[ MDKSA-2006:037 ] - Updated mozilla-firefox packages to address DoS vulnerability

2006-02-08 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2006:037 http://www.mandriva.com/security/ ___

iDefense Security Advisory 02.07.06: QNX Neutrino RTOS phfont Race Condition Vulnerability

2006-02-08 Thread [EMAIL PROTECTED]
QNX Neutrino RTOS phfont Race Condition Vulnerability iDefense Security Advisory 02.07.06 http://www.idefense.com/intelligence/vulnerabilities/display.php?id=383 February 7, 2006 I. BACKGROUND QNX Software Systems Ltd.'s Neutrino RTOS (QNX) is a real-time operating system designed for use in em

iDefense Security Advisory 02.07.06: QNX Neutrino RTOS su Command Buffer Overflow

2006-02-08 Thread [EMAIL PROTECTED]
QNX Neutrino RTOS su Command Buffer Overflow iDefense Security Advisory 02.07.06 http://www.idefense.com/intelligence/vulnerabilities/display.php?id=385 February 7, 2006 I. BACKGROUND QNX Software Systems Ltd.'s Neutrino RTOS (QNX) is a real-time operating system designed for use in embedded sy

iDefense Security Advisory 02.07.06: QNX Neutrino RTOS fontsleuth Command Format String Vulnerability

2006-02-08 Thread vendor-disclosure
QNX Neutrino RTOS fontsleuth Command Format String Vulnerability iDefense Security Advisory 02.07.06 http://www.idefense.com/intelligence/vulnerabilities/display.php?id=380 February 7, 2006 I. BACKGROUND QNX Software Systems Ltd.'s Neutrino RTOS (QNX) is a real-time operating system designed fo

Re: [myimei]MyBB 1.0.2 XSS attack in search.php

2006-02-08 Thread Steven M. Christey
The advisory says: >Status: patched in 1.0.3 ... >?Solution??? >No Patch available. >(bug reported to vendor today) I'm confused. One part of this advisory says there's a patch available, one part says there isn't. (By the way, this is an example of the "inconsistent" property of secur

iDefense Security Advisory 02.07.06: QNX RTOS 6.3.0 Local Denial of Service Vulnerability

2006-02-08 Thread [EMAIL PROTECTED]
QNX RTOS 6.3.0 Local Denial of Service Vulnerability iDefense Security Advisory 02.07.06 http://www.idefense.com/intelligence/vulnerabilities/display.php?id=386 February 7, 2006 I. BACKGROUND QNX Software Systems Ltd.'s Neutrino RTOS (QNX) is a real-time operating system designed for use in emb

Re: Workaround for unpatched Oracle PLSQL Gateway flaw

2006-02-08 Thread a
So, like, what about http://www.integrigy.com/info/IntegrigySecurityAnalysis-MODPLSQLVuln.pdf

iDefense Security Advisory 02.07.06: QNX Neutrino RTOS libph PHOTON_PATH Buffer Overflow Vulnerability

2006-02-08 Thread [EMAIL PROTECTED]
QNX Neutrino RTOS libph PHOTON_PATH Buffer Overflow Vulnerability iDefense Security Advisory 02.07.06 http://www.idefense.com/intelligence/vulnerabilities/display.php?id=382 February 7, 2006 I. BACKGROUND QNX Software Systems Ltd.'s Neutrino RTOS (QNX) is a real-time operating system designed f

Whomp Real Estate Manager XP 2005 Sql Injection

2006-02-08 Thread night_warrior771
##Night_Warrior ##night_warrior771[at]hotmail.com ##Whomp Real Estate Manager XP 2005 Sql Injection ##http://www.webeveyn.com/WHOMP/Rem/ ## ##Code For Admin Login : ## ##Username : ' or ''=' ##Password: ' or ''=' ## ## ##Contact :night_warrior771[at]hotmail.com ##Night_Warrior

iDefense Security Advisory 02.07.06: QNX Neutrino RTOS libAp ABLPATH Buffer Overflow Vulnerability

2006-02-08 Thread vendor-disclosure
QNX Neutrino RTOS libAp ABLPATH Buffer Overflow Vulnerability iDefense Security Advisory 02.07.06 http://www.idefense.com/intelligence/vulnerabilities/display.php?id=381 February 7, 2006 I. BACKGROUND QNX Software Systems Ltd.'s Neutrino RTOS (QNX) is a real-time operating system designed for u

Re: Workaround for unpatched Oracle PLSQL Gateway flaw

2006-02-08 Thread David Litchfield
So, like, what about http://www.integrigy.com/info/IntegrigySecurityAnalysis-MODPLSQLVuln.pdf This provides an excellent analysis of the problem. Further, it discusses the recommendation made by Vladimir Zakharychev from Webrecruiter. This recommendation is to set the "always_describe" / "Pls

iDefense Security Advisory 02.07.06: QNX Neutrino RTOS crttrap Arbitrary Library Loading Vulnerability

2006-02-08 Thread vendor-disclosure
QNX Neutrino RTOS crttrap Arbitrary Library Loading Vulnerability iDefense Security Advisory 02.07.06 http://www.idefense.com/intelligence/vulnerabilities/display.php?id=379 February 7, 2006 I. BACKGROUND QNX Software Systems Ltd.'s Neutrino RTOS (QNX) is a real-time operating system designed f

iDefense Security Advisory 02.07.06: QNX Neutrino RTOS phgrafx Command Buffer Overflow

2006-02-08 Thread [EMAIL PROTECTED]
QNX Neutrino RTOS phgrafx Command Buffer Overflow iDefense Security Advisory 02.07.06 http://www.idefense.com/intelligence/vulnerabilities/display.php?id=384 February 7, 2006 I. BACKGROUND QNX Software Systems Ltd.'s Neutrino RTOS (QNX) is a real-time operating system designed for use in embedd

[eVuln] PHP iCalendar File Inclusion Vulnerability

2006-02-08 Thread alex
New eVuln Advisory: PHP iCalendar File Inclusion Vulnerability http://evuln.com/vulns/70/summary.html Summary eVuln ID: EV0070 Software: PHP iCalendar Sowtware's Web Site: http://phpicalendar.net/ Versions: 2.0.1 2.1 2.2 Critical Level: Dangerous Type: File Incl

Re: Re: EasyCMS vulnerable to XSS injection.

2006-02-08 Thread kim
I would just like to follow up on this thread by announcing that the security-flaws detected by Preben has been successfully been removed in Easy CMS v1.3RC2. regards, Kim Steinhaug www.easycms.no

WiredRed EPOP XSS Vulnerability

2006-02-08 Thread Adrian Castro
WiredRed EPOP XSS Vulnerability ---Summary--- Software Affected: EPOP WebConference Server Software Versions: 4.1.0.755 Vendors URL:www.wiredred.com Vulnerability Type: Cross Site Scripting Proof of Concept: An exploit is not required Threat Level:

[ MDKSA-2006:036 ] - Updated mozilla packages to address DoS vulnerability

2006-02-08 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2006:036 http://www.mandriva.com/security/ ___

iDefense Security Advisory 02.07.06: QNX Neutrino RTOS passwd Command Buffer Overflow

2006-02-08 Thread [EMAIL PROTECTED]
QNX Neutrino RTOS passwd Command Buffer Overflow iDefense Security Advisory 02.07.06 http://www.idefense.com/intelligence/vulnerabilities/display.php?id=388 February 7, 2006 I. BACKGROUND QNX Neutrino RTOS is a real-time operating system designed for use in embedded systems. More information ab

iDefense Security Advisory 02.07.06: QNX RTOS 6.3.0 rc.local Insecure File Permissions Vulnerability

2006-02-08 Thread [EMAIL PROTECTED]
QNX RTOS 6.3.0 rc.local Insecure File Permissions Vulnerability iDefense Security Advisory 02.07.06 http://www.idefense.com/intelligence/vulnerabilities/display.php?id=387 February 7, 2006 I. BACKGROUND QNX Software Systems Ltd.'s Neutrino RTOS (QNX) is a real-time operating system designed for