The bugtraq list archive for Oct-06
- Oct 31, 2006
- Re: New Flaw in Firefox 2.0: DoS and possible remote code execution, Daniel Veditz
- Cross Site Scripting (XSS) Vulnerability in Web Mail service by "Walla! Communications LTD", LegendaryZion
- Directory listing on B-FOCuS Wireless 802.11b/g ADSL2+ Router by "ECI Telecom LTD", LegendaryZion
- Cross Site Scripting (XSS) Vulnerability in iPlanet Messaging Server Messenger Express by "Sun", LegendaryZion
- PHP-Nuke <= 7.9 Journal module (search.php) "forwhat" SQL Injection vulnerability, paisterist . nst
- [SECURITY] [DSA 1202-1] New screen packages fix arbitrary code execution, Moritz Muehlenhoff
- [SECURITY] [DSA 1201-1] New ethereal packages fix denial of service, Moritz Muehlenhoff
- Re: Re: New Flaw in Firefox 2.0: DoS and possible remote code execution, xxxx
- Re: New Flaw in Firefox 2.0: DoS and possible remote code execution, Gouki
- Re: New Flaw in Firefox 2.0: DoS and possible remote code execution, Josh Bressers
- Authentication bypass in BytesFall Explorer, RedTeam Pentesting
- Re: freenews---> fileinclude, pokley
- Re: freenews---> fileinclude, pokley
- New Flaw in Firefox 2.0: DoS and possible remote code execution, xxxx
- Sun java System Messenger Express XSS, handrix
- SQL Injection Vulnerability in bfExplorer 0.0.6, security
- [ MDKSA-2006:194 ] - Updated PostgreSQL packages fix vulnerabilities, security
- [ MDKSA-2006:193 ] - Updated ImageMagick packages fix vulnerabilities, security
- Hawking Technology wireless router WR254-CA DNS issue, Nikolai Grigoriev
- ActiveX security leaks in the TV owned web game platform, maxgipeh
- phpMyConferences <= 8.0.2 Remote File Inclusion, mfp . c
- ModSecurity 2.0, A Core Rule Set and Console now available, Ofer Shezaf
- Re: Free Rainbow Tables.com, Jerome Athias
- Re: Nucleus Core v3.23 - Remote File Include, Francesco Laurita
- Re: freenews---> fileinclude, Tamriel
- Re: CentiPaid <= 1.4.2 [$class_pwd] Remote File Include, Tamriel
- [security bulletin] HPSBTU02168 SSRT061237 rev.1 - HP Tru64 UNIX Running gzip, gunzip, and gzcat, Remote Unauthorized Arbitrary Code Execution or Denial of Service (DoS), security-alert
- [security bulletin] HPSBMA02121 SSRT061157 rev.3 - HP OpenView Storage Data Protector Remote Unauthorized Arbitrary Command Execution, security-alert
- Oct 30, 2006
- [security bulletin] HPSBMA02138 SSRT061184 rev.2 - HP OpenView Storage Data Protector, Remote Unauthorized Arbitrary Command Execution, security-alert
- unreliable vulnerability reports en-masee [was:Re: vulnerability in Symantec products], Gadi Evron
- Re: CentiPaid <= 1.4.2 [$class_pwd] Remote File Include, Francesco Laurita
- Multiple Remote File Include, firewall1954
- CORE FORCE R0.95 released!, CORE FORCE Team
- [ GLSA 200610-15 ] Asterisk: Multiple vulnerabilities, Raphael Marichez
- Metasploit Framework 2.7 Released, H D Moore
- opendocman <= 1.2p3 Bypass admin/user Login, k1tk4t
- [ECHO_ADV_53$2006] QnECMS <= 2.5.6 (adminfolderpath) Remote File Inclusion Vulnerability, erdc
- Punbb <= 1.2.13 Multiple Vulnerabilities, Nms
- Nucleus Core v3.23 - Remote File Include, firewall1954
- PHPEasyData Pro 2.2.1 (index.php) Remote SQL Injection Vulnerability, ajannhwt
- PHPEasyData Pro 1.4.1 (index.php) Remote SQL Injection Vulnerability, ajannhwt
- Simple Website Software v0.99 (common.php) Remote File Include, cw . cybersecurity
- Re: imageVue16.1 upload vulnerability, mjau
- [MajorSecurity Advisory #29]foresite CMS - Cross Site Scripting Issue, admin
- easy notes manager sql injection and authentication bypass, poplix
- freenews---> fileinclude, MoHaNdKo
- Re: phpAdsNew-2.0.8 <= (adlayer.php) Remote File Include, simo
- Re: vulnerability in Symantec products, jay.tomas
- SQL in WebWizForum by almaster hacker, almaster
- Back-end => 0.4.5 Remote File Include Vulnerability Exploit, h4ck3riran
- bbsNew => 2.0.1 Remote File Include Vulnerability Exploit, h4ck3riran
- Exporia => 0.3.0 Remote File Include Vulnerability Exploit, h4ck3riran
- CentiPaid <= 1.4.2 [$class_pwd] Remote File Include, firewall1954
- Re: [Full-disclosure] ZDI-06-035: Novell eDirectory NDS Server Host Header Buffer Overflow Vulnerability, Matt Richard
- [OpenPKG-SA-2006.027] OpenPKG Security Advisory (wordpress), OpenPKG
- [SECURITY] [DSA 1200-1] New Qt packages fix integer overflow, Noah Meyerhans
- [ GLSA 200610-14 ] PHP: Integer overflow, Raphael Marichez
- Oct 28, 2006
- Oct 27, 2006
- Microsoft .NET request filtering bypass vulnerability, research
- Hosting Controller 6.1 Hotfix <= 3.2 Vulnerability, playpacific . emulacaid
- Thepeak File Upload v1.3 : Read file vulneability, loveha
- Ban v0.1 (bannieres.php) File Include, mahmood ali
- phpAdsNew-2.0.8 <= (adlayer.php) Remote File Include, zooz_998
- [funsec] Haxdoor: UK Police Count 8, 500 Victims in Data Theft (So Far) (fwd), Gadi Evron
- phpLedAds 2.0(dir) File Include, mahmood ali
- PLS-Bannieres 1.21 (bannieres.php) File Include, mahmood ali
- RFID enabled e-passport skimming proof of concept code released (RFIDIOt), Adam Laurie
- GestArt <= vbeta 1 Remote File Include Vulnerabilities, ip . 123 . 456 . 78 . 90
- ArticleBeach Script <= 2.0 Remote File Inclusion Vulnerability, Bithedz