sql injection
- Low security hole affecting IPCalc's CGI wrapper
- mAds v1.0
- Major updates to Excel 0-day Vulnerability FAQ at SecuriTeam Blogs
- mambatstaff Mambo Component <= Remote Include Vulnerability
- Mambo Gallery Manager v095.r3 Remote File Inclusion Vulnerabilities
- Map MS Security Bulletins to MS KB numbers
- McAfee VirusScan Enterprise 8.0.0 Buffer Overflow
- Mercury Messenger
- Mico crashes when contected with wrong IOR / DoS
- MicroGuestBook Remote XSS Attack
- Microsoft Excel Array Index Error Remote Code Execution
- Microsoft Internet Explorer DOS Vulnerability
- Microsoft PowerPoint 0-day Vulnerability FAQ document written
- Microsoft Works - Buffer Overflows / Denial of Service (DoS)-Vulnerabilities
- MIMESweeper For Web 5.X Cross Site Scripting
- MiniBB Forum <= 1.5a Remote File Include (news.php)
- MiniBB Forum <= 1.5a Remote File Include (search.php-whosOnline.php)
- MiniBB Forum <= 1.5a Remote File Include Vulnerabilities
- MS Power Point Multiple Vulnerabilities (powerpnt.exe)- POC
- MS Power Point Multiple Vulnerabilities - (memory corruption) POC
- MS Power Point Multiple Vulnerabilities - (mso.dll) POC
- MS Word Unchecked Boundary Condition Vulnerability
- MS06-034 lies? IIS 6 can still be owned?
- Msie 7.0 beta Crash
- MT rmcek Toplist v2.2 Version Microsoft Access Driver ( MDB ) Download
- Multiple vulnerabilities in Open Cubic Player 2.6.0pre6 / 0.1.10_rc5
- Multiple vulnerabilities in OpenCMS
- Multiple vulnerabilities in TK8 Safe v.3.0.5
- Multiple vulnerabilities in UFO2000 svn 1057
- MusicBox <= 2.3.4 XSS SQL injection Vulnerability
- MyBulletinBoard (MyBB) 1.1.5 'CLIENT-IP' sql injection
- MyGallery "Room.php" SQL Injection
- MyNewsGroups <= 0.6b (myng_root) Remote Inclusion Vulnerability
- New Article Mambo Component <= 1.0 (com_articles.php) Remote File Include Vulnerabilities
- New CVE identifiers for separate PowerPoint 0-day issues assigned
- New CVE number states Excel Style handling as a separate issue
- New PowerPoint Trojan installs itself as LSP
- new shell bypass safe mode
- News <= 5.2 XSS, SQL Injection, Full Path Disclosure
- NewsPHP 2006 PRO XSS SQL injection Vulnerability
- Norton Insufficient protection of Norton service registry keys
- NSFOCUS SA2006-04 : Microsoft Office GIF Filter Buffer Overflow Vulnerability
- NSFOCUS SA2006-05 : Microsoft Excel SELECTION Record Memory Corruption Vulnerability
- NSFOCUS SA2006-06 : Microsoft Excel COLINFO Record Buffer Overflow Vulnerability
- NSFOCUS SA2006-07 : ISS RealSecure/BlackICE MailSlot Heap Overflow Detection Remote DoS Vulnerability
- Old vulnerable sotwares collection
- OPERA Web Browser 9 Denial OF Service
- Opsware NAS 6.0 reveals MySQL 'root' password
- Oracle 10g R2 and, probably, all previous versions
- Oracle and Apache mod_rewrite Vulnerability
- Oracle Database - SQL Injection in SYS.DBMS_CDC_IMPDP [DB01]
- Oracle Database - SQL Injection in SYS.DBMS_STATS [DB21]
- Oracle Database - SQL Injection in SYS.DBMS_UPGRADE [DB22]
- Oracle Database - SQL Injection in SYS.KUPW$WORKER [DB03]
- Orbitmatrix PHP Script v1.0
- osDate 1.1.7 multiple vulnerabilities
- Outpost Firewall Pro secrately fixing security flaws?
- PacSec 2006 CALL FOR PAPERS (Deadline Aug. 4; Event Nov. 27-30)
- PAPOO <=3RC3 sql injection / admin credentials disclosure
- PBL Guestbook <= 1.32 XSS & SQL Querys Vulnerabilities
- PcAnywhere > 12 Local Privilege Escalation
- Pearl Products Multiple Remote File Inclusion
- perForms <= 1.0 ([mosConfig_absolute_path]) Remote File Inclusion
- PHORUM 5 arbitrary local inclusion
- Phorum 5.1.14 XSS SQL injection Vulnerability
- Phorum 5.1.15 security release (fixes "PHORUM 5 arbitrary local inclusion")
- Photocycle v1.0 - XSS
- PHP Event Calendar versi 1.4 (path_to_calendar) Remote File Inclusion
- PHP ip2long() function circumvention
- PHP Live! v3.2 (header.php) Remote File Include Vulnerabilities
- PHP security (or the lack thereof)
- PHP-Auction SQL injection
- PHP-Blogger Multiple Cross Site Scripting Vulnerabilities
- Php-Fusion (Xss) With Avatar Upload
- PHP-Nuke INP XSS
- PHPAuction 2.1 (maybe higher) with phpAdsNew 2.0.5 RFI
- phpBB 2.0.21 Full Path Disclosure
- phpbb 3.x sql injection (with global moderator rights)
- phpMyAdmin : Cross-Site Scripting Vulnerability
- phpPolls 1.0.3 Administration ByPass
- Phpprobid <= 5.24 XSS SQL injection Vulnerability
- PhpWebGallery Cross Site Scripting Vulnerability
- Pivot <=1.30rc2 privilege escalation / remote commands execution
- Plesk Control Panel <= 8.0.0 XSS vulnerability
- plume-cms v1.0.4 Multiple Remote File include
- popup Vacation Rentals[calendar_year.php] SQL Injection
- Portail PHP v1.7 Remote File Include
- Possible code execution in Kaillera 0.86
- PrinceClan Chess Mambo Com <= 0.8 Remote Inclusion Vulnerability
- Professional Home Page Tools Login Script Cross Site Scripting Vulnerabilities
- Professional PHP Tools Guestbook Multiple Vulnerabilities
- Public Advisory: Horde 3.1.1, 3.0.10 Multiple Security Issues
- QTOFileManager 1.0
- randshop <= 1.1.x (index.php) Remote File Inclusion Vulnerability
- Remote Include Vulnerability ====> in Dr.Jr7 Gallery 3.2 RC1
- Rocks Clusters <=4.1 local root
- rPSA-2006-0122-1 kernel
- rPSA-2006-0122-2 kernel
- rPSA-2006-0128-1 samba samba-swat
- rPSA-2006-0130-1 kernel
- rPSA-2006-0132-1 tshark wireshark
- rPSA-2006-0133-1 libpng
- rPSA-2006-0134-1 sendmail sendmail-cf
- rPSA-2006-0135-1 gimp
- rPSA-2006-0137-1 firefox
- rPSA-2006-0139-1 httpd mod_ssl
- RUXCON 2006 Final Call For Papers
- RW::Download stats.php Remote File Inc.
- S21Sec-032-en: Vulnerability in Fatwire Content Server
- Samba Internal Data Structures DOS Vulnerability Exploit
- saphp "add.php" forumid Parameter SQL Injection
- ScozNews Final-Php <=1.1 Remote File Inclusion Vulnerability
- Secunia Research: AutoVue SolidModel Professional Buffer Overflow Vulnerability
- Secunia Research: BitZipper unacev2.dll Buffer Overflow Vulnerability
- Secunia Research: FileCOPA Directory Argument Handling Buffer Overflow
- Secunia Research: IceWarp Web Mail Two File Inclusion Vulnerabilities
- Secunia Research: Mozilla Firefox XPCOM Event Handling Memory Corruption
- Secunia Research: VisNetic Mail Server Two File Inclusion Vulnerabilities
- Securing PHP or finding PHP alternatives
- Securing PHP or finding PHP alternatives (was: PHP security (or the lack thereof))
- Security point-of-contact for Ameritrade?
- SECURITY UPDATE::Farsinews release FarsiNewsPro3.0Stable1SecurityPath1
- Several updates in MS PowerPoint 0-day Vulnerability FAQ at SecuriTeam Blogs
- Shopping Cart V0.9
- SMB Information Disclosure Vulnerability
- SmS Script SQL Injection
- sNews 1.3 XSS SQL
- SolpotCrew Advisory #2 - Advanced Poll ver 2.02 (base_path) Remote File Inclusion
- SolpotCrew Advisory #3 - com_trade Remote File Inclusion (mosConfig_absolute_path)
- Sport-slo.net Guestbook v1.0
- Sql injection in Diesel joke site script
- SQL injection Seir Anphin v666 Community Management System
- SQuery <= 4.5(libpath) Remote File Inclusion Exploit
- SQuery v.x (devi.php) (armygame.php) Remote File Inclusion
- SturGeoN Upload v1 Remote Command Execution Exploit
- SubberZ[Lite] - Remote File Include
- SYMSA-2006-004 (Full Details): Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution
- SYMSA-2006-007: Microsoft Office Malformed String Parsing Vulnerability
- SYMSA-2006-008:Password Safe - Lock Password Database Configuration Not Enforced
- TBE 4.0 XSS
- TigerTom Scripts
- ToendaCMS <= 1.0.0 arbitrary file upload
- ToorCon 2006 Call for Papers
- TOPo v.2.2.178 Account Reset
- Touch arbitrary file execute vulnerability
- TP-Book <= 1.00 Cross Site Scripting Vulnerabilities
- TSLSA-2006-0040 - kernel
- TSLSA-2006-0042 - multi
- TSRT-06-02: Microsoft SRV.SYS Mailslot Ring0 Memory Corruption Vulnerability
- TSRT-06-03: eIQnetworks Enterprise Security Analyzer Syslog Server Buffer Overflow Vulnerabilities
- TSRT-06-04: eIQnetworks Enterprise Security Analyzer Topology Server Buffer Overflow Vulnerability
- Two crash vulnerabilities in Freeciv 2.1.0-beta1 (SVN 15 Jul 2006)
- Unauthenticated access to BT Voyager config file and PPP credentials embedded in HTML form
- Unidomedia Chameleon LE/Pro Directory Traversal
- UPDATE: [ GLSA 200605-08 ] PHP: Multiple vulnerabilities
- Vanilla CMS <= 1.0.1 (RootDirectory) Remote file inclusion Vuln.
- Various heap and stack overflow bugs in AdPlug library 2.0 (CVS 04 Jul 2006)
- vBulletin 3.5.4 (install_path) Exploit
- VBZooM "sendmail.php" SQL Injection
- VBZooM <=V1.11 " ignore-pm.php" SQL Injection
- VBZooM <=V1.11 " reply.php" SQL Injection
- VBZooM <=V1.11 "sub-join.php" SQL Injection
- VMSA-2006-0003 VMware possible incorrect permissions on SSL key files
- WebEx Downloader Plug-in Multiple Vulnerabilities + rant
- Webmin / Usermin Arbitrary File Disclosure Vulnerability exploit
- Webmin / Usermin Arbitrary File Disclosure Vulnerability Perl
- WebScarab <= 20060621-0003 cross site scripting
- Webvizyon Portal 2006 Version SQL Injection
- Whitepaper: IT (in)security implementation in a real world example
- Windows Explorer URL File format overflow
- Windows XP/NT/SMB2003/2000 Denial of Service attack
- WordPress 2.0.3 SQL Error and Full Path Disclosure
- Write-up by Amit Klein: "Forging HTTP request headers with Flash"
- wwwThreads XSS
- Xss in MttKe-php v2.6
- XSS phpBB 2.0.21 in administration
- XSS vulnerability on AWBS
- ZDI-06-021: WebEx Downloader Plug-in Code Execution Vulnerability
- ZDI-06-022: Microsoft Office Excel File Rebuilding Code Execution Vulnerability
- ZDI-06-023: eIQNetworks Enterprise Security Analyzer Syslog Server Buffer Overflow Vulnerability
- ZDI-06-024: eIQNetworks Enterprise Security Analyzer License Manager Buffer Overflow Vulnerability
- ZDI-06-025: Mozilla Firefox Javascript navigator Object Vulnerability
- ZoneAlarm Insufficient protection of registry key 'VETFDDNT\Enum' Vulnerability
- Zyxel Prestige 660H-61 Cross-Site Scripting
Last message date: Mon Jul 31 2006 - 18:58:53 CDT
Archived on: Mon Jul 31 2006 - 18:58:54 CDT
565 messages sorted by: [ author ] [ date ] [ thread ]
not-noticeably.net