dedecms v5.3 Arbitrary File Upload Vulnerability

2009-06-30 Thread info
# Securitylab.ir # Application Info: # Name: dedecms # Version: v5.3 # Website: http://dedecms.com # # Discoverd By: Securitylab.ir # Website: http://securitylab.ir # Contacts: a

Empire Cms 5.1 sql injection

2009-06-30 Thread info
# Securitylab.ir # Application Info: # Name: Empire Cms # Version: 5.1 # Download: http://www.phome.net/OpenSource/download/EmpireCMS_5.1os_SC_GBK.zip # # Discoverd By: Securitylab

[ MDVSA-2009:147 ] pidgin

2009-06-30 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:147 http://www.mandriva.com/security/

Re: SIPS v0.2.2 Remote File Inclusion Vulnerability

2009-06-30 Thread Joe
On Tue, 30 Jun 2009, Cru3l.b0y wrote: Software : SIPS v0.2.2 Vendor : http://www.phpscripts-fr.net/scripts/hosted/sips022.zip This is not the vendor. This is YAPSI (Yet Another Php Script Index) SIPS was up to v0.3.1 as of 2005: http://sourceforge.net/projects/sips/

XAMPP for Windows (Xss/PHPinfo) Multiple Vulnerability

2009-06-30 Thread Cru3l.b0y
Hi Dear, I found new bug.please publish it.exploit attached to mail. Best Regards. # XAMPP for Windows (Xss/PHPinfo) Multiple Vulnerability # AUTHOR : Cru3l.b0y # DATE: 05 APR 2009 # SITE: WwW.DeltaHacking.Net # CONTACT : cru3l@deltahacking.net ###

Re: SIPS v0.2.2 Remote File Inclusion Vulnerability

2009-06-30 Thread Vladimir '3APA3A' Dubrovin
Dear Cru3l.b0y, This vulnerability was reported by the.leo.008_(at)_gmail.com 3 years ago: http://securityvulns.com/Odocument224.html --Tuesday, June 30, 2009, 7:20:48 PM, you wrote to bugtraq@securityfocus.com: Cb> Hi Dear, Cb> Please publish this bug. Cb> Thank you -- Skype: Vladimir.Du

SIPS v0.2.2 Remote File Inclusion Vulnerability

2009-06-30 Thread Cru3l.b0y
Hi Dear, Please publish this bug. Thank you /===\ |

[ GLSA 200906-05 ] Wireshark: Multiple vulnerabilities

2009-06-30 Thread Tobias Heinlein
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200906-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

Multiple Flaws in Huawei D100

2009-06-30 Thread filip . palian
Multiple Flaws in Huawei D100 by Filip Palian http://192.168.1.1/en/lan_status_adv.asp http://192.168.1.1/en/wlan_basic_cfg.asp http://192.168.1.1/en/lancfg.asp #9 Telnet service enabled by default Anyone in LAN is able to log in using default admin:admin account with root privileges. There is n

[ GLSA 200906-04 ] Apache Tomcat JK Connector: Information disclosure

2009-06-30 Thread Alex Legler
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200906-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[ GLSA 200906-03 ] phpMyAdmin: Multiple vulnerabilities

2009-06-30 Thread Alex Legler
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200906-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -