{PRL} Novell Netware OpenSSH Remote Stack Overflow

2010-09-02 Thread Francis Provencher
# Application: Novell Netware OpenSSH Remote Stack Overflow Platforms: Netware 6.5 Exploitation: Remote code execution CVE Number: Novell TID: 7006756 ZeroDayInitiative: ZDI-10-169 Author: Francis

Vulnerabilities in CMS WebManager-Pro

2010-09-02 Thread MustLive
Hello Bugtraq! I want to warn you about SQL Injection and Redirector (URL Redirector Abuse) vulnerabilities in CMS WebManager-Pro (SecurityVulns ID:11108). It's Ukrainian commercial CMS. SQL Injection: http://site/c.php?id=1%20and%20version()=5 Redirector:

[USN-982-1] Wget vulnerability

2010-09-02 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-982-1 September 02, 2010 wget vulnerability CVE-2010-2252 === A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04

[ MDVSA-2010:168 ] openssl

2010-09-02 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:168 http://www.mandriva.com/security/

Moovida Media Player version 2.0.0.15 Insecure DLL Hijacking Vulnerability (libc.dll,quserex.dll)

2010-09-02 Thread YGN Ethical Hacker Group
1. OVERVIEW The Moovida Media Player application is vulnerable to Insecure DLL Hijacking Vulnerability. Similar terms that describe this vulnerability have been come up with Remote Binary Planting, Unsafe Library Loading, and Insecure DLL Loading/Injection/Hijacking/Preloading. 2. PRODUCT