[OpenPKG-SA-2005.026] OpenPKG Security Advisory (lynx)

2005-12-03 Thread OpenPKG
Packages: Corrected Packages: OpenPKG CURRENT = lynx-2.8.5-20051030 = lynx-2.8.5.5-20051203 OpenPKG 2.5 = lynx-2.8.5-2.5.0 = lynx-2.8.5-2.5.1 OpenPKG 2.4 = lynx-2.8.5-2.4.0 = lynx-2.8.5-2.4.1 OpenPKG 2.3 = lynx-2.8.5-2.3.0 = lynx-2.8.5-2.3.1 Description

MDKSA-2005:221 - Updated spamassassin packages fixes vulnerability

2005-12-03 Thread Mandriva Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2005:221 http://www.mandriva.com/security/

Re: Re: Microsoft Windows CreateRemoteThread Exploit

2005-12-03 Thread warl0ck
You are a bit wrong q7x some firewalls and security programs will stop you from calling that function(and some others like that), for example the Tiny Personal Firewall.

eXtreme Styles mod = 2.2.1 Multiple Vulnerabilities

2005-12-03 Thread tommie1
Site: http://www.phpbbstyles.com/ 1. Remote File Content Disclosure http://forum/admin/xs_edit.php?edit=../../../../etc/passwd 2. Full Path Disclosure http://forum/admin/xs_edit.php?edit=viewbackup=1 http://wtf.bz/

[OpenPKG-SA-2005.025] OpenPKG Security Advisory (perl)

2005-12-03 Thread OpenPKG
Releases: Affected Packages: Corrected Packages: OpenPKG CURRENT = perl-5.8.7-20050921 = perl-5.8.7-20051203 OpenPKG 2.5 = perl-5.8.7-2.5.0 = perl-5.8.7-2.5.1 OpenPKG 2.4 = perl-5.8.7-2.4.0 = perl-5.8.7-2.4.1 OpenPKG 2.3 = perl-5.8.6-2.3.0

Alisveristr E-Commerce Admin Login SQL #304;njection

2005-12-03 Thread B3g0k
###Hi all ###B3g0k[at]hackermail.com ###Kurdish Hacker ###Special Thanx All Kurdish Hackers ###Freedom For Ocalan!!! ###--- ###Alisveristr E-commerce User Login Sql #304;njection ###Alisveristr E-commerce Admin Login Sql 304;njection

Re: WebCalendar

2005-12-03 Thread Louis Wang
Hi, Dan: For some vulnerability has fixed by the vendor, I have update this vulnerability advisory, sorry for any trouble I have caused to you. The following is the updated advisory.: === WebCalendar CRLF Injection Vulnerability I. BACKGROUND

MDKSA-2005:222 - Updated mailman packages fix various vulnerabilities

2005-12-03 Thread Mandriva Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2005:222 http://www.mandriva.com/security/

[OpenPKG-SA-2005.027] OpenPKG Security Advisory (php)

2005-12-03 Thread OpenPKG
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 OpenPKG Security AdvisoryThe OpenPKG Project http://www.openpkg.org/security.html http://www.openpkg.org [EMAIL PROTECTED]

[Updated] [FLSA-2005:166943] Updated php packages fix security issues

2005-12-03 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated php packages fix security issues Advisory ID: FLSA:166943 Issue date:2005-12-02 Product: Red Hat Linux, Fedora Core Keywords:

QNX 4.25 suided dhcp.client binary

2005-12-03 Thread lms
Hello all, I recently got a QNX 4.25 vmware image and i found that the dhcp.client shipped with it is suided. This obviously enables a normal user to control the NIC's configuration and produce some other attacks (eg: if the system has some services which depend on 'host/ip based' authentication

PHP-Fusion v6.00.109 SQL Injection and Info. Disclosure

2005-12-03 Thread xer0x . west
In the latest version of PHP-Fusion, the content management system by Digitanium (php-fusion.co.uk), there is an SQL Error in messages.php that reveals path names and a table name, and someone could possibly manipulate the SQL database. The error is as follows, it is with the Search and Sort

eXtreme Styles mod = 2.2.1 Multiple Vulnerabilities

2005-12-03 Thread tommie1
eXtreme Styles mod = 2.2.1 Multiple Vulnerabilities http://www.phpbbstyles.com/ Description === These vulnerabilities could allow an attacker that has gained administrative access view file content on the system. 1. Remote File Content

Zen-Cart = 1.2.6d blind SQL injection / remote commands execution:

2005-12-03 Thread retrogod
Zen-Cart = 1.2.6d blind SQL injection / remote commands execution: software: site: http://www.zencart.com/ description:Zen Cart™ truly is the art of e-commerce; a free,user-friendly, open source shopping cart system. The software is being developed by group of

more MD5 colliding examples

2005-12-03 Thread Gerardo Richarte
hello everybody, last month we presented in a lightning talk at PacSec a few interesting and somehow new things related to MD5 collisions: 2 different Win32 .EXE files with the same MD5 hash, and 4 different files (inputs) with the same MD5 hash. These are direct results of