[Full-Disclosure] CactuSoft CactuShop v5.x shopping cart software multiple security vulnerabilities

2004-03-31 Thread S-Quadra Security Research
S-Quadra Advisory #2004-03-31 Topic: CactuSoft CactuShop v5.x shopping cart software multiple security vulnerabilities Severity: High Vendor URL: http://www.cactushop.com Advisory URL: http://www.s-quadra.com/advisories/Adv-20040331.txt Release date: 31 Mar 2004 1. DESCRIPTION CactuShop is

[Full-Disclosure] ModSecurity 1.7.4 for Apache 2.x remote off-by-one overflow

2004-03-16 Thread S-Quadra Security Research
S-Quadra Advisory #2004-03-15 Topic: ModSecurity 1.7.4 for Apache 2.x remote off-by-one overflow Severity: Average Vendor URL: http://www.modsecurity.org Advisory URL: http://www.s-quadra.com/advisories/Adv-20040315.txt Release date: 15 Mar 2004 1. DESCRIPTION ModSecurity is an open source intr

[Full-Disclosure] Dogpatch Software CFWebstore 5.0 shopping cart software multiple security vulnerabilities

2004-03-12 Thread S-Quadra Security Research
S-Quadra Advisory #2004-03-12 Topic: Dogpatch Software CFWebstore 5.0 shopping cart software multiple security vulnerabilities Severity: High Vendor URL: http://www.cfwebstore.com Advisory URL: http://www.s-quadra.com/advisories/Adv-20040312.txt Release date: 12 Mar 2004 1. DESCRIPTION "

[Full-Disclosure] Spider Sales shopping cart software multiple security vulnerabilities

2004-03-03 Thread S-Quadra Security Research
S-Quadra Advisory #2004-03-03 Topic: Spider Sales shopping cart software multiple security vulnerabilities Severity: High Vendor URL: http://www.spidersales.com Advisory URL: http://www.s-quadra.com/advisories/Adv-20040303.txt Release date: 03 Mar 2004 1. DESCRIPTION "Spider Sales is a pow

[Full-Disclosure] EarlyImpact ProductCart shopping cart software multiple security vulnerabilities

2004-02-16 Thread S-Quadra Security Research
S-Quadra Advisory #2004-02-16 Topic: EarlyImpact ProductCart shopping cart software multiple security vulnerabilities Severity: High Vendor URL: http://www.earlyimpact.com Advisory URL: http://www.s-quadra.com/advisories/Adv-20040216.txt Release date: 16 Feb 2004 1. DESCRIPTION ProductCar

[Full-Disclosure] CactuSoft CactuShop 5.0 Lite shopping cart software backdoor

2004-02-06 Thread S-Quadra Security Research
S-Quadra Advisory #2004-02-06 Topic: CactuSoft CactuShop 5.0 Lite shopping cart software backdoor Severity: High Vendor URL: http://www.cactushop.com Advisory URL: http://www.s-quadra.com/advisories/Adv-20040206.txt Release date: 06 Feb 2004 1. DESCRIPTION CactuShop is an ASP application fo

[Full-Disclosure] Re: QuadComm Q-Shop ASP Shopping Cart Software multiple security vulnerabilities

2004-01-26 Thread S-Quadra Security Research
Hello, The italian team for localization of Q-SHOP shopping cart software provided the patch for the Q-SHOP Euro (italian version of Q-SHOP). Patch is available at http://www.q-shop.it/patch/QSE_FIX_2004_01_26.zip Nick Gudov S-Quadra Security Research

[Full-Disclosure] QuadComm Q-Shop ASP Shopping Cart Software multiple security vulnerabilities

2004-01-23 Thread S-Quadra Security Research
S-Quadra Advisory #2004-01-23 Topic: QuadComm Q-Shop ASP Shopping Cart Software multiple security vulnerabilities Severity: High Vendor URL: http://www.quadcomm.com Advisory URL: http://www.s-quadra.com/advisories/Adv-20040123.txt Release date: 23 Jan 2004 1. DESCRIPTION Q-Shop is a shopping

[Full-Disclosure] @Mail web interface multiple security vulnerabilities

2003-12-09 Thread S-Quadra Security Research
S-Quadra Advisory #2003-12-09 Topic: @Mail web interface multiple security vulnerabilities Severity: Average Vendor URL: http://www.atmail.com Advisory URL: http://www.s-quadra.com/advisories/Adv-20031209.txt Release date: 09 Dec 2003 1. DESCRIPTION "@Mail is a feature rich Email so

[Full-Disclosure] GnuPG 1.2.3, 1.3.3 external HKP interface format string issue

2003-12-03 Thread S-Quadra Security Research
S-Quadra Advisory #2003-12-03 Topic: GnuPG 1.2.3, 1.3.3 external HKP interface format string issue Severity: Low Vendor URL: http://www.gnupg.org Advisory URL: http://www.s-quadra.com/advisories/Adv-20031203.txt Release date: 3 Dec 2003 1. DESCRIPTION GnuPG is a complete and

[Full-Disclosure] Virtual Programming VP-ASP Shopping Cart 5.0 multiple SQL Injection Vulnerabilities

2003-12-01 Thread S-Quadra Security Research
S-Quadra Advisory #2003-11-28 Topic: Virtual Programming VP-ASP Shopping Cart 5.0 multiple SQL Injection Vulnerabilities Severity: Average Vendor URL: http://www.vpasp.com Advisory URL: http://www.s-quadra.com/advisories/Adv-20031128.txt Release date: 28 Nov 2003 1. DESCRIPTION Virtual P

[Full-Disclosure] FreeRADIUS <= 0.9.3 rlm_smb module stack overflow vulnerability

2003-11-26 Thread S-Quadra Security Research
S-Quadra Advisory #2003-11-26 Topic: FreeRADIUS <= 0.9.3 rlm_smb module stack overflow vulnerability Severity: High Vendor URL: http://www.freeradius.org Advisory URL: http://www.s-quadra.com/advisories/Adv-20031126.txt Release date: 26 Nov 2003 1. DESCRIPTION The FreeRADIUS

[Full-Disclosure] Monit 4.1 HTTP interface multiple security vulnerabilities

2003-11-24 Thread S-Quadra Security Research
S-Quadra Advisory #2003-11-24 Topic: Monit 4.1 HTTP interface Multiple Security Vulnerabilities Severity: High Vendor URL: http://www.tildeslash.com/monit/ Advisory URL: http://www.s-quadra.com/advisories/Adv-20031124.txt Release date: 22 Nov 2003 1. DESCRIPTION Monit (http://

[Full-Disclosure] FreeRADIUS 0.9.2 "Tunnel-Password" attribute handling vulnerability

2003-11-21 Thread S-Quadra Security Research
S-Quadra Vendor Report #2003-11-21 Topic: FreeRADIUS 0.9.2 "Tunnel-Password" attribute Handling Vulnerability Severity: Average Release date: 21 Nov 2003 1. DESCRIPTION The FreeRADIUS Server (http://www.freeradius.org) is a high-performance and highly configurable GPL'd free