[ MDKSA-2006:164 ] - Updated xorg-x11/XFree86 packages fix integer overflow vulnerabilities

2006-09-14 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2006:164 http://www.mandriva.com/security/

ToorCon Pre-Registration Closing Friday!

2006-09-14 Thread [EMAIL PROTECTED]
PRE-REGISTRATION CLOSING ON FRIDAY, SEPTEMBER 15TH Don't miss out on the discounted rates for attending ToorCon 8, San Diego's exclusive hacker convention, going on from September 29th through October 1st. [http://www.toorcon.org] GENERAL ADMISSION Currently general admission is only $80 which

ADOdb Date Library Full path Bugs

2006-09-14 Thread security
Hello,, ADOdb Date Library, part of the ADOdb abstraction library Full path bugs Discovered By : HACKERS PAL Copy rights : HACKERS PAL Website : http://www.soqor.net Email Address : [EMAIL PROTECTED] ADOdb Date Library, part of the ADOdb abstraction library Full path adodb/server.php

DCP-Portal SE 6.0 multiple injections

2006-09-14 Thread security
Hello,, DCP-Portal SE 6.0 multiple injections Discovered By : HACKERS PAL Copy rights : HACKERS PAL Website : http://www.soqor.net Email Address : [EMAIL PROTECTED] sql injections if magic_qoutes_gpc = off /*/ lostpassword.php you can recive

Mailman 2.1.8 Multiple Security Issues

2006-09-14 Thread Moritz Naumann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SA0013 - Public Advisory + + Mailman 2.1.8 Multiple Security Issues + + PUBLISHED ON Sep 13, 2006

[ GLSA 200609-10 ] DokuWiki: Arbitrary command execution

2006-09-14 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200609-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

XSS vulnerability in Blojsom

2006-09-14 Thread p3rlhax
I. BACKGROUND Taken from the Blojsom Website : Blojsom is a Java-based, full-featured, multi-blog, multi-user software package that was inspired by blosxom. blojsom aims to retain a simplicity in design while adding flexibility in areas such as the flavors, templating, plugins, and the

Secunia Research: Tagger LE PHP eval() Injection Vulnerabilities

2006-09-14 Thread Secunia Research
== Secunia Research 14/09/2006 - Tagger LE PHP eval() Injection Vulnerabilities - == Table of Contents Affected

[USN-346-2] Fixed linux-restricted-modules-2.6.15 for previous Linux kernel update

2006-09-14 Thread Martin Pitt
=== Ubuntu Security Notice USN-346-2 September 14, 2006 linux-restricted-modules-2.6.15 regression fix === A security issue affects the following Ubuntu releases: Ubuntu 6.06

Magic News Pro = 1.0.3 (script_path) Remote File Inclusion Exploit

2006-09-14 Thread saudi . unix
# #Magic News Pro = 1.0.3 (script_path) Remote File Inclusion Exploit # # #Critical Level : Dangerous # #By Saudi Hackrz # #http://www.reamdaysoft.com

Re: PHP Advanced Transfer Manager v1.20 ; Multiple Remote File Include Vulnerabilities

2006-09-14 Thread Carsten Eilers
Hi, (M.o.H.a.J.a.L.i) schrieb am Thu, 14 Sep 2006 02:17:53 +0300: Have You Tried it before commenting??? Of course, and include_location is initialized in 1.20 and 1.30. we know it has been initialized but it weirdly works... Which PHP/Webserver/System? Maybe it depends on special versions?

SIP over TLS: X.509 peer authentication vulnerability in Ingate products

2006-09-14 Thread Per Cederqvist
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SIP over TLS: X.509 peer authentication vulnerability in Ingate products Product: Ingate Firewall and Ingate SIParator Versions: all current versions Tracking ID: 2829 Summary

Fullpath disclosure in Blue Magic Board 5.5

2006-09-14 Thread hack2prison
Blue Magic Board (BMB) is nice forum system written by http://bmforum.com Some file error and show fullpath. I test newest version, maybe all older versions are infected. http://domain.ext/[bmb_path]/footer.php http://domain.ext/[bmb_path]/header.php

SolpotCrew Advisory #9 - phpQuiz v0.01 design and coding byJule Slootbeek (pagename) Remote File Inclusion

2006-09-14 Thread chris_hasibuan
#SolpotCrew Community # # phpQuiz v0.01 design and coding byJule Slootbeek (pagename) Remote File Inclusion # # Download file : http://www.furor-normannicus.de/phpQuiz/download/phpQuiz.zip #

Layered Defense Advisory :Symantec AntiVirus Corporate Edition Format String Vulnerability

2006-09-14 Thread dh
== Layered Defense Advisory 13 September 2006 == 1) Affected Software Symantec AntiVirus Corporate Edition 10.0 Symantec AntiVirus Corporate Edition 9.0 Symantec AntiVirus Corporate Edition

[security bulletin] HPSBUX02126 SSRT051019 rev.1 - HP-UX running X.25 Local Denial of Service (Dos)

2006-09-14 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c00705202 Version: 1 HPSBUX02126 SSRT051019 rev.1 - HP-UX running X.25 Local Denial of Service (Dos) NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Re: Snitz Forums 2000 v3.4.06

2006-09-14 Thread bob
Vender has supplied a fix: http://forum.snitz.com/forum/topic.asp?TOPIC_ID=62773

PhotoPost =4.6 (PP_PATH) Remote File Inclusion Exploit

2006-09-14 Thread saudi . unix
# #PhotoPost =4.6 (PP_PATH) Remote File Inclusion Exploit # # #Critical Level : Dangerous # #By Saudi Hackrz # #http://www.popphoto.com/ #