Joomla! 1.5.20 = Cross Site Scripting (XSS) Vulnerability

2010-10-12 Thread YGN Ethical Hacker Group
1. OVERVIEW The Joomla! web application was vulnerable to Cross Site Scripting vulnerability. 2. PRODUCT DESCRIPTION Joomla is a free and open source content management system (CMS) for publishing content on the World Wide Web and intranets. It comprises a model–view–controller (MVC) Web

[SECURITY] [DSA 2118-1] New subversion packages fix authentication bypass

2010-10-12 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - --- Debian Security Advisory DSA-2118-1 secur...@debian.org http://www.debian.org/security/ Nico Golde October 8th, 2010

JS Calendar 1.5.1 Joomla Component Multiple Remote Vulnerabilities

2010-10-12 Thread Salvatore Fresta aka Drosophila
JS Calendar 1.5.1 Joomla Component Multiple Remote Vulnerabilities Name JS Calendar Vendorhttp://www.joomlaseller.com Versions Affected 1.5.1 AuthorSalvatore Fresta aka Drosophila Website http://www.salvatorefresta.net Contact

Vulnerabilities in AltConstructor

2010-10-12 Thread MustLive
Hello Bugtraq! I want to warn you about Cross-Site Scripting and Brute Force vulnerabilities in AltConstructor. It's Ukrainian commercial CMS. - Affected products: - Vulnerable are all versions of CMS AltConstructor, before version released at

[SECURITY] [DSA-2115-2] New moodle packages fix several vulnerabilities

2010-10-12 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2115-2 secur...@debian.org http://www.debian.org/security/ Florian Weimer October 11, 2010

Re: JE Guestbook 1.0 Joomla Component Multiple Remote Vulnerabilities

2010-10-12 Thread joomextensions
Hello, We are move that error on Our 1.1 version. There are no error on latest version. Please check that. Regards, Hardik mistry

[CORE-2010-0624] MS OpenType CFF Parsing Vulnerability

2010-10-12 Thread Core Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://corelabs.coresecurity.com/ MS OpenType CFF Parsing Vulnerability 1. *Advisory Information* Title: MS OpenType CFF Parsing Vulnerability Advisory Id: CORE-2010-0624 Advisory

[ MDVSA-2010:199 ] subversion

2010-10-12 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:199 http://www.mandriva.com/security/

[ MDVSA-2010:199 ] subversion

2010-10-12 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:199 http://www.mandriva.com/security/