Linksys Cisco Wag120N CSRF Vulnerability

2011-02-25 Thread irancrash
Hardware : Linksys Cisco Wag120n(And perhaps similar versions) Type of vunlnerability : CSRF ( Change Admin Password And Add User ) Risk of use : High Producer Website

prestashop vuln: sql injection submitted to bugtraq@securityfocus.com

2011-02-25 Thread Antonio S.M
Hello, I am Antonio San Martino, i write you to incloude this sql injection vulnerabilities in your database. The vulnerable version is prestashop 1.3.3 and is vulnerable to sql injection Vulnerable software and vendor: Prestashop, verion: 1.3.3 - 0.246s Sql Injection Vulnerabilities

[BMSA-2011-01] Insecure secure cookie in web.go

2011-02-25 Thread Nam Nguyen
BLUE MOON SECURITY ADVISORY 2011-01 === :Title: Insecure secure cookie in web.go :Severity: Low :Reporter: Blue Moon Consulting :Products: web.go :Fixed in: -- Description --- web.go is the simplest way to write web applications in the Go programming

CA20110223-01: Security Notice for CA Host-Based Intrusion Prevention System

2011-02-25 Thread Williams, James K
CA20110223-01: Security Notice for CA Host-Based Intrusion Prevention System Issued: February 23, 2011 Updated: February 24, 2011 CA Technologies support is alerting customers to a security risk associated with CA Host-Based Intrusion Prevention System (HIPS). A vulnerability exists that can

DoS Condition with Altigen VoIP Phone Systems

2011-02-25 Thread Patrick Kelley
If you run a NMAP network scan against the IP of the phone server, it will crash the Altigen's Gateway service, rendering the system useless until rebooted. All information saved in the phone system at the time is lost. Port 5061 crashes due to HEAP Overflow. Following message: Application

Re: Linksys Cisco Wag120N CSRF Vulnerability

2011-02-25 Thread tadeu1
I would like to recommend to people who want to test the code to disable/wipe out unnecessary options such as remote_management and http_wanport since they could give eventual outside attacker chances of authentication. Another doubt lies on the possibility that this code implictly relies on a

[USN-1071-1] Linux kernel vulnerabilities

2011-02-25 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-1071-1 February 25, 2011 linux-source-2.6.15 vulnerabilities CVE-2010-3086, CVE-2010-3859, CVE-2010-3873, CVE-2010-3875, CVE-2010-3876, CVE-2010-3880, CVE-2010-4078, CVE-2010-4080, CVE-2010-4081,