[security bulletin] HPSBOV02364 SSRT080078 rev.3 - HP OpenVMS SMGRTL Run Time Library, Local Authorized User, Gain Privileged Access

2008-09-25 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01539423 Version: 3 HPSBOV02364 SSRT080078 rev.3 - HP OpenVMS SMGRTL Run Time Library, Local Authorized User, Gain Privileged Access NOTICE: The information in this Security Bulletin should

php create_function commond injection vulnerability

2008-09-25 Thread root
php use create_function function to CREATE an anonymous function like below(stolen from php_manual): -- Description string create_function ( string args, string code ) Creates an anonymous function from the parameters passed, and returns a unique

Google Docs (HTML code) Multiple Cross Site Scripting Vulnerabilities

2008-09-25 Thread alfredo . melloni
Google Docs (HTML code) Multiple Cross Site Scripting Vulnerabilities I. Background: Google Docs is an online application which makes possibile to Create and share your work online. You can use it to create Documents, Presentations, Spreadsheets and Forms. II. Description: Multiple cross site

[security bulletin] HPSBST02372 SSRT080133 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-052 to MS08-055

2008-09-25 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01560892 Version: 1 HPSBST02372 SSRT080133 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-052 to MS08-055 NOTICE: The information in this Security Bulletin

Re: php create_function commond injection vulnerability

2008-09-25 Thread lmfao
Are you kidding ? As the PHP manual said if you use double quotes there will be a need to escape the variable names. In your example you use a function with double quotes, without escaping the variable $sort_by, so this is not a PHP vulnerability, but a development one. For this time,

C4 Security Advisory - ABB PCU400 4.4-4.6 Remote Buffer Overflow

2008-09-25 Thread Idan Ofrat
Background - Vendor product information: PCU400 is the modern product when implementing an effective data acquisition network in SCADA-based systems PCU400, Process Communication Unit 400 forms the communication interface to the network of remote terminal units (RTUs) together

Cross Site Scripting (XSS) Vulnerabilitiy in flatpress 0.804, CVE-2008-4120

2008-09-25 Thread Fabian Fingerle
Cross Site Scripting (XSS) Vulnerabilitiy in flatpress 0.804, CVE-2008-4120 References http://www.datensalat.eu/~fabian/cve/CVE-2008-4120-flatpress.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4120 http://www.flatpress.org/ Description FlatPress is an open-source

adnforum = 1.0b / Insecure Cookie Handling Vulnerability

2008-09-25 Thread Pepelux
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- adnforum = 1.0b / Insecure Cookie Handling Vulnerability -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- $ Program: adnforum $ Version: = 1.0b $ File affected: index.php $ Download: http://sourceforge.net/projects/adnforum/

Fwd: Returned post for bugtraq@securityfocus.com

2008-09-25 Thread Jose Luis
#! /usr/bin/perl # -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- # Libra PHP File Manager = 1.18 / Local File Inclusion Vulnerability # -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- # Program: Libra PHP File Manager # Version: = 1.18 # File affected:

[USN-645-3] Firefox and xulrunner regression

2008-09-25 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-645-3 September 25, 2008 firefox-3.0, xulrunner-1.9 regression https://launchpad.net/bugs/270429 === A security issue affects the following

SQL Injection in EasyRealtorPRO 2008

2008-09-25 Thread SmOk3
Original article: http://www.davidsopas.com/2008/09/sql-injection-in-easyrealtorpro/ EasyRealtorPRO 2008 provides you with all features you need to setup your own business oriented real estate website on your own domain name. Our support team will install the script on your server and then you

[ GLSA 200809-16 ] Git: User-assisted execution of arbitrary code

2008-09-25 Thread Pierre-Yves Rofes
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200809-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - -

[ GLSA 200809-17 ] Wireshark: Multiple Denials of Service

2008-09-25 Thread Pierre-Yves Rofes
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200809-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - -

[ GLSA 200809-18 ] ClamAV: Multiple Denials of Service

2008-09-25 Thread Pierre-Yves Rofes
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200809-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - -