[Full-disclosure] High security hole in NullLogic Groupware
- From: Tim Brown <timb@xxxxxxxxxxxxxxxxxxxx>
- Date: Mon, 6 Jul 2009 01:50:52 +0100
Hi,
I've identified a couple of security flaws affecting the NullLogic Groupware
which may allow compromise of accounts, denial of service or even remote code
execution. These issues were reported by email to the developer but no
response was forthcoming.
Tim
--
Tim Brown
<mailto:timb@xxxxxxxxxxxxxxxxxxxx>
<http://www.nth-dimension.org.uk/>
Attachment:
NDSA20090413.txt.asc
Description: application/pgp-keys
Attachment:
signature.asc
Description: This is a digitally signed message part.
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- Prev by Date: [Full-disclosure] Medium security hole in TekRADIUS
- Next by Date: [Full-disclosure] [SECURITY] [DSA 1827-1] New ipplan packages fix cross-site scripting
- Previous by thread: [Full-disclosure] Medium security hole in TekRADIUS
- Next by thread: [Full-disclosure] [SECURITY] [DSA 1827-1] New ipplan packages fix cross-site scripting
- Index(es):
Relevant Pages
|