Re: XSS in JAB Guest Book

2006-12-09 Thread Barnz
Hello, The problem should not be fixed in the download, using the strip_tags() functions.

KDPics Multiple Vulnerabities

2006-12-09 Thread mr_kaliman
KDPics 1.16 and prior Vendor site: http://www.kdland.org/kdpics/ Product: KDPics = 1.16 Vulnerability: Remote File Inclusion Vulnerability XSS Credits: Mr_KaLiMaN Reported to Vendor: 30.11.06 Public disclosure: 09.12.06 Description: Remote File Inclusion

ProNews V1.5 XSS SQL Injection

2006-12-09 Thread mr_kaliman
ProNews V1.5 Vendor site: http://www.scripthp.com/ Product: ProNews V1.5 Vulnerability: XSS SQL Injection Vulnerability Credits: Mr_KaLiMaN Reported to Vendor: 01.12.06 Public disclosure: 09.12.06 Description: XSS permanent:

Messageriescripthp V2.0 XSS SQL Injection

2006-12-09 Thread mr_kaliman
Messageriescripthp V2.0 --- Vendor site: http://www.scripthp.com/ Product: Messageriescripthp V2.0 Vulnerability: XSS SQL Injection Vulnerability Credits: Mr_KaLiMaN Reported to Vendor: 01/12/06 Public disclosure: 09/12/06 Description: SQL Injection

AnnonceScriptHP V2.0 Multiple Vulnerabilities

2006-12-09 Thread mr_kaliman
AnnonceScriptHP V2.0 Vendor site: http://www.scripthp.com/ Product: AnnonceScriptHP V2.0 Vulnerability: XSS SQL Injection Vulnerability Credits: Mr_KaLiMaN Reported to Vendor: 02/12/06 Public disclosure: 09/12/06 Description: Password disclosure (all members):

[SECURITY] [DSA 1231-1] New gnupg packages fix arbitrary code execution

2006-12-09 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1231-1[EMAIL PROTECTED] http://www.debian.org/security/ Moritz Muehlenhoff December 9th, 2006

iDefense Security Advisory 12.08.06: Multiple Vendor Antivirus RAR File Denial of Service Vulnerability

2006-12-09 Thread iDefense Labs
Multiple Vendor Antivirus RAR File Denial of Service Vulnerability iDefense Security Advisory 12.08.06 http://labs.idefense.com/intelligence/vulnerabilities/ Dec 08, 2006 I. BACKGROUND AntiVirus products typically handle searching files for known viruses within their scan engines. Most scan

iDefense Security Advisory 12.08.06: Sophos Antivirus CHM Chunk Name Length Memory Corruption Vulnerability

2006-12-09 Thread iDefense Labs
Sophos Antivirus CHM Chunk Name Length Memory Corruption Vulnerability iDefense Security Advisory 12.08.06 http://labs.idefense.com/intelligence/vulnerabilities/ Dec 08, 2006 I. BACKGROUND Sophos AntiVirus offers protection from the latest Trojans, worms and Viruses. More information is

iDefense Security Advisory 12.08.06: Sophos Antivirus CHM File Heap Overflow Vulnerability

2006-12-09 Thread iDefense Labs
Sophos Antivirus CHM File Heap Overflow Vulnerability iDefense Security Advisory 12.08.06 http://labs.idefense.com/intelligence/vulnerabilities/ Dec 08, 2006 I. BACKGROUND Sophos AntiVirus offers protection from the latest Trojans, worms and Viruses. More information is available on the vendors

Call For Papers: SecurityOPUS 2007

2006-12-09 Thread Sharkey
Call for Papers Security OPUS - Call for Papers March 19-20, 2006. San Francisco, California. USA http://www.securityopus.com/papers.phphttp://www.securityopus.com/papers.php Security OPUS is an annual meeting of professional security researchers and information security practioners. The

[ GLSA 200612-02 ] xine-lib: Buffer overflow

2006-12-09 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200612-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[SECURITY] [DSA 1232-1] New clamav packages fix denial of service

2006-12-09 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1232-1[EMAIL PROTECTED] http://www.debian.org/security/ Moritz Muehlenhoff December 9th, 2006