The bugtraq list archive for Aug-05
- Aug 31, 2005
- Ariba password exposure vulnerability, gerald626
- Vulnerability in Symantec Anti Virus Corporate Edition v9.x, golovast
- CMS Made Simple <= 0.10 - PHP injection, groszynskif
- RE: secure client-side platform, Beauford, Jason
- Flatnuke 2.5.6 (possibly prior versions) Underlying system information disclosure / Administrative & users credentials disclosure, retrogod
- Re: ICMP attacks against TCP: Conclusions, Damien Miller
- Simple Machine Forum 1-0-5 (possibly prior versions) user IP address / information disclosure, retrogod
- Obsidis #1 Call for Papers, angelo
- XSS in GreyMatter blog, poizon
- [SECURITY] [DSA 792-1] New pstotext packages fix arbitrary command execution, Martin Schulze
- [security bulletin] SSRT051003 rev.0 - HP-UX Java Web Start remote unauthorized privileged access, security-alert
- [ GLSA 200508-21 ] phpWebSite: Arbitrary command execution through XML-RPC and SQL injection, Sune Kloppenborg Jeppesen
- [ GLSA 200508-22 ] pam_ldap: Authentication bypass vulnerability, Sune Kloppenborg Jeppesen
- secure client-side platform, liudieyu
- Indiatimes Messenger 6.0 Buffer Overflow (Remote), ViPeR
- [security bulletin] SSRT051004 rev.0 - HP-UX Java Runtime Environment (JRE) Untrusted Applet Elevates Privilege, security-alert
- Call for new mailing lists @ SecurityFocus, Alfred Huger
- Re: Vulnerability in Helpdesk software Hesk 0.92, Thomas Krüger
- MS05-042 Security Update Problems, Andrew McCullough
- [SECURITY] [DSA 791-1] New maildrop packages fix arbitrary group mail command execution, Martin Schulze
- Re: Vulnerability in Helpdesk software Hesk 0.92, not
- Re: PunBB BBCode IMG Tag Script Injection Vulnerability, Aaron Horst
- Fetchmail 6.2.5 exploit for Bugtraq ID: 14349, bannedit
- Aug 30, 2005
- [SECURITY] [DSA 790-1] New phpldapadmin packages fix unauthorised access, Martin Schulze
- e107 0.6 forum_post.php create new topics in non-existing forums, Marc Ruef
- [UNTRUE] Gadu-Gadu supposedly fixed the invisible detection vulnerability?, Maciej Soltysiak
- Re: ICMP attacks against TCP: Conclusions, Dan Yefimov
- [ GLSA 200508-20 ] phpGroupWare: Multiple vulnerabilities, Thierry Carrez
- [USN-173-3] Fixed apache2 packages for USN-173-2, Martin Pitt
- [ GLSA 200508-19 ] lm_sensors: Insecure temporary file creation, Thierry Carrez
- phpLDAPadmin 0.9.6 - 0.9.7/alpha5 (possibly prior versions) system disclosure,, retrogod
- iDEFENSE Security Advisory 08.29.05: Symantec AntiVirus 9 Corporate Edition Local Privilege Escalation Vulnerability, iDEFENSE Labs
- iDEFENSE Security Advisory 08.29.05: Adobe Version Cue VCNative Arbitrary File Overwrite Vulnerability, iDEFENSE Labs
- iDEFENSE Security Advisory 08.29.05: Adobe Version Cue VCNative Arbitrary Library Loading Vulnerability, iDEFENSE Labs
- SUSE Security Announcement: pcre integer overflows (SUSE-SA:2005:048), Marcus Meissner
- BNBT EasyTracker Remote Denial of Service Vulnerability, Sowhat .
- SUSE Security Announcement: php4/php5 Pear::XML_RPC code injection and PCRE integer overflow problems (SUSE-SA:2005:049), Marcus Meissner
- Aug 29, 2005
- Re: Sophos Antivirus Library Remote Heap Overflow, list
- AutoLinks Pro 2.1, none
- [SECURITY] [DSA 789-1] New PHP 4 packages fix several vulnerabilities, Martin Schulze
- Member.php SQL Injection in MyBB, W7ED
- PunBB BBCode IMG Tag Script Injection Vulnerability, y3dips
- WASC-Articles: 'Preventing Log Evasion in IIS', contact
- Vulnerability in Helpdesk software Hesk 0.92, s2b
- Re: unload event in ie/mozilla/opera, gegegz
- SimplePHPBlog Arbitrary File Deletion and Sample Exploit, 'ken'@FTU
- [cosmoshop <= 8.10.78] be the shopadmin in one step, innate
- Land Down Under 801 And Prior Multiple SQL Injection Vulnerabilities, h4cky0u . org
- [SECURITY] [DSA 788-1] New kismet packages fix arbitrary code execution, Martin Schulze
- Multiple CMS/Forum Vulnablilties, pacifico\", 0] //--></script>a
- Multiple vulnerabilities in BFCommand & Control for Battlefield 1942 and Vietnam, Luigi Auriemma
- Secunia Research: SqWebMail HTML Emails Script Insertion Vulnerability, Secunia Research
- Land Down Under, bendeniz_avci
- Xcon2005 papers released, alert7
- FUD Forum < 2.7.1 PHP code injection vurnelability, riklaunim
- PHP-Fusion <= v6.00.107 XSS exploit, slacker4ever_1
- Aug 27, 2005
- RE: Sophos Antivirus Library Remote Heap Overflow, Dowling, Gabrielle
- Re: Tool for Identifying Rogue Linksys Routers, Tony Rall
- Re: Tool for Identifying Rogue Linksys Routers, Paul Halliday
- Re: ZipTorrent 1.3.7.3 Discloses Proxy Passwords to Local Users, Nicholas Knight
- XSS security hole in phpwebnotes., nf2
- MDKSA-2005:153 - Updated gnumeric packages fix integer overflow vulnerability, Mandriva Security Team
- Re: Tool for Identifying Rogue Linksys Routers, Mike Kershaw
- MDKSA-2005:154 - Updated python packages fix integer overflow vulnerability, Mandriva Security Team
- Re: Tool for Identifying Rogue Linksys Routers, Volker Tanger
- Looking Glass v20040427 arbitrary commands execution / cross site scripting, retrogod
- Sophos Antivirus Library Remote Heap Overflow, list
- MDKSA-2005:149 - Updated lm_sensors packages fix temporary file vulnerability, Mandriva Security Team
- Re: Tool for Identifying Rogue Linksys Routers, Dave Hull
- DMA[2005-0826a] - 'Nokia Affix Bluetooth btsrv poor use of popen()', KF (lists)
- [SECURITY] [DSA 786-1] New simpleproxy packages fix arbitrary code execution, Martin Schulze
- Simple PHP Blog File Upload and User Credentials Exposure Vulnerabilities, Scott Dewey
- Multiple PHP Images Galleries EXIF Metadata XSS Vulnerabilities, Cedric Cochin
- Re: unload event in ie/mozilla/opera, Michael Shigorin
- MDKSA-2005:151 - Updated pcre packages fix integer overflow vulnerability, Mandriva Security Team