Section: .. / 0712-advisories /
| /// File Name: |
websense-bypass.txt |
Description:
|
Websense Enterprise version 6.3.1 suffers from a web filtering bypass vulnerability due to a trust condition with the User-Agent: setting.
| | Author: | mrhinkydink | | File Size: | 1974 | | Last Modified: | Dec 13 17:52:09 2007 |
| MD5 Checksum: | 836b78b61b542dba2b9e8dfdd6ee55df |
|
| /// File Name: |
joomla-csrf.txt |
Description:
|
Multiple cross site request forgery vulnerabilities may exist in all versions of Joomla!.
| | Author: | Zinho | | Homepage: | http://www.hackerscenter.com/ | | File Size: | 1888 | | Last Modified: | Dec 28 20:08:24 2007 |
| MD5 Checksum: | e5543c23ddaa171f1203ab0dd31397dd |
|
| /// File Name: |
coolplayer-overflow.txt |
Description:
|
CoolPlayer versions 217 and below suffer from a buffer overflow vulnerability in CPLI_Readtag_OGG.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | File Size: | 1851 | | Last Modified: | Dec 28 20:22:15 2007 |
| MD5 Checksum: | 2ce29fda2f085a9662141dc8d5b8db3c |
|
| /// File Name: |
fig-xml.txt |
Description:
|
Flash Image Gallery suffers from a direct download vulnerability where config.xml, the file containing the username and password for the administrator, can be directly accessed by anyone remotely. Advisory is in Spanish.
| | Author: | Yamabushiken | | File Size: | 1848 | | Last Modified: | Dec 13 17:06:16 2007 |
| MD5 Checksum: | a55edfc714d8b5a437f050ecb9f78d3a |
|
| /// File Name: |
mcafeeps-exec.txt |
Description:
|
McAfee SecurityCenter Privacy Service version 8.1.0.136 suffers from a script insertion vulnerability.
| | Author: | Doz | | Homepage: | http://www.hackerscenter.com/ | | File Size: | 1828 | | Last Modified: | Dec 4 00:11:00 2007 |
| MD5 Checksum: | f781b19c2470e9ef5f79632345c377cf |
|
| /// File Name: |
AD20071206.txt |
Description:
|
Avast! Home/Professional versions below 4.7.1098 suffer from a remote heap corruption vulnerablity when processing tar files.
| | Author: | Sowhat | | Homepage: | http://www.nevisnetworks.com/ | | File Size: | 1819 | | Last Modified: | Dec 7 12:57:50 2007 |
| MD5 Checksum: | d8ae0cd83f95804e538540b842699117 |
|
| /// File Name: |
authcas-sql.txt |
Description:
|
The Apache::AuthCAS module appears susceptible to SQL injection attacks via the cookie.
| | Author: | Matthias Bethke | | File Size: | 1797 | | Last Modified: | Dec 7 19:34:20 2007 |
| MD5 Checksum: | bcbad04999e8756593a479b393069e06 |
|
| /// File Name: |
uber-upload.txt |
Description:
|
Uber Uploader versions 5.3.6 and below suffer from a remote file upload vulnerability.
| | Author: | JosS | | Homepage: | http://www.spanish-hackers.com/ | | File Size: | 1732 | | Last Modified: | Dec 17 21:18:28 2007 |
| MD5 Checksum: | 23779cbba8bb1a5097810d8a1b0a4136 |
|
| /// File Name: |
CVE-2007-6244.txt |
Description:
|
The Adobe Flash Player suffers from a cross site scripting vulnerability in an Active-X control.
| | Author: | Collin Jackson | | File Size: | 1686 | | Related CVE(s): | CVE-2007-6244 | | Last Modified: | Dec 19 21:11:36 2007 |
| MD5 Checksum: | 703be4bb207a89818449a0ea3790ddcb |
|
| /// File Name: |
TPTI-07-21.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of the Adobe Flash Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
| | Author: | Aaron Portnay | | Homepage: | http://www.tippingpoint.com/ | | File Size: | 1645 | | Related CVE(s): | CVE-2007-6242 | | Last Modified: | Dec 19 21:09:06 2007 |
| MD5 Checksum: | 471b8be534d4bd287dd4dc8a2886b641 |
|
| /// File Name: |
zoomprayer.txt |
Description:
|
Zoom Player versions 6.00 beta 2 and below suffer from a unicode related buffer overflow vulnerability.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | zoomprayer.tgz | | File Size: | 1624 | | Last Modified: | Dec 24 15:05:30 2007 |
| MD5 Checksum: | 2702f61a218bbd385e2e5237529fdfd8 |
|
| /// File Name: |
websense-xss.txt |
Description:
|
Websense Enterprise and Websense Web Security Suite contain a Version 6.3 is affected. vulnerability in the login page that is susceptible to a cross site scripting attack.
| | Author: | Dave Lewis | | Homepage: | http://www.liquidmatrix.org/ | | File Size: | 1565 | | Last Modified: | Dec 10 19:56:52 2007 |
| MD5 Checksum: | 4932a8e05d9f9d82c73b755f2e32e9af |
|
| /// File Name: |
twit-eval.txt |
Description:
|
The Twitgit and Twitterlex widgets are susceptible to an insecure use of eval().
| | Author: | Thomas Roessler | | File Size: | 1540 | | Last Modified: | Dec 5 22:51:05 2007 |
| MD5 Checksum: | b593c71934e7794aae60a7dd4124ecc0 |
|
| /// File Name: |
ciscoworks-xss.txt |
Description:
|
CiscoWorks versions 2.6 and below suffer from a cross site scripting vulnerability.
| | Author: | Dave Lewis | | Homepage: | http://www.liquidmatrix.org/ | | File Size: | 1533 | | Last Modified: | Dec 6 00:31:06 2007 |
| MD5 Checksum: | 9b84cccc8260ebaeb7ba41ddf2ebfff6 |
|
| /// File Name: |
PR06-08.txt |
Description:
|
BEA Plumtree Portal is vulnerable to a internal hostname disclosure vulnerability.
| | Author: | Adrian Pastor, Jan Fry | | Homepage: | http://www.procheckup.com/ | | File Size: | 1530 | | Last Modified: | Dec 4 00:02:42 2007 |
| MD5 Checksum: | d6f1cecbee28f150e44052f22a42beb0 |
|
| /// File Name: |
PR06-09.txt |
Description:
|
By performing an advanced search, unauthenticated users can enumerate valid usernames with a single HTTP request on the BEA Plumtree Portal.
| | Author: | Adrian Pastor, Jan Fry, Richard Brain | | Homepage: | http://www.procheckup.com/ | | File Size: | 1291 | | Last Modified: | Dec 4 00:04:21 2007 |
| MD5 Checksum: | ea76691b3dd25da468a4123c8de2c266 |
|
| /// File Name: |
firefox-filefocus.txt |
Description:
|
Firefox version 2.0.0.11 suffers from a file focus stealing vulnerability.
| | Author: | Carl Hardwick | | File Size: | 972 | | Last Modified: | Dec 2 16:09:11 2007 |
| MD5 Checksum: | a0f7065c5bea16e2e5097c956b701ada |
|
| /// File Name: |
pdflib-overflows.txt |
Description:
|
pdflib, a library used for generating PDFs on the fly, suffers from multiple buffer overflow vulnerabilities due to the use of strcpy().
| | Author: | poplix | | Homepage: | http://px.dynalias.org/ | | File Size: | 839 | | Last Modified: | Dec 24 18:16:32 2007 |
| MD5 Checksum: | 5b5319a4404f4f00c7533d2437c848fa |
|
| /// File Name: |
yshortcut-overflow.txt |
Description:
|
It appears that the YShortcut toolbar has a buffer overflow vulnerability.
| | Author: | Elazar Broad | | File Size: | 783 | | Last Modified: | Dec 20 16:22:42 2007 |
| MD5 Checksum: | 93c676aa83060f2436e7fd3889e4df0d |
|
| /// File Name: |
roundcube-xss.txt |
Description:
|
Roundcube webmail does not sanitize payloads allowing for cross site scripting attacks to occur when used in conjunction with Microsoft Internet Explorer.
| | Author: | Tomas Kuliavas | | Homepage: | http://www.topolis.lt/ | | Related Exploit: | expression.eml.gz | | File Size: | 729 | | Last Modified: | Dec 10 17:36:22 2007 |
| MD5 Checksum: | a304c7fefc56602b855eea3ab5e06236 |
|
|
|
|
|