[Full-disclosure] Vulnerability Centreon IT Network Monitoring v2.1.5

2010-04-02 Thread Mehdi Mahdjoub - Sysdream IT Security Services
#!/usr/bin/perl # //[PoC]-// # # Title : Centreon IT Network Monitoring v2.1.5 - Injection SQL # Version : 2.1.5 # Author : Jonathan Salwan (j.sal...@sysdream.com) # # # [Vuln sql injection] # http://localhost/centreon/main.php?p=201host_id=-1%20[SQL Injection]o=pmin=1 # #

[Full-disclosure] Vulnerability Astaro Security Linux v5

2010-03-23 Thread Mehdi Mahdjoub - Sysdream IT Security Services
Program : Astaro Security Linux v5 PoC : XSS Homepage : http://www.astaro.com/ Found by : Vincent Hautot Contact : v.hautot () sysdream com //- Application description Astaro Security Linux is a complete network security solution that protects

[Full-disclosure] Vulnerability Httpdx v1.5.3b

2010-03-19 Thread Mehdi Mahdjoub - Sysdream IT Security Services
Program : Httpdx v1.5.3b PoC : Remote Crash Service (if http.log=1) Homepage : http://sourceforge.net/projects/httpdx/ Found by : Jonathan Salwan This Advisory: Jonathan Salwan Contact : j.sal...@sysdream.com //- Application description