The bugtraq list archive for Mar-06
- Mar 31, 2006
- Warcraft III Replay Parser Script Remote Command Exucetion Vulnerability And Cross-Site Scripting Attacking, botan
- Buffer-overflow and in-game crash in Zdaemon 1.08.01, Luigi Auriemma
- DbbS<=2.0-alpha SQL injection, dabdoub-mosikar
- Re: Re: Cantv/Movilnet's Web SMS vulnerability., rrecabarren
- RE: Sudo tricks, Burton Strauss
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data, Jeff Rosowski
- OSSTMM Security Analyst Training Live Stream on the Web, Pete Herzog
- RE: recursive DNS servers DDoS as a growing DDoS problem, Geo.
- EzASPSite <= 2.0 RC3 Remote SQL Injection Exploit Vulnerability., Mustafa Can Bjorn IPEKCI
- RE: WebVulnCrawl searching excluded directories for hackable web servers, Michael Scheidell
- Re: On classifying attacks, Gadi Evron
- Re: Sudo tricks, Javor Ninov
- [security bulletin] HPSBUX02108 SSRT061133 rev.2 - HP-UX running Sendmail, Remote Execution of Arbitrary Code, security-alert
- Black Hat Call for Papers and Registration now open, Jeff Moss
- MonAlbum 0.8.7 SQL Injection, undefined1
- Oxygen<=1.x.x SQL injection, dabdoub-mosikar
- Mar 30, 2006
- MediaSlash Gallery 'rub' variable Remote File inlcusion Vulnerability, simo64
- Re: recursive DNS servers DDoS as a growing DDoS problem, Geo.
- Re: recursive DNS servers DDoS as a growing DDoS problem, Stephen Samuel
- Re: recursive DNS servers DDoS as a growing DDoS problem, gboyce
- Re: recursive DNS servers DDoS as a growing DDoS problem, mike davis
- [security bulletin] HPSBUX02102 SSRT051078 rev.2 - HP-UX usermod(1M) Local Unauthorized Access., security-alert
- [security bulletin] HPSBUX02103 SSRT5953 rev.2 - HP-UX passwd(1) Local Denial of Service (DoS), security-alert
- strip_tags() but not only vulnerability, Tõnu Samuel
- [SECURITY] Samba 3.0.21-3.0.21c: Exposure of machine account credentials in winbindd log files, Gerald (Jerry) Carter
- Smurfable Linux Kernel, Tomasz Chomiuk
- Re: On classifying attacks, David M Chess
- Buffer overflows in Dia XFig import, lars
- McAfee VirusScan DUNZIP32.dll Buffer Overflow Vulnerability, Juha-Matti Laurio
- X-Changer <=v0.2 Demo SQL injection, dabdoub-mosikar
- [ MDKSA-2006:061 ] - Updated mailman packages fix DoS from badly formed mime multipart messages., security
- Mar 29, 2006
- [ GLSA 200603-26 ] bsd-games: Local privilege escalation in tetris-bsd, Stefan Cornelius
- Full path disclosure in Webcalendar 1.1.0-CVS, crasher
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data, Tõnu Samuel
- Re: Cantv/Movilnet's Web SMS vulnerability., raven
- Resource to Report and Stop Phishing Scams, Paul Laudanski
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data, Jasper Bryant-Greene
- PhxContacts <= 0.93.1 beta Multiple SQL injection & xss, dabdoub-mosikar
- Re: Re: phpBB 2.06 search.php SQL injection, fritz-li
- Re: Sudo tricks, Krzysztof Halasa
- [eVuln] Skull-Splitter's PHP Downloadcounter for Wallpapers SQL Injection, alex
- [eVuln] Skull-Splitter's PHP Guestbook XSS Vulnerability, alex
- [xfocus-SD-060329]MPlayer: Multiple integer overflows, XFOCUS Security Team
- [HV-INFO] Enova hardware encryption: false sense of security, vuln
- Re: [SECURITY] [DSA 1020-1] New flex packages fix insecure code generation, Moritz Muehlenhoff
- XSS in PHPKIT Version 1.6.03, badnet_xoopiter
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are runningweb with sensitive data, Tõnu Samuel
- Re: Secunia Research: Microsoft Internet Explorer "createTextRange()"Code Execution, edubp2002
- Critical PHP bug - act ASAP if you are running web with sensitive data, Tõnu Samuel
- Mar 28, 2006
- Re: [Full-disclosure] Critical PHP bug - act ASAP if you are running web with sensitive data, Stefan Esser
- Re: PHP-Stats <= 0.1.9.1 remote commands execution, nomail
- Re: Sudo tricks, Steven M. Christey
- Re: SendGate: Sendmail Multiple Vulnerabilities (Race Condition DoS, Memory Jumps, Integer Overflow), Gadi Evron
- Cantv/Movilnet's Web SMS vulnerability., Bugtraq @ SNSecurity
- Determina Fix for CVE-2006-1359 (Zero Day MS Internet Explorer Remote "CreateTextRange()" Code Execution), Determina Secure
- Re: SYM06-006, Veritas NetBackup: Multiple Overflow Vulnerabilities in NetBackup Daemons, secure
- Re: [SECURITY] [DSA 1020-1] New flex packages fix insecure code generation, Matthew R. Dempsky
- Announcement: The Web Hacking Incidents Database, contact
- Re: On classifying attacks, Gadi Evron
- Re: Sudo tricks, Thomas M. Payerle
- ArabPortal 2.0 Stable CrossSiteScripting, o . y . 6
- Re: Microsoft Windows XP SP2 Firewall issue, Thor (Hammer of God)
- Re: SendGate: Sendmail Multiple Vulnerabilities (Race Condition DoS, Memory Jumps, Integer Overflow), Casper . Dik
- [SECURITY] [DSA 1021-1] New netpbm-free packages fix arbitrary command execution, Moritz Muehlenhoff
- Secunia Research: Blazix Web Server JSP Source Code Disclosure Vulnerability, Secunia Research
- Re: SendGate: Sendmail Multiple Vulnerabilities (Race Condition DoS, Memory Jumps, Integer Overflow), Geo.
- Genius VideoCAM NB Local Privilege Escalation, beford
- XSS in AL-Caricatier, xx_hack_xx_2004
- [eVuln] Maian Support Authentication Bypass, alex
- [eVuln] Maian Events SQL Injection Vulnerability, alex
- VWar <= 1.5.0 R11 Remote Code Execution Exploit, uid0
- EEYE: Temporary workaround for IE createTextRange vulnerability, Marc Maiffret
- PHPLiveHelper 1.8 remote command execution (include) Xploit (perl), stormhacker
- [SECURITY] [DSA 1020-1] New flex packages fix insecure code generation, Moritz Muehlenhoff
- SYM06-006, Veritas NetBackup: Multiple Overflow Vulnerabilities in NetBackup Daemons, secure