CA Secure Content Manager HTTP Gateway Service FTP Request Vulnerabilities

2008-06-05 Thread Williams, James K
Title: CA Secure Content Manager HTTP Gateway Service FTP Request Vulnerabilities CA Advisory Date: 2008-06-03 Reported By: Sebastian Apelt working with ZDI/TippingPoint Cody Pierce, TippingPoint DVLabs Impact: A remote attacker can cause a denial of service or execute

AST-2008-009: AST-2008-007 Cryptographic keys generated by OpenSSL on Debian-based systems compromised

2008-06-05 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2008-009 ++ | Product | Asterisk-Addons |

e107 Plugin echat MENU Blind SQL Injection Vulnerability

2008-06-05 Thread hadihadi_zedehal_2006
## # # # ::e107 Plugin echat MENU Blind SQL Injection

[security bulletin] HPSBST02312 SSRT071428 rev.2 - HP StorageWorks Storage Mirroring Software, Remote Execution of Arbitrary Code

2008-06-05 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01362558 Version: 2 HPSBST02312 SSRT071428 rev.2 - HP StorageWorks Storage Mirroring Software, Remote Execution of Arbitrary Code NOTICE: The information in this Security Bulletin should be

Remote DoS vulnerability in Linksys WRH54G

2008-06-05 Thread dubingyao
1. DESCRIPTION There is a DoS vulnerability in Cisco Linksys router WRH54G http service. Any anonymous attacker could crash the http service easily by sending a malformed http request, and needn't any privilege. When the device attempts to process the malformed request, it will be possible

SMEweb 1.4b (SQL/XSS) Multiple Remote Vulnerabilities

2008-06-05 Thread tan_prathan
=== SMEweb 1.4b (SQL/XSS) Multiple Remote Vulnerabilities === ,--^--,,-,---^--, | | `' | O .. CWH Underground Hacking Team

Akamai Download Manager File Downloaded To Arbitrary Location Vulnerability

2008-06-05 Thread cocoruder
Akamai Download Manager File Downloaded To Arbitrary Location Vulnerability by cocoruder([EMAIL PROTECTED]) http://ruder.cdut.net Summary: A parameter injection vulnerability exists in Akamai Download Manager. By exploiting this vulnerability, the remote attacker can make the users to

AST-2008-009: (Corrected subject) Remote crash vulnerability in ooh323 channel driver

2008-06-05 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2008-009 ++ | Product | Asterisk-Addons |

iDefense Security Advisory 06.04.08: VMware Tools HGFS Local Privilege Escalation Vulnerability

2008-06-05 Thread iDefense Labs
iDefense Security Advisory 06.04.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jun 04, 2008 I. BACKGROUND VMware is a software virtualization system which allows multiple virtual computers to run on a single system. VMware Tools provides drivers and utilities to enhance and optimize

iDefense Security Advisory 06.04.08: VMware Multiple Products vmware-authd Untrusted Library Loading Vulnerability

2008-06-05 Thread iDefense Labs
iDefense Security Advisory 06.04.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jun 04, 2008 I. BACKGROUND VMware Inc. markets several virtualization products which allow multiple virtual computers to run on a single system. For more information visit the following URL.

Re: iDefense Security Advisory 06.04.08: VMware Tools HGFS Local Privilege Escalation Vulnerability

2008-06-05 Thread iDefense Labs
iDefense Labs wrote: VII. CVE INFORMATION The Common Vulnerabilities and Exposures (CVE) project has assigned the name CVE-2008-5671 to this issue. This is a candidate for inclusion in the CVE list (http://cve.mitre.org/), which standardizes names for security problems. This should be

F5 FirePass Content Inspection Management XSS

2008-06-05 Thread nnposter
F5 FirePass Content Inspection Management XSS Product: F5 FirePass http://www.f5.com/products/firepass/ The F5 FirePass SSL VPN appliance provides rudimentary web request sanitization for resources exposed through the appliance via Portal Access. This Content Inspection feature can be

WEBAlbum = 2.0 Remote Stored Cross Site Scripting Vulnerability

2008-06-05 Thread tan_prathan
WEBAlbum = 2.0 Remote Stored Cross Site Scripting Vulnerability AUTHOR : CWH Underground DATE : 5 June 2008 SITE : www.citec.us