Exploit
EXPLOIT DATABASE
- Sat, 04 Feb 2012 13:51:36 +0000: [papers] - [Turkish] DoS/DDoS Attacks Agains DNS - Exploit-DB updates
- Fri, 03 Feb 2012 13:50:46 +0000: [dos] - PHP 5.4SVN-2012-02-03 htmlspecialchars/entities Buffer Overflow - Exploit-DB updates
- Fri, 03 Feb 2012 13:26:04 +0000: [dos] - torrent-stats httpd.c Denial of Service - Exploit-DB updates
- Thu, 02 Feb 2012 19:48:12 +0000: [webapps] - Achievo v1.4.3 - Multiple Web Vulnerabilities - Exploit-DB updates
- Thu, 02 Feb 2012 18:03:00 +0000: [webapps] - OSCommerce v3.0.2 - Persistent Cross Site Vulnerability - Exploit-DB updates
- Thu, 02 Feb 2012 12:36:27 +0000: [remote] - Icona SpA C6 Messenger DownloaderActiveX Control Arbitrary File Download and Execute - [CVE: 2008-2551] - Exploit-DB updates
- Thu, 02 Feb 2012 12:35:57 +0000: [remote] - Sunway Forcecontrol SNMP NetDBServer.exe Opcode 0x57 - Exploit-DB updates
- Thu, 02 Feb 2012 12:34:37 +0000: [dos] - NetSarang Xlpd Printer Daemon 4 Denial of Service Vulnerability - Exploit-DB updates
- Thu, 02 Feb 2012 12:31:24 +0000: [dos] - OfficeSIP Server 3.1 Denial Of Service Vulnerability - Exploit-DB updates
- Thu, 02 Feb 2012 12:28:54 +0000: [webapps] - Apache Struts Multiple Persistent Cross-Site Scripting Vulnerabilities - Exploit-DB updates
- Thu, 02 Feb 2012 12:25:19 +0000: [webapps] - Sphinix Mobile Web Server 3.1.2.47 Multiple Persistent XSS Vulnerabilities - Exploit-DB updates
- Thu, 02 Feb 2012 12:20:12 +0000: [papers] - [French] Votre première exploitation de BOF - Exploit-DB updates
- Wed, 01 Feb 2012 22:06:47 +0000: [webapps] - MailEnable Webmail Cross-Site Scripting Vulnerability - [CVE: 2012-0389] - Exploit-DB updates
- Wed, 01 Feb 2012 21:16:14 +0000: [remote] - Webkit normalize bug for android 2.2 (CVE-2010-1759) - [CVE: 2010-1759] - Exploit-DB updates
- Wed, 01 Feb 2012 21:14:39 +0000: [papers] - [Hebrew] Digital Whisper Security Magazine #29 - Exploit-DB updates
PACKETSTORM DATABASE
- 4 February 2012: Mandriva Linux Security Advisory 2012-013 - Files ≈ Packet Storm
Mandriva Linux Security Advisory 2012-013 - Security issues were identified and fixed in mozilla firefox and thunderbird. Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes. Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce the IPv6 literal address syntax, which allows remote attackers to obtain sensitive information by making XMLHttpRequest calls through a proxy and reading the error messages. Various other issues were also addressed. - 4 February 2012: Ubuntu Security Notice USN-1355-1 - Files ≈ Packet Storm
Ubuntu Security Notice 1355-1 - It was discovered that if a user chose to export their Firefox Sync key the "Firefox Recovery Key.html" file is saved with incorrect permissions, making the file contents potentially readable by other users. Nicolas Gregoire and Aki Helin discovered that when processing a malformed embedded XSLT stylesheet, Firefox can crash due to memory corruption. If the user were tricked into opening a specially crafted page, an attacker could exploit this to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. Various other issues were also addressed. - 4 February 2012: Ubuntu Security Notice USN-1355-2 - Files ≈ Packet Storm
Ubuntu Security Notice 1355-2 - USN-1355-1 fixed vulnerabilities in Firefox. This update provides an updated Mozvoikko package for use with the latest Firefox. It was discovered that if a user chose to export their Firefox Sync key the "Firefox Recovery Key.html" file is saved with incorrect permissions, making the file contents potentially readable by other users. Nicolas Gregoire and Aki Helin discovered that when processing a malformed embedded XSLT stylesheet, Firefox can crash due to memory corruption. If the user were tricked into opening a specially crafted page, an attacker could exploit this to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. Various other issues were also addressed. - 4 February 2012: Ubuntu Security Notice USN-1355-3 - Files ≈ Packet Storm
Ubuntu Security Notice 1355-3 - USN-1355-1 fixed vulnerabilities in Firefox. This update provides updated ubufox and webfav packages for use with the latest Firefox. It was discovered that if a user chose to export their Firefox Sync key the "Firefox Recovery Key.html" file is saved with incorrect permissions, making the file contents potentially readable by other users. Nicolas Gregoire and Aki Helin discovered that when processing a malformed embedded XSLT stylesheet, Firefox can crash due to memory corruption. If the user were tricked into opening a specially crafted page, an attacker could exploit this to cause a denial of service via application crash, or potentially execute code with the privileges of the user invoking Firefox. Various other issues were also addressed. - 4 February 2012: Conduit Wibiya Login Toolbar Cross Site Scripting - Files ≈ Packet Storm
Conduit Wibiya Login Toolbar suffers from a cross site scripting vulnerability. - 4 February 2012: Conduit Wibiya Password Recovery Toolbar Cross Site Scripting - Files ≈ Packet Storm
Conduit Wibiya Password Recovery Toolbar suffers from a cross site scripting vulnerability. - 4 February 2012: Conduit Image Search Engine Cross Site Scripting - Files ≈ Packet Storm
Conduit Image Search Engine suffers from a cross site scripting vulnerability. - 4 February 2012: EMC Documentum xPlore Information Disclosure - Files ≈ Packet Storm
EMC Documentum xPlore contains an information disclosure vulnerability that may allow unauthorized users, under certain circumstances, to see certain information on protected objects in an xPlore search result. They will not, however, be allowed to view the objects themselves, or any associated content. Versions 1.0, 1.1 and 1.2 are affected. - 4 February 2012: Simkom Cross Site Scripting - Files ≈ Packet Storm
Simkom suffers from a cross site scripting vulnerability. - 4 February 2012: Douglass Media SQL Injection - Files ≈ Packet Storm
Douglass Media suffers from a remote SQL injection vulnerability. - 4 February 2012: Anfibia Remote Command Execution - Files ≈ Packet Storm
Anfibia suffers from a remote command execution vulnerability. - 4 February 2012: Raw CMS Cross Site Scripting - Files ≈ Packet Storm
Raw CMS suffers from a cross site scripting vulnerability. - 3 February 2012: PHP-Fusion 7.02.04 SQL Injection - Files ≈ Packet Storm
PHP-Fusion version 7.02.04 suffers from a remote SQL injection vulnerability in weblinks.php. - 3 February 2012: Port Tester 0.1 - Files ≈ Packet Storm
This is a simple little port scanning script written in python. - 3 February 2012: RFC6528 - Defending Against Sequence Number Attacks - Files ≈ Packet Storm
This document specifies an algorithm for the generation of TCP Initial Sequence Numbers (ISNs), such that the chances of an off-path attacker guessing the sequence numbers in use by a target connection are reduced. This document revises (and formally obsoletes) RFC 1948, and takes the ISN generation algorithm originally proposed in that document to Standards Track, formally updating RFC 793.
OPENSOURCE VULNERABILITY DATABASE
- : SAP NetWeaver Design Time Repository /dtr/system-tools/reports/FileQuery Multiple Parameter XSS - Latest OSVDB Vulnerabilities
SAP NetWeaver Design Time Repository /dtr/system-tools/reports/FileQuery Multiple Parameter XSS - : SAP NetWeaver Design Time Repository /dtr/system-tools/reports/ActivityQuery user Parameter XSS - Latest OSVDB Vulnerabilities
SAP NetWeaver Design Time Repository /dtr/system-tools/reports/ActivityQuery user Parameter XSS - : SAP NetWeaver Design Time Repository /dtr/system-tools/reports/CollisionQuery Multiple Parameter XSS - Latest OSVDB Vulnerabilities
SAP NetWeaver Design Time Repository /dtr/system-tools/reports/CollisionQuery Multiple Parameter XSS - : SAP NetWeaver Design Time Repository /dtr/system-tools/reports/ResourceDetails path Parameter XSS - Latest OSVDB Vulnerabilities
SAP NetWeaver Design Time Repository /dtr/system-tools/reports/ResourceDetails path Parameter XSS - : SAP RFC SDK Library Unspecified Format String - Latest OSVDB Vulnerabilities
SAP RFC SDK Library Unspecified Format String - : SAP RFC SDK Library HTML Page Handling Remote Memory Corruption - Latest OSVDB Vulnerabilities
SAP RFC SDK Library HTML Page Handling Remote Memory Corruption - : SAP NetWeaver ICF BSP RequestParts.htm sap-ffield Parameter XSS - Latest OSVDB Vulnerabilities
SAP NetWeaver ICF BSP RequestParts.htm sap-ffield Parameter XSS - : Inter-PRO Client Configuration File Handling Remote Overflow - Latest OSVDB Vulnerabilities
Inter-PRO Client Configuration File Handling Remote Overflow - : SAP NetWeaver Build Service Component CBSUtils devconfwiz.jsp WORKSPACE1 Parameter XSS - Latest OSVDB Vulnerabilities
SAP NetWeaver Build Service Component CBSUtils devconfwiz.jsp WORKSPACE1 Parameter XSS - : SAP NetWeaver JPR Proxy Server Component TransportServlet list Multiple Parameter XSS - Latest OSVDB Vulnerabilities
SAP NetWeaver JPR Proxy Server Component TransportServlet list Multiple Parameter XSS
SECURITYFOCUS DATABASE
- Sat, 29 Dec 2012 00:00:00 +0000: Vuln: Pligg CMS 'status' Parameter SQL Injection Vulnerability - SecurityFocus Vulnerabilities
Pligg CMS 'status' Parameter SQL Injection Vulnerability - Fri, 03 Feb 2012 00:00:00 +0000: Vuln: Joomla! Multiple Information Disclosure Vulnerabilities - SecurityFocus Vulnerabilities
Joomla! Multiple Information Disclosure Vulnerabilities - Fri, 03 Feb 2012 00:00:00 +0000: Vuln: QEMU KVM CVE-2012-0029 Local Privilege Escalation Vulnerability - SecurityFocus Vulnerabilities
QEMU KVM CVE-2012-0029 Local Privilege Escalation Vulnerability - Fri, 03 Feb 2012 00:00:00 +0000: Vuln: Mozilla Firefox/SeaMonkey/Thunderbird XPConnect Security Check Cross Domain Scripting Vulnerability - SecurityFocus Vulnerabilities
Mozilla Firefox/SeaMonkey/Thunderbird XPConnect Security Check Cross Domain Scripting Vulnerability - : Bugtraq: [ MDVSA-2012:013 ] mozilla - SecurityFocus Vulnerabilities
[ MDVSA-2012:013 ] mozilla - : Bugtraq: ESA-2012-010: EMC Documentum xPlore information disclosure vulnerability - SecurityFocus Vulnerabilities
ESA-2012-010: EMC Documentum xPlore information disclosure vulnerability - : Bugtraq: RFC 6528 on Defending against Sequence Number Attacks - SecurityFocus Vulnerabilities
RFC 6528 on Defending against Sequence Number Attacks - : Bugtraq: [SECURITY] [DSA 2403-1] php5 security update - SecurityFocus Vulnerabilities
[SECURITY] [DSA 2403-1] php5 security update - : More rss feeds from SecurityFocus - SecurityFocus Vulnerabilities
News, Infocus, Columns, Vulnerabilities, Bugtraq ...









