Re: Microsoft Help (WINHLP32.EXE) - Multiple Remote Code Execution and Denial Of Service Vulnerabilities

2006-08-12 Thread Reversemode
Hi, Nobody should open an untrusted .HLP file. An HLP file is the most similar to an executable but not being one, mainly due to its powerful scripting language. One of the documented macros documented and supported by this format is "RegisterRoutine". Using this macro we can reference any Expor

ScatterChat Advisory 2006-01: Cryptanalytic Attack Vulnerability

2006-08-12 Thread ScatterChat Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ScatterChat Advisory 2006-01: Cryptanalytic Attack Vulnerability Technical Report CVE ID: CVE-2006-4021 August 11th, 2006 http://www.scatterchat.com/ SUMMARY ScatterChat (http://www.scatterchat.com/) is an instant messaging project that aims to pr

Forum Software ASPPlayground.NET Advanced Edition 2.4.5 Unicode Xss

2006-08-12 Thread blood2_20032003
Author:-=Mizo=- script:Forum Software © ASPPlayground.NET Advanced Edition 2.4.5 Unicode bug:-www.XXX./forum/calendar.asp?calendarID=|Xss| greetz to Mahbub,Lezr.com,3asfh.net and ReMoTer

(Security Advisory) SYM06-014 Symantec Backup Exec Internal RPC Overflow

2006-08-12 Thread Secure
Any further revisions to this information, if required, will be posted to the official advisory located at : http://www.symantec.com/avcenter/security/Content/2006.08.11.html Symantec Security Advisory SYM06-014 BID 19479 11 August 2006 Symantec Backup Exec for Windows Server: RPC Interfac

Re: myBloggie <= 2.1.3 (mybloggie_root_path) Remote File Inclusion Vulnerability

2006-08-12 Thread nukedx
Hi, I checked these files you said vulnerable and could not see any vulnerability. Lets check lines 25-34 of index.php: --source code of index.php lines 25 to 34- 25: //error_reporting('E_ALL'); 26: 27: define('IN_MYBLOGGIE', true); 28: 29: session_start(); 30: header("Cache-control: priva

Microsoft Help (WINHLP32.EXE) - Multiple Remote Code Execution and Denial Of Service Vulnerabilities

2006-08-12 Thread Benjamin Tobias Franz
Microsoft Help (WINHLP32.EXE) - Multiple Remote Code Execution and Denial Of Service Vulnerabilities ... discovered by Benjamin Tobias Franz Affected Vendor: Microsoft Affected Product: Microsoft Windows - Microsoft Help (WINHLP32.EXE) Description: Multiple remote code execution and denial of s

[SECURITY] [DSA 1150-1] New shadow packages fix privilege escalation

2006-08-12 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1150-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze August 12th, 2006

Concurrency-related vulnerabilities in browsers - expect problems

2006-08-12 Thread Michal Zalewski
Good morning, "Fame-hungry sociopath torches cars, finds browser flaws WARSAW, Poland (AP) -- police are on a look out for a local adolescent vandal who continues to terrorize local IT workers in what appears to be a bizzare bid for fame. Larry Seltzer reports from the scene." Well, I ju

myEvent <= 1.4 Multiple Remote File Include Vulnerabilities

2006-08-12 Thread sh3ll
--- myEvent 1.4 Multiple Remote File Include Vulnerabilities --- Author : Sh3ll Date : 2006/08/11 HomePage : http://www.

Calendarix <= 0.7 (calpath) Remote File Inclusion Vulnerability

2006-08-12 Thread sh3ll
--- Calendarix 0.7 calpath Remote File Inclusion --- Author : Sh3ll Date : 2006/08/11 HomePage : http://www.sh3ll.ir Co