Bugtraq
- TextFileBB 1.0.16 Multiple XSS
- TopList <= 1.3.8 (PHPBB Hack) Remote File Inclusion Vulnerability
- XSS Attack On DirectAdmin Hosting Managment
- W-Agora 4.20 XSS
- poll.pl<--remote commands execution exploit
- Invision Power Board 2.1.5 POC
- Re: phpMyForum Cross Site Scripting & CRLF injection
- Re: Recent Oracle exploit is _actually_ an 0day with no patch
- Re: Apple Mac OS X Safari 2.0.3 Vulnerability
- RE: Invision Vulnerabilities, including remote code execution
- Re: VWar Path Disclosure
- [Kurdish Secure Advisory #1] I-RATER Platinum "Admin/configsettings.tpl.php" Remote File Include Vulnerability
- Neomail.pl Local Cross Site Scripting
- RE: Recent Oracle exploit is _actually_ an 0day with no patch
- From: Kornbrust, Alexander
- Re: Recent Oracle exploit is _actually_ an 0day with no patch
- [Kurdish Security #2] Artmedic Event Remote File Include Vulnerability
- [ GLSA 200604-18 ] Mozilla Suite: Multiple vulnerabilities
- [Kurdish Security #3] CoolMenus Event Remote File Include Vulnerability (For PHP)
- Re: Recent Oracle exploit is _actually_ an 0day with no patch
- [Argeniss] Alert - Yahoo! Mail XSS vulnerability
- WinISO/UltraISO/MagicISO/PowerISO Directory Traversal Vulnerability
- [ECHO_ADV_31$2006] Sws Web Server 0.1.7 Strcpy() & Syslog() Format String Vulnerability
- Secunia Research: Servant Salamander unacev2.dll Buffer Overflow Vulnerability
- Cireos Portal Cross Site Scripting
- Re: Recent Oracle exploit is _actually_ an 0day with no patch
- BL4's SMTP server BufferOverflow Vulnerable
- [SECURITY] [DSA 1046-1] New Mozilla packages fix several vulnerabilities
- [SECURITY] [DSA 1045-1] New OpenVPN packages fix arbitrary code execution
- [USN-275-1] Mozilla vulnerabilities
- Re: Instant Photo Gallery <= Multiple XSS
- SQL injection exploit IPB <= 2.1.4
- [security bulletin] HPSBMA02113 SSRT061148 rev.1 - HP Oracle for OpenView (OfO) Critical Patch Update April 2006
- Re: Instant Photo Gallery <= Multiple XSS
- From: security curmudgeon
- [ GLSA 200604-17 ] Ethereal: Multiple vulnerabilities in protocol dissectors
- From: Sune Kloppenborg Jeppesen
- [security bulletin] HPSBUX02075 SSRT051074 rev.4 - HP-UX Running xterm Local Unauthorized Access
- [security bulletin] HPSBUX02108 SSRT061133 rev.9 - HP-UX running Sendmail, Remote Execution of Arbitrary Code
- Land Down Under 802 and below version Path Disclosure Vulnerability
- [USN-274-1] MySQL vulnerability
-
- MyBB 1.1.1 Local SQL Injections
- Re: Invision Vulnerabilities, including remote code execution
- Re: Apple Mac OS X Safari 2.0.3 Vulnerability
- [EEYEB-20060227] Juniper Networks SSL-VPN Client Buffer Overflow
- Re: Invision Vulnerabilities, including remote code execution
- Re: XV multiple buffer overflows (update)
- Re: Apple Mac OS X Safari 2.0.3 Vulnerability
- ZDI-06-011: Mozilla Firefox Table Rebuilding Code Execution Vulnerability
- Local XXS Attack On CuteNews
- XXS Attack On FarsiNews
- Open Bulletin Board < Multiple Vulnerability
- SQL Injection On DUportal
- [eVuln] warforge.NEWS SQL Injection and Multiple XSS Vulnerabilities
- [SECURITY] [DSA 1043-1] New abcmidi packages fix arbitrary code execution
- [ GLSA 200604-15 ] xine-ui: Format string vulnerabilities
- From: Sune Kloppenborg Jeppesen
- Secunia Research: SpeedProject Products ACE Archive Handling Buffer Overflow
- [SECURITY] [DSA 1044-1] New Mozilla Firefox packages fix several vulnerabilities
- [ GLSA 200604-16 ] xine-lib: Buffer overflow vulnerability
- From: Sune Kloppenborg Jeppesen
- DevBB <= 1.0.0 XSS
- MySmartBB<---v 1.1.x SQL Injection/XSS
- [SECURITY] [DSA 1044-1] New Mozilla Firefox packages fix several vulnerabilities
- Cisco Security Advisory: Cisco VPN 3000 Concentrator Vulnerable to Crafted HTTP Attack
- From: Cisco Systems Product Security Incident Response Team
- [ MDKSA-2006:079 ] - Updated ruby packages fix vulnerability
- [ MDKSA-2006:078 ] - Updated mozilla-thunderbird packages fix numerous vulnerabilities
- [ MDKSA-2006:077 ] - Updated ethereal packages fix numerous vulnerabilities
- [ MDKSA-2006:076 ] - Updated mozilla packages fix numerous vulnerabilities
- Recent Oracle exploit is _actually_ an 0day with no patch
- DCForumLite V 3.0<--XSS/SQL Injection
- Instant Photo Gallery <= Multiple XSS
- Re: Apple Mac OS X Safari 2.0.3 Vulnerability
- Instant Photo Gallery <= Multiple XSS
- Multiple browsers Windows mailto protocol Office 2003 file attachment exploit
- Re: Advisory: Clansys <= 1.1 PHP Code Insertion Vulnerability.
- RE: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Multiple vulnerabilities in IP3 Networks 'NetAccess' NA75 appliance
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Thor (Hammer of God)
- PowerPoint Phishing Trojan
- Fenice - Open Media Streaming Server remote BOF exploit
- Re: NASL 'Split' function Buffer overflow Vulnerability
- [SECURITY] [DSA 1042-1] New Cyrus SASL packages fix denial of service
- Re: NASL 'Split' function Buffer overflow Vulnerability
- Re: Apple Mac OS X Safari 2.0.3 Vulnerability
- Invision Vulnerabilities, including remote code execution
- Re: ADVISORY FOR IOPUS SECURE EMAIL ATTACHMENTS
- Re: ADVISORY FOR IOPUS SECURE EMAIL ATTACHMENTS
- NASL 'Split' function Buffer overflow Vulnerability
- [SECURITY] [DSA 1041-1] New abc2ps packages fix arbitrary code execution
- PhpWebFtp Cross Site Scripting Vulnerability
- [ MDKSA-2006:075 ] - Updated mozilla-firefox packages fix numerous vulnerabilities
- NextAge Shopping Cart Software XSS
- photokorn 1.53 , 1.542 << Sql
- [ MDKSA-2006:073 ] - Updated cyrus-sasl packages addresses vulnerability
- [ MDKSA-2006:074 ] - Updated php packages address multiple vulnerabilities.
- Re: vbulletin<--3.0.x SQL Injection
- Re: Apple Mac OS X Safari 2.0.3 Vulnerability
- Quick 'n Easy FTP Server pro/lite Logging unicode stack overflow
- RE: [BULK] - Websense Filter Bypass
- ADVISORY FOR IOPUS SECURE EMAIL ATTACHMENTS
- Advisory: My Gaming Ladder Combo System <= 7.0 Remote File Inclusion Vulnerability.
- From: Mustafa Can Bjorn IPEKCI
- vbulletin<--3.0.x SQL Injection
- VWar Path Disclosure
- [MajorSecurity] phpMyAgenda 3.0 Final - Remote File Include Vulnerability
- Firefox Remote Code Execution and DoS 1.5.0.2
- Apple Mac OS X Safari 2.0.3 Vulnerability
- Advisory: Clansys <= 1.1 PHP Code Insertion Vulnerability.
- From: Mustafa Can Bjorn IPEKCI
- Format string bug in Skulltag 0.96f
- Multiple PHP4/PHP5 vulnerabilities
- Denial of service bugs in OpenTTD 0.4.7
- Buffer-overflow and crash in Fenice OMS 1.10
- Re: evoBlog Remote Name tag Script injection
- RIblog Remote SQL Injection Exploit
- [MajorSecurity] TotalCalendar 2.30 - Remote File Include Vulnerability
- [USN-273-1] Ruby vulnerability
- BK Forum <= 4.0 Remote SQL Injection
- XSS Bug in OpenGear Server Website
- FileLodge Bolt (showonlineusers.php) Cross-Site Scripting Vulnerbility
- [ GLSA 200604-12 ] Mozilla Firefox: Multiple vulnerabilities
- [eVuln] RateIt SQL Injection Vulnerability
- [ GLSA 200604-13 ] fbida: Insecure temporary file creation
- From: Sune Kloppenborg Jeppesen
- [ GLSA 200604-14 ] Dia: Arbitrary code execution through XFig import
- From: Sune Kloppenborg Jeppesen
- Scry Gallery XSS Vulnerability
- [SECURITY] [DSA 1039-1] New blender packages fix several vulnerabilities
- [SECURITY] [DSA 1040-1] New gdm packages fix local root exploit
- NSFOCUS SA2006-02 : IBM AIX mklvcopy Local Privilege Escalation Vulnerability
- From: NSFOCUS Security Team
- NSFOCUS SA2006-03 : IBM AIX rm_mlcache_file Local Race Condition Vulnerability
- From: NSFOCUS Security Team
- [USN-272-1] cyrus-sasl2 vulnerability
- MSIE (mshtml.dll) OBJECT tag vulnerability
- Yahoo! Mail XSS Vulnerability
- Re: redirection vuln crawlers breed & security through obscurity
- FlexBB 0.5.5 Exploit [ function/showprofile.php ] Remote SQL Injection
- Re: Strengthen OpenSSH security?
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Thor (Hammer of God)
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Thor (Hammer of God)
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Thor (Hammer of God)
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Thor (Hammer of God)
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Thor (Hammer of God)
- [ GLSA 200604-11 ] Crossfire server: Denial of Service and potential arbitrary code execution
- Advisory: CoreNews <= 2.0.1 Multiple Remote Vulnerabilities.
- From: Mustafa Can Bjorn IPEKCI
- Advisory: Simplog <= 0.93 Multiple Remote Vulnerabilities.
- From: Mustafa Can Bjorn IPEKCI
- vBulletin <= 3.5.4 with MKPortal 1.1 Remote SQL Injection Vulnerability.
- From: Mustafa Can Bjorn IPEKCI
- dForum <= 1.5 Multiple Remote File Inclusion Vulnerabilities.
- From: Mustafa Can Bjorn IPEKCI
- VWar <= ver 1.21 Remote Code Execution Exploit
- [SECURITY] [DSA 1038-1] New xzgv packages fix arbitrary code execution
- [Symantec Security Advisor] Symantec Scan Engine Multiple Vulnerabilities
- Rapid7 Advisory R7-0019: Directory traversal vulnerability in SolarWinds TFTP Server for Windows
- Rapid7 Advisory R7-0023: Symantec Scan Engine File Disclosure Vulnerability
- Rapid7 Advisory R7-0022: Symantec Scan Engine Known Immutable DSA Private Key
- Rapid7 Advisory R7-0021: Symantec Scan Engine Authentication Fundamental Design Error
- Scry Gallery Directory Traversal & Full Path Disclosure Vulnerabilites
- Re: Mini-NUKE v2.3<<--- SQL Injection
- [SECURITY] [DSA 1037-1] New zgv packages fix arbitrary code execution
- RE: [BULK] - Websense Filter Bypass
- bloggage Remote SQL Injection
- r57shell.php <= 1.3 XSS
- [eVuln] MWNewsletter SQL Injection and XSS Vulnerabilities
- Re: Strengthen OpenSSH security?
- BK Forum <<--V.4.0 SQL Injection
- [SecuriWeb 2006.1] directory traversal in Asterisk@Home and ARI
- [ GLSA 200604-10 ] zgv, xzgv: Heap overflow
- From: Sune Kloppenborg Jeppesen
- [ GLSA 200604-09 ] Cyrus-SASL: DIGEST-MD5 Pre-Authentication Denial of Service
- From: Sune Kloppenborg Jeppesen
- Mini-NUKE v2.3<<--- SQL Injection
- Re: Strengthen OpenSSH security?
- Websense Filter Bypass
- 4images <= 1.7 XSS
- RE: Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- RE: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- Re: Re[3]: Bypassing ISA Server 2004 with IPv6
- Re: Strengthen OpenSSH security?
- Re: Strengthen OpenSSH security?
- Re: Re[3]: Bypassing ISA Server 2004 with IPv6
- From: Thor (Hammer of God)
- Re: Strengthen OpenSSH security?
- Re: Strengthen OpenSSH security?
- Re: Strengthen OpenSSH security?
- [Argeniss] Oracle Database 10gR1 Buffer overflow in VERIFY_LOG procedure
- RE: (addendum) redirection vuln crawlers breed & security through obscurity
- Allied Telesyn Switch UDP Data Flood Management Denial Of Service Vulnerability
- New site about security conferences : www.security-briefings.com
- From: newslist@xxxxxxxxxxxxxxxxxxxxxx
- Ad-Aware Revisited
- [security bulletin] HPSBST02112 SSRT061129 rev.1 - HP StorageWorks Secure Path for Windows Remote Denial of Service (DoS)
- [security bulletin] HPSBTU02095 SSRT051007 rev.3 - HP Tru64 UNIX Running DNS BIND4/BIND8 as Forwarders: Remote Unauthorized Privileged Access
- Re: CuteNews 1.4.1 <= Cross Site Scripting
- axoverzicht.cgi<==Remote File Inclusion
- ThWboard 3 Beta 2.84 Cross Site Scripting
- PHPSurveyor <= 0.995 'save.php/surveyid' remote cmmnds xctn
- [eVuln] MWGuest XSS Vulnerability
- ASPSitem <= 1.83 Remote SQL Injection Vulnerability
- From: Mustafa Can Bjorn IPEKCI
- Strengthen OpenSSH security?
- [USN-271-1] Firefox vulnerabilities
- PCPIN Chat <= 5.0.4 "login/language" remote cmmnds xctn
- [eVuln] N.T. Version 1.1.0 XSS and PHP Code Insertion Vulnerabilities
- SQL Injection in incredibleindia.org
- Re: Re[2]: Bypassing ISA Server 2004 with IPv6
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- Re: Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- From: somerandomaddress99
- [eVuln] MD News Authentication Bypass and SQL Injection Vulnerabilities
- Re[3]: Bypassing ISA Server 2004 with IPv6
- EasyGallery Cross-Site Scripting
- Confixx SQL Injection exploit (confixx_exploit.pl)
- Re: Re[2]: Bypassing ISA Server 2004 with IPv6
- From: Thor (Hammer of God)
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- Re: RE: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- RE: redirection vuln crawlers breed & security through obscurity
- Tlen.PL e-mail XSS vulnerability.
- Re: Multiple Vulnerabilities in LucidCMS
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Fortinet28 box does not resist has small synflood!
- ContentBoxx Login.php Cross-Site Scripting
- Re: RE: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- WWWThread RC 3 MultBugs
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- redirection vuln crawlers breed & security through obscurity
- From: Ivan Sergio Borgonovo
- Shbablek Mail Vulnerablitiy - Cross-Site Scripting
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Re: phpBB Admin command execution
- Cisco Security Advisory: Multiple Vulnerabilities in the WLSE Appliance
- From: Cisco Systems Product Security Incident Response Team
- ThWboard <= 3 Beta 2.84 SQL Injection
- RechnungsZentrale V2 - SQL injection and Remote PHP inclusion vulnerabilities
- [security bulletin] HPSBUX02108 SSRT061133 rev.7 - HP-UX running Sendmail, Remote Execution of Arbitrary Code
- Re: [KAPDA::#41] - Mambo/Joomla rss component vulnerability
- Re: Path Disclosure and Arbitrary File Read Vulnerability in SLAB5000
- Cisco Security Advisory: Cisco IOS XR MPLS Vulnerabilities
- From: Cisco Systems Product Security Incident Response Team
- XSS Vulnerability in Guest-book script powered by Community Architect
- [MajorSecurity]ActualAnalyzer - Remote File Include Vulnerability
- Oracle 10g 10.2.0.2.0 DBA exploit
- FreeBSD Security Advisory FreeBSD-SA-06:14.fpu
- From: FreeBSD Security Advisories
- SQL Injection in package SYS.DBMS_LOGMNR_SESSION
- CuteNews 1.4.1 <= Cross Site Scripting
- Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- [Symantec Security Advisory] LiveUpdate for Macintosh Local Privilege Escalation
- Multiple critical and high risk issues in Oracle's database server
- From: NGSSoftware Insight Security Research
- [KAPDA::#41] - Mambo/Joomla rss component vulnerability
- phpLister v. 0.4.1 XSS Attacking
- [ MDKSA-2006:072 ] - Updated kernel packages fix multiple vulnerabilities
- Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Ansgar -59cobalt- Wiechers
- Re: [Full-disclosure] [Argeniss] Alert - Yahoo! Webmail XSS
- Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- blur6ex Local File Inclusion and SQL injection .
- axoverzicht.cgi <= XSS
- Another flaw in Firefox 1.5.0.2: to open files from remote
- Re: [Full-disclosure] [Argeniss] Alert - Yahoo! Webmail XSS
- Re: - PHPGraphy <= 0.9.11 "editwelcome" unauthorized access / cross site scripting -
- Remote Xine Format String Vulnerability
- Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- Linpha 1.1.0 - XSS Vulnerabilities
- RE: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- From: Forrest J. Cavalier III
- Re: gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- From: Michael Chamberlain
- [SA-03] Example of Grsecurity protection avoid.
- [eVuln] Wire Plastik wpBlog SQL Injection Vulnerability
- gcc 4.1 bug miscompiles pointer range checks, may place you at risk
- [Argeniss] Alert - Yahoo! Webmail XSS
- Neon Responder (Dos,Exploit)
- FlexBB 0.5.5 Bypass Exploit
- [ GLSA 200604-08 ] libapreq2: Denial of Service vulnerability
- ZDI-06-009: Mozilla Firefox Tag Parsing Code Execution Vulnerability
- AnimeGenesis <= XSS
- Tiny PHP forum - vulns
- [eVuln] CzarNews XSS and Multiple SQL Injection Vulnerabilities
- Neuron Blog <= 1.1 XSS
- ShoutBOOK <= 1.1 XSS
- - PHPGraphy <= 0.9.11 "editwelcome" unauthorized access / cross site scripting -
- [SECURITY] [DSA 1036-1] New bsdgames packages fix local privilege escalation
- PhpWebFTP 3.2 Login Script
- BetaBoard Cross Site Scripting vulnerability
- MyEvent Remote File Execution And XSS Attacking
- Re: Snipe Gallery <= 3.1.4 Multiple XSS
- Calendarix "yearcal.php" XSS Attacking
- FlexBB v0.5.5 BETA [SQL Inj] [XSS] [Login bypass]
- Xss In bMachine 2٫7
- Re: [KAPDA]CopperminePhotoGallery1.4.4~ PluginInclusionSystem(index.php)~ RemoteFileInclusion attack
- DbbS<=2.0-alpha Multiple Vulnerabilities
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- From: Thor (Hammer of God)
- Re: Vulnerabilities in MOD
- Snipe Gallery <= 3.1.4 Multiple XSS
- phpFaber TopSites Script Cross-Site Scripting
- Boardsolution <= 1.12 XSS
- FlexBB <= 0.5.7 BETA XSS
- PhpGuestbook <= 1.0 XSS
- Tiny Web Gallery <= 1.4 XSS
- RE: osCommerce "extras/" information/source code disclosure
- PHP Album <= 0.3.2.3 remote commnads execution
- Re[3]: Bypassing ISA Server 2004 with IPv6
- [SECURITY] [DSA 1035-1] New fcheck packages fix insecure temporary file creation
- [eVuln] aWebBB Multiple XSS and SQL Injection Vulnerabilities
- Re: Firefox 1.5.0.1 Password Manager Arbtirary User Browsing History Disclosure
- [KAPDA]CopperminePhotoGallery1.4.4~ PluginInclusionSystem(index.php)~ RemoteFileInclusion attack
- [KAPDA]MyBB1.1.0~global.php~ParameterExtracting
- ZDI-06-010: Mozilla Firefox CSS Letter-Spacing Heap Overflow Vulnerability
- Re: QuickBlogger v1.4 Cross-Site Scripting
- manila.userland cross site scriptable
- Dokeos 1.6.4 SQL Injection Vulnerability
- Re[2]: Bypassing ISA Server 2004 with IPv6
- a Yahoo Vulnerability
- Re: Sql Injection in Confixx 3.06 & 3.08 & 3.?? ?
- Re: SAXoPRESS - directory traversal aka Saxotech Online
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- Re: [ECHO_ADV_27$2006] Indexu <= 5.0.1 Remote File Inclusion
- planetSearch+ - XSS Vulnerabilities
- RE: [Full-disclosure] Microsoft DNS resolver: deliberately sabotagedhosts-file lookup
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- Xss In ar-blog v 5.2
- PAJAX Remote Code Injection and File Inclusion Vulnerability
- Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- From: Brandon S. Allbery KF8NH
- [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup
- Re: Re: NETGEAR WGT624 Wireless DSL router default user name/password vulnerability
- Re: phpWebSite 0.10.? (topics.php) Remote SQL Injection Exploit
- Re: [Full-disclosure] SEC Consult SA-20060314 :: Opera Browser CSS Attribute Integer Wrap / Buffer Overflow
- Firefox 1.5.0.1 Password Manager Arbtirary User Browsing History Disclosure
- [ GLSA 200604-07 ] Cacti: Multiple vulnerabilities in included ADOdb
- Avast Linux Home Edition (vulnerability on a temporary folder creation)
- Re: Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2
- phpBB template file code execution
- [SECURITY] [DSA 1034-1] New horde2 packages fix several vulnerabilities
- Serendipity Blog vuln
- phpBB Admin command execution
- Encyclopedia <= 3.0 (login.php) CrossSite Scripting - XSS
- Re: phpMyAdmin 2.7.0-pl1
- osCommerce "extras/" information/source code disclosure
- Farsinews Cross-Site Scripting & Path disclosure vulnerability
- Vulnerabilities in MODx
- Vulnerabilities in Papoo
- Vulnerabilities in lifetype
- [eVuln] aWebNews Multiple XSS and SQL Injection Vulnerabilities
- Re: Simplog <=0.9.2 multiple vulnerabilities
- PowerClan 1.14 - SQL Injection
- Camino Browser HTML Parsing Null Pointer Dereference Denial of Service Vulnerability
- [eVuln] RedCMS Multiple XSS and SQL Injection Vulnerabilities
- Re: RE: IBM
- TalentSoft Web+Shop Path Disclosure
- Re: IBM
- ZDI-06-008: Novell GroupWise Messenger Accept-Language Buffer Overflow
- SEC Consult SA-20060314 :: Opera Browser CSS Attribute Integer Wrap / Buffer Overflow
- SaphpLesson 2.0 (forumid) Remote SQL Injection Exploit
- MyBB 1.10 New CrossSiteScripting ' member.php '
- Re: Jupiter CMS <= 1.1.5 multiple XSS attack vectors.
- phpMyAdmin 2.7.0-pl1
- QuickBlogger v1.4 Cross-Site Scripting
- Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2
- RE: IBM
- Re: Confixx 3.1.2 <= SQL Injection
- MyBB 1.10 New XSS ' member.php '
- Recon 2006: speaker lineup announcement
- Re: google xss
- RevoBoard [email] tag XSS
- Re: Multiple vulnerabilities in Blur6ex
- phpWebSite 0.10.? (topics.php) Remote SQL Injection Exploit
- [BuHa-Security] Multiple Vulnerabilities in MS IE 6.0 SP2
- Remote File Inclusion in VBulletin ImpEx
- [BuHa-Security] Stack Based Buffer Overflow Vulnerability in Amaya 9.4 #2
- [BuHa-Security] Stack Based Buffer Overflow Vulnerability in Amaya 9.4
- [eVuln] qliteNews SQL Injection Vulnerability
- [BuHa-Security] DoS Vulnerability in Firefox 1.5.0.1
- Secunia Research: Adobe Document Server for Reader Extensions Multiple Vulnerabilities
- SimpleBBS v1.1(posts.php) remote command execution
- Windows Help Heap Overflow
- PatroNet CMS Xss Vuln
- Re: phpWebsite <= SQL Injection (friend.php) & (article.php)
- Clansys Multiple Xss Vulnerabilities
- [USN-270-1] xpdf vulnerabilities
- [security bulletin] HPSBUX02108 SSRT061133 rev.6 - HP-UX running Sendmail, Remote Execution of Arbitrary Code
- Vulnerability in Microsoft FrontPage Server Extensions Could Allow Cross-Site Scripting
- From: Esteban Martinez Fayo
- Exploiting out of memory crashes and null pointers [was: Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2]
- [SECURITY] [DSA 1033-1] New horde3 packages fix several vulnerabilities
- Simplog <=0.9.2 multiple vulnerabilities
- Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2
- [eVuln] QLnews XSS and PHP Code Insertion Vulnerabilities
- [SECURITY] [DSA 1032-1] New zope-cmfplone packages fix unprivileged data manipulation
- Re: Buffer-overflow in Ultr@VNC 1.0.1 viewer POC
- Microsoft Internet Explorer DBCS Remote Memory Corruption Vulnerability
- 2nd European Conference on Computer Network Defense (EC2ND)
- SAXoPRESS - directory traversal
- Re: google xss
- IT Underground, London 2006 - call for papers
- IMF 2006 - Submission Deadline Extension
- [ MDKSA-2006:070 ] - Updated openvpn packages fix vulnerability
- [ MDKSA-2006:071 ] - Updated xscreensaver packages fix clear-text password vulnerability
- Re: Bypassing ISA Server 2004 with IPv6
- AzDGVote File inclusion
- [SRC-Telindus advisory] - HP System Management Homepage Remote Unauthorized Access
- Re: Re: PHPList <= 2.10.2 remote commands execution
- Re: google xss
- [eVuln] VNews Multiple Vulnerabilities
- Tritanium Bulletin Board 1.2.3 - XSS
- IBM
- Confixx 3.1.2 <= SQL Injection
- Manila <= 9.5 - XSS Vulnerabilities
- ZDI-06-007: Microsoft Windows Address Book (WAB) File Format Parsing Vulnerability
- [eVuln] [V]Book Multiple Vulnerabilities
- Realplayer .SWF Multiple Remote Memory Corruption Vulnerabilities
- phpListPro <= 2.0 - Remote File Include Vulnerability
- Multiple vulnerabilities in Blur6ex
- [ MDKSA-2006:069 ] - Updated openvpn packages fix vulnerability
- INDEXU <= 5.0.1 (theme_path)and (base_path) Remote File Inclusion Exploit
- Confixx 3.1.2 <= Cross Site Scripting Vuln
- Re: function *() php/apache Crash PHP 4.4.2 and 5.1.2
- Re: PHPList <= 2.10.2 remote commands execution
- [USN-269-1] xscreensaver vulnerability
- PHPWebGallery Multiple Cross Site Scripting Vulnerabilities
- phpMyForum Cross Site Scripting & CRLF injection
- Jbook Cross Site Scripting
- [eVuln] phpNewsManager Multiple SQL Injections
- PHPList <= 2.10.2 remote commands execution
- Vegadns blind sql injection and cross site scripting
- Re: Bypassing ISA Server 2004 with IPv6
- From: Thor (Hammer of God)
- RE: google xss
- Re: Bypassing ISA Server 2004 with IPv6
- From: Thor (Hammer of God)
- Myspace.com - Intricate Script Injection
- MyBB 1.10 'newthread.php' < CrossSiteScripting >
- copy() Safe Mode Bypass PHP 4.4.2 and 5.1.2
- tempnam() open_basedir bypass PHP 4.4.2 and 5.1.2
- function *() php/apache Crash PHP 4.4.2 and 5.1.2
- phpinfo() Cross Site Scripting PHP 5.1.2 and 4.4.2
- PhpOpenChat 3.0.x ADODB Server.php "sql" SQL injection
- Vulnerabilities in SPIP
- TUGZip Archive Extraction Directory traversal
- Re[2]: Bypassing ISA Server 2004 with IPv6
- Oracle read-only user can insert/update/delete data via specially crafted views
- XMB Forum 1.9.5-Final XSS
- Re: IE6 Crash
- [Overflow.pl] Clam AntiVirus Win32-UPX Heap Overflow (not default configuration)
- IE6 Crash
- RE: recursive DNS servers DDoS as a growing DDoS problem
- [SECURITY] [DSA 1025-1] New dia packages fix arbitrary code execution
- [security bulletin] HPSBUX02111 SSRT061132 rev.1 - HP-UX su(1) Local Unauthorized Access
- [security bulletin] HPSBUX02110 SSRT061110 rev.1 - HP-UX Running wu-ftpd Remote Denial of Service (DoS)
- Re: Bios Information Leakage
- [SECURITY] [DSA 1023-1] New kaffeine packages fix arbitrary code execution
- Re: Buffer-overflow in Ultr@VNC 1.0.1 viewer and server
- [ GLSA 200604-06 ] ClamAV: Multiple vulnerabilities
- From: Sune Kloppenborg Jeppesen
- [SECURITY] [DSA 1026-1] New sash packages fix potential arbitrary code execution
- Multiple vulnerability in jupiter CMS
- [SECURITY] [DSA 1030-1] New moodle packages fix several vulnerabilities
- Re: Format string in Doomsday 1.8.6
- Cisco Security Advisory: Cisco Optical Networking System 15000 series and Cisco Transport Controller Vulnerabilities
- From: Cisco Systems Product Security Incident Response Team
- Virtual War File İnclusion
- Google Reader "preview" and "lens" script improper feed validation
- [SECURITY] [DSA 1029-1] New libphp-adodb packages fix several vulnerabilities
- XSS Bug in Cherokee Webserver
- Re: Flaw in commonly used bash random seed method
- Re: Another Internet Explorer Address Bar Spoofing Vulnerability
- [SECURITY] [DSA 1027-1] New mailman packages fix denial of service
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data
- Shadowed Portal Cross Site Scripting
- [ GLSA 200604-04 ] Kaffeine: Buffer overflow
- From: Sune Kloppenborg Jeppesen
- [eVuln] newsletter - sourceworkshop SQL Injection Vulnerability
- Re: recursive DNS servers DDoS as a growing DDoS problem
- [SECURITY] [DSA 1018-2] New Linux kernel 2.4.27 packages fix several vulnerabilities
- MAXDEV CMS Multiple vulnerabilities
- [ GLSA 200604-05 ] Doomsday: Format string vulnerability
- [ MDKSA-2006:067 ] - Updated clamav packages fix vulnerabilities
- [ECHO_ADV_28$2006] Clever Copy <= 3.0 Connect.inc Critical Information Disclosure
- [SECURITY] [DSA 1028-1] New libimager-perl packages fix denial of service
- Re: SQL injection in Invision Power Board v2.1.5
- PHPMyChat <= 0.14.5 remote commands execution
- LayerOne 2006 - Finalized Speaker Line-Up Announced
- [USN-268-1] Kaffeine vulnerability
- [eVuln] vCounter - sourceworkshop SQL Injection Vulnerability
- Matt Wright Guestbook Xss Script İnjection
- [ MDKSA-2006:065 ] - Updated kaffeine packages fix remote buffer overflow vulnerability
- PHPMyChat 0.15.0dev "SYS enter" remote commands xctn (not properly patched from previous versions)
- [eVuln] VSNS Lemon Multiple Vulnerabilities
- [KAPDA::#38] - MyBB 1.1.0~functions_post.php~XSS Attack
- Re: Re: Another Internet Explorer Address Bar Spoofing Vulnerability
- Re: recursive DNS servers DDoS as a growing DDoS problem
- [ MDKSA-2006:068 ] - Updated mplayer packages fix integer overflow vulnerabilities
- [security bulletin] HPSBUX02108 SSRT061133 rev.3 - HP-UX running Sendmail, Remote Execution of Arbitrary Code
- RE: Another way to spoof Internet Explorer Address Bar
- google xss
- [SECURITY] [DSA 946-2] New sudo packages fix privilege escalation
- [SECURITY] [DSA 1031-1] New cacti packages fix several vulnerabilities
- Welcome to XCon2006 in China!
- Re: Bypassing ISA Server 2004 with IPv6
- Re: FleXiBle Development Script Remote Command Exucetion And XSS Attacking
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Black Hat Call for Papers and Registration now open
- [Kaffeine Security Advisory] Heap based buffer overflow in http_peek()
- Sire 2.0 Nws Remote File inclusion & Arbitary Files Upload
- [eVuln] phpNewsManager Multiple SQL Injections
- SQL Injection in Chipmunk Guestbook
- Re: recursive DNS servers DDoS as a growing DDoS problem
- [Updated] [FLSA-2006:186277] Updated sendmail packages fix security issue
- [FLSA-2006:184098] Updated libc-client packages fixes security issue
- [FLSA-2006:184074] Updated pine package fixes security issue
- [eVuln] Null news SQL Injection Vulnerability
- [FLSA-2006:180159] Updated unzip package fixes security issue
- [FLSA-2006:183571-2] Updated tar package fixes security issue
- [FLSA-2006:183571-1] Updated tar package fixes security issue
- [FLSA-2006:170411] Updated imap packages fix security issue
- [FLSA-2006:156290] Updated cyrus-imapd packages fix security issues
- [FLSA-2006:156139] Updated tcpdump packages fix security issues
- Xss In SaphpLesson3.0
- Autonomous LAN party File iNclusion
- Re: Buffer-overflow in Ultr@VNC 1.0.1 viewer and server
- [ MDKSA-2006:066 ] - Updated FreeRADIUS packages fix off-by-one overflow vulnerabilty
- [FLSA-2006:152896] Updated mod_python package fixes a security issue
- Cisco Security Advisory: Cisco 11500 Content Services Switch HTTP Request Vulnerability
- From: Cisco Systems Product Security Incident Response Team
- [SECURITY] [DSA 1024-1] New clamav packages fix several vulnerabilities
- Re: Bypassing ISA Server 2004 with IPv6
- [FLSA-2006:152873] Updated xine package fixes security issues
- Re: Re: Bypassing ISA Server 2004 with IPv6
- Linux Kernel Local DoS vulnerability.
- Re: Flaw in commonly used bash random seed method
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data
- From: Jasper Bryant-Greene
- [ECHO_ADV_27$2006] AngelineCMS 0.8.1 Installpath Remote File Inclusion
- [SEC-1 LTD] HP Colour LaserJet 2500 and 4600 Toolbox Directory Traversal Vulnerability
- [ECHO_ADV_27$2006] AngelineCMS 0.8.1 Installpath Remote File Inclusion
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Re: recursive DNS servers DDoS as a growing DDoS problem
- [SECURITY] [DSA 1022-1] New storebackup packages fix several vulnerabilities
- [Full-disclosure] PIRANA exploitation framework and SMTP contentfilter security
- From: Jean-Sébastien Guay-Leroux
- Black Hat Call for Papers and Registration now open
- Re: Limbo CMS code execution
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are runningweb with sen
- From: mailinglist mailinglist
- Another way to spoof Internet Explorer Address Bar
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data
- From: Jasper Bryant-Greene
- NOD32 local privilege escalation vulnerability
- Re: Flaw in commonly used bash random seed method
- ArabPortal 2.0.1 Stable [ 9 CrossSiteScripting & 1 SQL Injection ] MultBugz
- Re: Another Internet Explorer Address Bar Spoofing Vulnerability
- RE: recursive DNS servers DDoS as a growing DDoS problem
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data
- Re: Flaw in commonly used bash random seed method
- Buffer-overflow in Ultr@VNC 1.0.1 viewer and server
- RE: recursive DNS servers DDoS as a growing DDoS problem
- From: Thomas Guyot-Sionnest
- [ GLSA 200604-03 ] FreeRADIUS: Authentication bypass in EAP-MSCHAPv2 module
- Re: recursive DNS servers DDoS as a growing DDoS problem
- [ GLSA 200604-02 ] Horde Application Framework: Remote code execution
- [security bulletin] HPSBPI2109 SSRT061141 rev.1 - HP Color LaserJet 2500 and 4600 Toolbox Running on Microsoft Windows Remote Unauthorized Disclosure of Information
- Barracuda ZOO archiver security bug leads to remote compromise
- From: Jean-Sébastien Guay-Leroux
- Re: DoS-ing sysklogd?
- Re: DoS-ing sysklogd?
- [ GLSA 200604-01 ] MediaWiki: Cross-site scripting vulnerability
- Barracuda LHA archiver security bug leads to remote compromise
- From: Jean-Sébastien Guay-Leroux
- RE: recursive DNS servers DDoS as a growing DDoS problem
- Re: On product vulnerability history and vulnerability complexity
- [USN-267-1] mailman vulnerability
- Re: On product vulnerability history and vulnerability complexity
- Format string in Doomsday 1.8.6
- RE: recursive DNS servers DDoS as a growing DDoS problem
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Re: On product vulnerability history and vulnerability complexity
- Re: recursive DNS servers DDoS as a growing DDoS problem
- SMART Technologies SynchronEyes Remote Denial of Services
- RUXCON 2006 Call for Papers
- Re: Bypassing ISA Server 2004 with IPv6
- Re: Flaw in commonly used bash random seed method
- Multiple Vulnerabilities in LucidCMS
- Bypassing ISA Server 2004 with IPv6
- SYMSA-2006-002: McAfee WebShield SMTP Format String Vulnerability
- From: CS_Advisories Mailbox
- ReloadCMS <= 1.2.5stable Cross site scripting / remote command execution
- Re: recursive DNS servers DDoS as a growing DDoS problem
- [ MDKSA-2006:062 ] - Updated dia packages fix buffer overflow vulnerabilities
- [ MDKSA-2006:064 ] - Updated MySQL packages fix logging bypass vulnerability
- Re: recursive DNS servers DDoS as a growing DDoS problem
- Re: On product vulnerability history and vulnerability complexity
- From: Forrest J. Cavalier III
- Re: On classifying attacks
- Re: Cantv/Movilnet's Web SMS vulnerability.
- Re: WebVulnCrawl searching excluded directories for hackable web servers
- SQL Injection in Softbiz Image Gallery
- Re: On product vulnerability history and vulnerability complexity
- RE: recursive DNS servers DDoS as a growing DDoS problem
- Re: On product vulnerability history and vulnerability complexity
- Re: On product vulnerability history and vulnerability complexity
- Re: Flaw in commonly used bash random seed method
- MyBB 1.10 New CrossSiteScripting
- VWar <= 1.5.0 R12 Remote File Inclusion Exploit
- RE: DoS-ing sysklogd?
- Re: Mis-diagnosed XSS bugs hiding worse issues due to PHP feature
- Flaw in commonly used bash random seed method
- Hosting Controller AccountActions.asp and saveuploadfiles.asp vulns (PoC)
- Another Internet Explorer Address Bar Spoofing Vulnerability
- [SECURITY] [DSA 1000-2] New Apache2::Request packages fix denial of service
- [USN-266-1] dia vulnerabilities
- Re: On product vulnerability history and vulnerability complexity
- Secunia Research: AN HTTPD Script Source Disclosure Vulnerability
- Phpwebgallery <= 1.4.1 SQL injection Vulnerability
- SiteMan <= All version SQL injection in admin_login.asp
- Re: recursive DNS servers DDoS as a growing DDoS problem
- GeSWall 2.2 – Free Intrusion Prevention System for Windows
- From: GentleSecurity Team
- PHPNuke-Clan 3.0.1 Remote File Inclusion Exploit
- DoS-ing sysklogd?
- Re: Re: Re: phpBB 2.06 search.php SQL injection
- From: theguywhocouldwipeyourphpBB
- Re: Mis-diagnosed XSS bugs hiding worse issues due to PHP feature
- FleXiBle Development Script Remote Command Exucetion And XSS Attacking
- RE: recursive DNS servers DDoS as a growing DDoS problem
- Re: [Full-disclosure] Mis-diagnosed XSS bugs hiding worse issues due to PHP feature
- SQuery <= 4.5 Remote File Inclusion Exploit
- Re: recursive DNS servers DDoS as a growing DDoS problem
- linksubmit <= All version Html Tag Injector in index.php
- Mis-diagnosed XSS bugs hiding worse issues due to PHP feature
