what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 25 of 34 RSS Feed

Files Date: 2008-09-18 to 2008-09-19

Secunia Security Advisory 31939
Posted Sep 18, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - SuSE has issued an update for gnutls. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise an application using the library.

tags | advisory, denial of service, vulnerability
systems | linux, suse
SHA-256 | f7439decc209fe72313177d2058ab25b5ac8e153b32e26f1be6f301db3c5893c
webhost-database.txt
Posted Sep 18, 2008
Authored by r45c4l | Site darkc0de.com

HyperStop WebHost suffers from an arbitrary database backup vulnerability.

tags | exploit, arbitrary
SHA-256 | 91f2df240a01bfe12144215ba967d991cc02352b3e92ffd31a33f251cc78c247
vitags-exec.txt
Posted Sep 18, 2008
Authored by Eli the Bearded

vi and ex appear to suffer from an arbitrary code execution vulnerability via the tags file.

tags | advisory, arbitrary, code execution
SHA-256 | 8e4fe4e30f1f789cf10e78023c7e75eb49e76cb5d096c0fcdd86bfc30ecfecd3
Ubuntu Security Notice 646-1
Posted Sep 18, 2008
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 646-1 - It was discovered that rdesktop did not properly validate the length of packet headers when processing RDP requests. If a user were tricked into connecting to a malicious server, an attacker could cause a denial of service or possible execute arbitrary code with the privileges of the user. Multiple buffer overflows were discovered in rdesktop when processing RDP redirect requests. If a user were tricked into connecting to a malicious server, an attacker could cause a denial of service or possible execute arbitrary code with the privileges of the user. It was discovered that rdesktop performed a signed integer comparison when reallocating dynamic buffers which could result in a heap-based overflow. If a user were tricked into connecting to a malicious server, an attacker could cause a denial of service or possible execute arbitrary code with the privileges of the user.

tags | advisory, denial of service, overflow, arbitrary
systems | linux, ubuntu
advisories | CVE-2008-1801, CVE-2008-1802, CVE-2008-1803
SHA-256 | 1a39857e464c47ce103fd843802e8f3ac9a25c778331cb477c908a2d3d530407
Secunia Security Advisory 31899
Posted Sep 18, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in FFmpeg, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).

tags | advisory, denial of service
SHA-256 | e313a27c9be6b7627b5e34f6b8fa78311efbeb76b4ca54117767ecd2796f036b
Secunia Security Advisory 31908
Posted Sep 18, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Two vulnerabilities have been reported in the Talk module for Drupal, which can be exploited by malicious users to conduct script insertion attacks, and by malicious people to bypass certain security restrictions.

tags | advisory, vulnerability
SHA-256 | 15cd4ad0e529a13588c84a2736fd216bee92e36420e866b799a5f176d1b61387
Secunia Security Advisory 31914
Posted Sep 18, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Justin C. Klein Keane has reported a vulnerability in the Link To Us module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.

tags | advisory
SHA-256 | 9be0b0fbb309b1fde4184359abb6c4e8aabaab768f6f7dc8e453707c43b3b44c
Secunia Security Advisory 31918
Posted Sep 18, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - A vulnerability has been reported in the phpMyAdmin extension for TYPO3, which can be exploited by malicious users to compromise a vulnerable system.

tags | advisory
SHA-256 | 94d2baaf1e2ae117658880f0d5f7ff6850ed6c33dd447cb9bcf2c5414fea8b34
Secunia Security Advisory 31938
Posted Sep 18, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - John Cobb has discovered a vulnerability in Quick.Cart, which can be exploited by malicious people to conduct cross-site scripting attacks.

tags | advisory, xss
SHA-256 | 3244c4ba85368ca46c7a69ab6fd1a8f9a076564c4299c552773bfadc861a66da
Mandriva Linux Security Advisory 2008-189
Posted Sep 18, 2008
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory - Multiple vulnerabilities were discovered in ClamAV and corrected with the 0.94 release. A vulnerability in ClamAV's chm-parser allowed remote attackers to cause a denial of service (application crash) via a malformed CHM file. A vulnerability in libclamav would allow attackers to cause a denial of service via vectors related to an out-of-memory condition. Multiple memory leaks were found in ClamAV that could possibly allow attackers to cause a denial of service via excessive memory consumption. A number of unspecified vulnerabilities in ClamAV were reported that have an unknown impact and attack vectors related to file descriptor leaks. Other bugs have also been corrected in 0.94 which is being provided with this update. Because this new version has increased the major of the libclamav library, updated dependent packages are also being provided. The previous update had experimental support enabled, which caused ClamAV to report the version as 0.94-exp rather than 0.94, causing ClamAV to produce bogus warnings about the installation being outdated. This update corrects that problem.

tags | advisory, remote, denial of service, vulnerability, memory leak
systems | linux, mandriva
advisories | CVE-2008-1389, CVE-2008-3912, CVE-2008-3913, CVE-2008-3914
SHA-256 | 7fed0fc5a456da386e0f0d493038985b933c7c0ca06e6ca0f353d56bc41c15fe
alcomediacms-default.txt
Posted Sep 18, 2008
Authored by baltazar, sinner_01 | Site darkc0de.com

Alcomedia CMS has a default administrative login left in it upon installation.

tags | exploit
SHA-256 | ea4c805419e39d3b2ee1f6d726a302882ed43bcc3546f32264e6be9bae4539c4
wan-sql.txt
Posted Sep 18, 2008
Authored by baltazar, sinner_01 | Site darkc0de.com

The World Association of Newspapers suffers from a remote SQL injection vulnerability in articles.php.

tags | exploit, remote, php, sql injection
SHA-256 | fee366ae992c786a3161cbe7d11678cc706d379c414b7b825b86f3682809d178
IVIZ-08-010.txt
Posted Sep 18, 2008
Authored by Jonathan Brossard | Site ivizsecurity.com

The password checking routine of SafeBoot Device Encryption fails to sanitize the BIOS keyboard buffer after reading passwords, resulting in plain text password leakage to unprivileged local users. Affected is McAfee Safeboot Device Encryption version 4, Build 4750 and below.

tags | advisory, local
SHA-256 | 78a8f15592e7899a1c913eeb459f8791629f0e1831fb0927ed20feae27499353
proactive-lfi.txt
Posted Sep 18, 2008
Authored by r45c4l | Site darkc0de.com

ProActive CMS suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | c9846d2ae423ae1ad4d13dcbe643b396a8cc054b3d6d0e7cb07107209dc5b324
Secunia Security Advisory 31923
Posted Sep 18, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - HaCker_Egy has reported a vulnerability in E-Php Content Management System, which can be exploited by malicious people to conduct SQL injection attacks.

tags | advisory, php, sql injection
SHA-256 | c64e4906acbad306d3d79004dfa9dbcde299f65714e0d9a3c3d0a912970017b2
sama-xss.txt
Posted Sep 18, 2008
Authored by Lagon666

The Sama Educational Management System suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 3d61ffe060557cc9b43397d81bedf6a4cc68db7a50191d85c6d8099e2a1d143f
drupallink-xss.txt
Posted Sep 18, 2008
Authored by Mad Irish | Site madirish.net

The Link to Us module in Drupal suffers from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | 5fbf55a40e4ec7f225239908cfb63b65ea1cd612ae872293125c575b5ae480f8
HP Security Bulletin 2008-00.78
Posted Sep 18, 2008
Authored by Hewlett Packard | Site hp.com

HP Security Bulletin - A potential security vulnerability has been identified with HP OpenVMS SMGRTL Run Time Library. The vulnerability could be exploited locally by an authorized user to gain extended privileges.

tags | advisory
advisories | CVE-2008-3540
SHA-256 | b6bcce69547bc1df33441518cef314abf988c2f1bf7333d21aecb1881dc7a48d
menalto-hijack.txt
Posted Sep 18, 2008
Authored by Hanno Boeck | Site hboeck.de

Menalto Gallery versions prior to 2.2.6 failed to set the secure flag in the session cookie allowing for session hijacking.

tags | advisory
advisories | CVE-2008-3662
SHA-256 | abff3ad67ab14ebf55f9da0c0e8959080407847a2106e0bb1f87d45c942811ac
cyask-disclose.txt
Posted Sep 18, 2008
Authored by xy7

CYASK version 3.x suffers form a local file disclosure vulnerability in collect.php.

tags | exploit, local, php, info disclosure
SHA-256 | 906f1c59e697d9ab71c6ce749a8b5ca2a357dcc52ec4429b7b22316f1f6c5804
jokescripts-sql.txt
Posted Sep 18, 2008
Authored by sarbot511

Diesel Joke Site suffers from a remote SQL injection vulnerability in picture_category.php.

tags | exploit, remote, php, sql injection
SHA-256 | 915d6d4b6ab21a487c553c1ad66f4fc4cb48c1be094e0e78df8a061ddf503a7b
proarcade-sql.txt
Posted Sep 18, 2008
Authored by SuNHouSe2

ProArcadeScript version 1.3 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | d44522cbdc96b2b533c8bca54fbfe7e615972c179d9b8f69981dfe5aedf290f2
addalink-sql.txt
Posted Sep 18, 2008
Authored by ka0x

Addalink versions 4 and below suffer form a remote SQL injection vulnerability.

tags | exploit, remote, sql injection
SHA-256 | f67eacd3340319df0287d05c6431ff7bc8814ea7a330dc8b346b70f53c013389
Secunia Security Advisory 31788
Posted Sep 18, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - SirGod has discovered a vulnerability in iScripts EasyIndex, which can be exploited by malicious people to conduct SQL injection attacks.

tags | advisory, sql injection
SHA-256 | 627cdfd31060885cc95f9631c0a89d4545350cad49971e918590830d128df7f7
Secunia Security Advisory 31852
Posted Sep 18, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Shinnok raydenxy has discovered a vulnerability in Personal FTP Server, which can be exploited by malicious users to cause a DoS (Denial of Service).

tags | advisory, denial of service
SHA-256 | ca49574c61af6f0c3031b4f9667832add9f7a95deb164b3debea4a1ad220c240
Page 1 of 2
Back12Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close