[Full-disclosure] Persistant XSS Vulnerability in rediff

2010-02-01 Thread rockey killer
*About Redif*f Rediff.com (Nasdaq: REDF) is one of the premier worldwide online providers of news, information, communication, entertainment and shopping services. Rediff.com provides a platform for Indians worldwide to connect with one another online. Rediff.com is committed to offering a

[Full-disclosure] XSS vulnerability in Drupal's MP3 Player contributed module (version 6.x-1.0-beta1)

2010-02-01 Thread Martin Barbella
XSS vulnerability in Drupal's MP3 Player contributed module (version 6.x-1.0-beta1) Discovered by Martin Barbella martybarbe...@gmail.com Description of Vulnerability: - Drupal is a free software package that allows an individual or a community of users to easily

[Full-disclosure] [ MDVSA-2010:030 ] kernel

2010-02-01 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:030 http://www.mandriva.com/security/

[Full-disclosure] Seagate Black Armor security issue

2010-02-01 Thread Jason Ellison
List, I found a security issue on a Seagate Black Armor 440 NAS. I'm looking for a PoC at Seagate to discuss this issue. Jason Ellison ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and

[Full-disclosure] iDefense Security Advisory 02.01.10: RealNetworks RealPlayer 11 HTTP Chunked Encoding Integer Overflow Vulnerability

2010-02-01 Thread iDefense Labs
iDefense Security Advisory 02.01.10 http://labs.idefense.com/intelligence/vulnerabilities/ Feb 01, 2010 I. BACKGROUND RealPlayer is an application for playing various media formats, developed by RealNetworks Inc. Since late 2003, Real Player has been based on the open-source Helix Player. More

[Full-disclosure] [CORE-2010-0106] Cisco Secure Desktop XSS/JavaScript Injection

2010-02-01 Thread Core Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://www.coresecurity.com/corelabs/ Cisco Secure Desktop XSS/JavaScript Injection 1. *Advisory Information* Title: Cisco Secure Desktop XSS/JavaScript Injection Advisory Id:

[Full-disclosure] iDefense Security Advisory 02.01.10: RealNetworks RealPlayer CMediumBlockAllocator Integer Overflow Vulnerability

2010-02-01 Thread iDefense Labs
iDefense Security Advisory 02.01.10 http://labs.idefense.com/intelligence/vulnerabilities/ Feb 01, 2010 I. BACKGROUND RealPlayer is an application for playing various media formats, developed by RealNetworks Inc. Since late 2003, Real Player has been based on the open-source Helix Player. More

[Full-disclosure] iDefense Security Advisory 02.01.10: Real Networks RealPlayer Compressed GIF Handling Integer Overflow

2010-02-01 Thread iDefense Labs
iDefense Security Advisory 02.01.10 http://labs.idefense.com/intelligence/vulnerabilities/ Feb 01, 2010 I. BACKGROUND RealPlayer is an application for playing various media formats, developed by RealNetworks Inc. Since late 2003, Real Player has been based on the open-source Helix Player. More

[Full-disclosure] [CORE-2009-1126] Corel Paint Shop Pro Photo X2 FPX Heap Overflow

2010-02-01 Thread CORE Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://www.coresecurity.com/corelabs/ Corel Paint Shop Pro Photo X2 FPX Heap Overflow 1. *Advisory Information* Title: Corel Paint Shop Pro Photo X2 FPX Heap Overflow Advisory

Re: [Full-disclosure] Persistant XSS Vulnerability in rediff

2010-02-01 Thread Jeff Williams
Hey Mustlive, if you still alive you should talk about this on your blog :) 2010/2/2 rockey killer skg...@gmail.com *About Redif*f Rediff.com (Nasdaq: REDF) is one of the premier worldwide online providers of news, information, communication, entertainment and shopping services. Rediff.com

[Full-disclosure] Internet attack defense: License and registration please...

2010-02-01 Thread Ivan .
Your documents please? http://government.zdnet.com/?p=6934 ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/