XSS bug in Monkey (0.5.0) HTTP server

2002-09-30 Thread DownBload
) Author e-mail: [EMAIL PROTECTED] Monkey Project: http://monkeyd.sourceforge.net Date: 29.09.2002 Impact: XSS code execution Tested on: Debian 2.1 (2.0.36 kernel) Discovered by: DownBload Mail me

IIL Advisory: Reverse traversal vulnerability in Monkey (0.1.4) HTTP server

2002-09-25 Thread DownBload
author: Eduardo Silva (EdsipeR) Author e-mail: [EMAIL PROTECTED] Monkey Project: http://monkeyd.sourceforge.net Date: 06.09.2002 Impact: Attacker can read files out of SERVER_ROOT directory Tested on: Debian 2.1 (2.0.36 kernel) Discovered by: DownBload

IIL Advisory: Format String bug in Null Webmail (0.6.3)

2002-09-25 Thread DownBload
] Homepage: http://http://www.nulllogic.com/webmail/ Date: 1.07.2002 Impact: I don't know (yet) Tested on: nowhere Discovered by: DownBload Mail me @: [EMAIL PROTECTED] ==[ Overview Null Webmail is CGI interface to SMTP

IIL Advisory: Vulnerabilities in acWEB HTTP server

2002-09-25 Thread DownBload
: somewhere on sourceforge Date: 10.09.2002 Impact: DoS, XSS, etc. Tested on: Windows 98 Discovered by: DownBload Mail me @: [EMAIL PROTECTED] ==[ Overview Sourceforge: acWEB is an OpenSource replacement for MS IIS and other

SSI CSS execution in MakeBook 2.2

2002-06-12 Thread DownBload
[ DownBload Security Research Lab Advisory ] [-] Advisory name: SSI CSS execution in MakeBook 2.2 Advisory number: 5 Application: MakeBook 2.2 (CGI script