Multiple XSS in Geeklog 1.3.7

2003-01-19 Thread snooq
nothing new. typical XSS bugs. summary === Geeklog is a web portal system written in PHP. There exists 5 XSS holes in the software. the 'holes' === --1-- http://vulnerable.host/profiles.php?uid= --2-- http://vulnerable.host

Security Update: [CSSA-2003-002.0] Linux: Webmin Cross-site Scripting and Session ID Spoofing Vulnerabilities

2003-01-19 Thread security
To: [EMAIL PROTECTED] [EMAIL PROTECTED] [EMAIL PROTECTED] [EMAIL PROTECTED] __ SCO Security Advisory Subject:Linux: Webmin Cross-site Scripting and Session ID Spoofing Vulnerabil

Re[2]: Opentype font file causes Windows to restart.

2003-01-19 Thread Andrew
I have not yet investigated the problem thoroughly, but as far as I'm aware it's caused by complicated outlines -- the font file contains only 1 character, with about 1000 points in it. If anyone wishes to examine the file in depth, I'd recommend using TTX (http://www.letterror.com/code/ttx/ ) - i

phpBB SQL Injection vulnerability

2003-01-19 Thread Ulf Harnhammar
phpBB SQL Injection vulnerability PROGRAM: phpBB VENDOR: phpBB Group HOMEPAGE: http://www.phpbb.com/ VULNERABLE VERSIONS: 2.0.3, possibly others IMMUNE VERSIONS: 2.0.4 LOGIN REQUIRED: yes DESCRIPTION: "phpBB is a UBB-style dissussion board written in PHP backended by a MySQL database. It inclu

[OpenPKG-SA-2003.002] OpenPKG Security Advisory (dhcpd)

2003-01-19 Thread OpenPKG
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 OpenPKG Security AdvisoryThe OpenPKG Project http://www.openpkg.org/security.html http://www.openpkg.org [EMAIL PROTECTED]