[Full-disclosure] I miss Netdev.

2009-10-15 Thread Steven James
So I wrote him a song: http://www.soundclick.com/bands/page_songInfo.cfm?bandID=866231songID=8216151 ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia -

[Full-disclosure] Drupal XML Sitemap 6.x-1.1 XSS Vulnerability

2009-10-15 Thread Justin Klein Keane
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Details of this vulnerability can also be found at http://www.madirish.net/?article=435 Description of Vulnerability: Drupal (http://drupal.org) is a robust content management system (CMS) written in PHP and MySQL that provides extensibility through

[Full-disclosure] Snitz Forums 2000 Multiple Cross-Site Scripting Vulnerabilities

2009-10-15 Thread Andrea Fabrizi
** Application: Snitz Forums 2000 Version affected: 3.4.07 Website: http://forum.snitz.com/ Discovered By: Andrea Fabrizi Email: andrea.fabr...@gmail.com Web: http://www.andreafabrizi.it Vuln: Multiple Cross-Site Scripting

[Full-disclosure] [ MDVSA-2009:279 ] ocaml-mysql

2009-10-15 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:279 http://www.mandriva.com/security/

[Full-disclosure] [USN-849-1] libsndfile vulnerabilities

2009-10-15 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-849-1 October 15, 2009 libsndfile vulnerabilities CVE-2009-1788, CVE-2009-1791 === A security issue affects the following Ubuntu releases:

Re: [Full-disclosure] Drupal XML Sitemap 6.x-1.1 XSS Vulnerability

2009-10-15 Thread Andrew Farmer
On 15 Oct 2009, at 07:24, Justin Klein Keane wrote: Applying the following patch mitigates these threats. - --- site_map/site_map.module2009-09-30 15:09:49.295134033 -0400 +++ site_map/site_map.module 2009-09-30 15:09:30.09976 -0400 @@ -14,7 +14,7 @@ function site_map_help($path,