BugTraq

Syndicate content
The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!
Updated: 1 day 1 hour ago

[USN-658-1] Moodle vulnerability

Thu, 2008-10-23 13:33
Posted by Kees Cook on Oct 23

===========================================================
Ubuntu Security Notice USN-658-1 October 23, 2008
moodle vulnerability
CVE-2008-1502, CVE-2008-1502
===========================================================

A security issue affects the following Ubuntu releases:

...

Categories: Mailing Lists

[SECURITY] [DSA 1659-1] New libspf2 packages fix potential remote code execution

Thu, 2008-10-23 12:00
Posted by Florian Weimer on Oct 23

------------------------------------------------------------------------
Debian Security Advisory DSA-1659-1 security_at_debian.org
http://www.debian.org/security/ Florian Weimer
October 23, 2008 ...

Categories: Mailing Lists

[security bulletin] HPSBST02379 SSRT080143 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-056 to MS08-066

Thu, 2008-10-23 11:55
Posted by security-alert_at_hp.com on Oct 23

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c01579861
Version: 1

HPSBST02379 SSRT080143 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-056 to MS08-066

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

...

Categories: Mailing Lists

Re: MJGuest 6.8 GT Cross Site Scripting Vulnerability

Thu, 2008-10-23 01:38
Posted by alighieri_m_at_libero.it on Oct 23

('binary' encoding is not supported, stored as-is) This vulnerability has been fixed with the updated package of the script, released on 22 October 2008.

Download it here:
http://www.mdsjack.bo.it/index.php?page=mjguest#download
Received on Oct 23 2008

Categories: Mailing Lists

Re: vshop - Axcoto cart lt 0.1alpha Local File Inclusion Vulnerability

Thu, 2008-10-23 01:33
Posted by Jose Luis on Oct 23

I'm sorry ... this is not vulnerable. I confused the program

2008/10/22 Pepelux <pepelux_at_enye-sec.org>:
> -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
> vshop - Axcoto cart <= 0.1alpha / Local File Inclusion Vulnerability
>...

Categories: Mailing Lists

txtshop - beta 1.0 Local File Inclusion Vulnerability

Thu, 2008-10-23 01:32
Posted by Pepelux on Oct 23

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
txtshop - beta 1.0 / Local File Inclusion Vulnerability
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

$ Program: txtshop
$ Version: <= 1.0
$ File affected: ADMIN/header.php
$ Download: ...

Categories: Mailing Lists

SiteEngine 5.x Multiple Remote Vulnerabilities

Wed, 2008-10-22 18:45
Posted by xuanmumu_at_gmail.com on Oct 22

('binary' encoding is not supported, stored as-is) Due to incorrect use of intval function, leading to the logic of inspection parameters can be bypassed, resulting in SQL injection vulnerability.

-=0x01=- SQL injection Vulnerability
vul code like this:
if ( intval( $id ) )
{
...

Categories: Mailing Lists

freeSSHd (stf - rename) Buffer Overflow Vulnerability

Wed, 2008-10-22 15:55
Posted by writ3r_at_gmail.com on Oct 22

('binary' encoding is not supported, stored as-is) # freeSSHd (rename) Buffer Overflow Vulnerability
# http://www.milw0rm.com/exploits/6800 <-- Same vuln just further research

# Registers
# EAX 00000000
# ECX 41414141
# EDX 7C9037D8 ntdll.7C9037D8
# EBX 00000000
# ESP 001376BC
# EBP...

Categories: Mailing Lists

GoodTech SSH Remote Buffer Overflow Exploit

Wed, 2008-10-22 15:52
Posted by writ3r_at_gmail.com on Oct 22

('binary' encoding is not supported, stored as-is) # GoodTech SSH Remote Buffer Overflow Exploit
# Written by r0ut3r - writ3r [at] gmail.com
#
# SSH_FXP_OPEN command contains a buffer oveflow.
#
# All other operations are also vulnerable, opendir, unlink, etc.

use Net::SSH2;

my $user =...

Categories: Mailing Lists

vshop - Axcoto cart lt 0.1alpha Local File Inclusion Vulnerability

Wed, 2008-10-22 13:47
Posted by Pepelux on Oct 22

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
vshop - Axcoto cart <= 0.1alpha / Local File Inclusion Vulnerability
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

$ Program: vshop - Axcoto cart
$ Version: <= 0.1alpha
$ File affected:...

Categories: Mailing Lists

phpcrs lt 2.06 Local File Inclusion Vulnerability (this is the correct :)

Wed, 2008-10-22 13:44
Posted by Pepelux on Oct 22

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
phpcrs <= 2.06 / Local File Inclusion Vulnerability
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

$ Program: phpcrs
$ Version: <= 2.06
$ File affected: frame.php
$ Download: http://sourceforge.net/projects/phpcrs/

Found by...

Categories: Mailing Lists

[SECURITY] [DSA 1658-1] New dbus packages fix denial of service

Wed, 2008-10-22 11:50
Posted by Thijs Kinkhorst on Oct 22

------------------------------------------------------------------------
Debian Security Advisory DSA-1658-1 security_at_debian.org
http://www.debian.org/security/ Thijs Kinkhorst
October 22, 2008 ...

Categories: Mailing Lists

SNMP Injection: Achieving Persistent HTML Injection via SNMP on Embedded Devices

Wed, 2008-10-22 09:07
Posted by ProCheckUp Research on Oct 22

SNMP Injection: Achieving Persistent HTML Injection via SNMP on Embedded
Devices

Introduction

In our earlier "ZyXEL Gateways Vulnerability Research" paper[1], we
introduced a new technique: SNMP injection a.k.a. persistent HTML
injection via SNMP. Such a technique allowed us to...

Categories: Mailing Lists

SECOBJADV-2008-05: Symantec Veritas Storage Foundation Arbitrary File Read Vulnerability

Wed, 2008-10-22 08:41
Posted by Security Objectives Corporation on Oct 22

======================================================================
= Security Objectives Advisory (SECOBJADV-2008-05) =
======================================================================

Veritas Storage Foundation Arbitrary File Read Vulnerability

...

Categories: Mailing Lists

Re: FGA-2008-23:EMC NetWorker Denial of Service Vulnerability

Wed, 2008-10-22 07:38
Posted by Security_Alert_at_emc.com on Oct 22

('binary' encoding is not supported, stored as-is) Correction to the posted bulletin:

The Networker software versions affected are incorrectly identified.

The following Networker products are affected by this issue:

* NetWorker Server, Storage Node and Client 7.3.x and 7.4, 7.4.1, 7.4.2
*...

Categories: Mailing Lists