Onpub CMS 1.4 1.5 - Multiple SQL Injection Vulnerabilities

2013-10-28 Thread Vulnerability Lab
Document Title: === Onpub CMS 1.4 1.5 - Multiple SQL Injection Vulnerabilities References (Source): http://www.vulnerability-lab.com/get_content.php?id=1120 Release Date: = 2013-10-26 Vulnerability Laboratory ID (VL-ID):

Feeder.co RSS Feeder 5.2 Chrome - Persistent Software Vulnerability

2013-10-28 Thread Vulnerability Lab
Document Title: === Feeder.co RSS Feeder 5.2 Chrome - Persistent Software Vulnerability Release Date: = 2013-10-26 Vulnerability Laboratory ID (VL-ID): 1119 Common Vulnerability Scoring System:

Paypal Inc Bug Bounty #104 - Persistent Exception Vulnerability

2013-10-28 Thread Vulnerability Lab
Document Title: === Paypal Inc Bug Bounty #104 - Persistent Exception Vulnerability References (Source): http://www.vulnerability-lab.com/get_content.php?id=1038 PayPal Security UID: gJ1127yy Release Date: = 2013-10-26 Vulnerability Laboratory ID

[SECURITY] [DSA 2785-1] chromium-browser security update

2013-10-28 Thread Michael Gilbert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2785-1 secur...@debian.org http://www.debian.org/security/ Michael Gilbert October 26, 2013

[SECURITY] [DSA 2787-1] roundcube security update

2013-10-28 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2787-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso October 27, 2013

Call for Papers, 2014 Symposium on Cryptography and Authentication (SCA2014) , Suzhou, China

2013-10-28 Thread 2014 Symposium on Cryptography and Authentication (SCA2014)
This message was sent to [bugtraq@securityfocus.com]. Unsubscribe If you cannot read it, please click here. Call for Papers 2014 Symposium on Cryptography and Authentication (SCA2014)

[CVE-2012-6297] DD-WRT v24-sp2 Command Injection

2013-10-28 Thread Craig Young
Unfortunately command injections like the NETGEAR one Zachary Cutlip and I both came across are all too common in embedded systems. Similar to NETGEAR and Linksys having commands injected when running ping, I have also noticed that DD-WRT v24-sp2 is prone to command injection from specially

Call for Papers, 2014 Symposium on Protocols and Rules for Security (SPRS2014)

2013-10-28 Thread 2014 Symposium on Protocols and Rules for Security (SPRS2014)
This message was sent to [bugtraq@securityfocus.com]. Unsubscribe If you cannot read it, please click here. 2014 Symposium on Protocols and Rules for Security (SPRS2014) Call for Papers

[SECURITY] [DSA 2786-1] icu security update

2013-10-28 Thread Michael Gilbert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2786-1 secur...@debian.org http://www.debian.org/security/ Michael Gilbert October 27, 2013

Multiple CSRF Horde Groupware Web mail Edition 5.1.2

2013-10-28 Thread m . benetrix
# Exploit Title : Multiple CSRF Horde Groupware Web mail Edition Author:Marcela Benetrix Date: 10/25/13 version: 5.1.2 software link:http://www.horde.org/apps/webmail # GroupWare Web mail Edition Horde Groupware Webmail Edition is a free,

vBulletin remote admin injection exploit

2013-10-28 Thread simo
#!/usr/bin/perl # # Title: vBulletin remote admin injection exploit # Author: Simo Ben youssef # Contact: Simo_at_Morxploit_com # Coded: 17 September 2013 # Published: 24 October 2013 # MorXploit Research # http://www.MorXploit.com # # Vendor: vBulletin (www.vbulletin.com) # Version: 4.1.x /

[ISecAuditors Security Advisories] XSS vulnerability in LinkedIn

2013-10-28 Thread ISecAuditors Security Advisories
= INTERNET SECURITY AUDITORS ALERT 2013-003 - Original release date: March 3rd, 2013 - Last revised: March 10th, 2013 - Discovered by: Vicente Aguilera Diaz - Severity: 4.3/10 (CVSSv2 Base Score) = I.

[scip_Advisory 10847] MobileIron 4.5.4 Device Registration regpin Cross Site Scripting

2013-10-28 Thread Marc Ruef
MobileIron 4.5.4 Device Registration regpin Cross Site Scripting scip AG Vulnerability ID 10847 (10/28/2013) http://www.scip.ch/en/?vuldb.10847 I. INTRODUCTION MobileIron is a commercial solution to provide secure access to mobile users in corporate environments. More information is available

[PT-2013-46] Local File Include in Nagios Looking Glass

2013-10-28 Thread noreply
--- (PT-2013-46) Positive Technologies Security Advisory Local File Include in Nagios Looking Glass --- ---[ Vulnerable software ] Nagios Looking Glass Version: 1.1.0 beta 2

Re: Call for Papers, 2014 Symposium on Protocols and Rules for Security (SPRS2014)

2013-10-28 Thread Brandon Butterworth
td style=PADDING-BOTTOM: 5px; LINE-HEIGHT: 22px; PADDING-LEFT: 5px; PADDING-RIGHT: 5px; FONT-FAMILY: Times New Roman; COLOR: #2b2b2b; FONT-SIZE: 19px; PADDING-TOP: 5px align=leftp style=line-height:23px;font-size:20px;Dear Colleagues,/p pWe would like to cordially invite you to submit

ILIAS eLearning 4.3.4 4.4 CMS - Persistent Notes Web Vulnerability

2013-10-28 Thread Vulnerability Lab
Document Title: === ILIAS eLearning 4.3.4 4.4 CMS - Persistent Notes Web Vulnerability References (Source): http://www.vulnerability-lab.com/get_content.php?id=1122 Release Date: = 2013-10-27 Vulnerability Laboratory ID (VL-ID):

CVE-2013-5695 Multilple Cross Site Scripting (XSS) Attacks in Ops View

2013-10-28 Thread J. Oquendo
CVE-2013-5695 Multilple Cross Site Scripting (XSS) Attacks in Ops View Version(s): Opsview pre 4.4.1 Author: J. Oquendo (joquendo at e-fensive dot net) I. ADVISORY Title: Multilple Cross Site Scripting (XSS) Attacks in Ops View Date published: 2013-10-28 Vendor contacted: 2013-09-04 II.