[Full-disclosure] [ MDVSA-2011:197 ] php

2011-12-30 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:197 http://www.mandriva.com/security/

[Full-disclosure] [SECURITY] [DSA 2376-1] ipmitool security update

2011-12-30 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2376-1 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst December 30, 2011

[Full-disclosure] [SECURITY] [DSA 2263-2] movabletype-opensource security update

2011-12-30 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2263-2 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst December 30, 2011

[Full-disclosure] Winn Guestbook v2.4.8c Stored XSS

2011-12-30 Thread tom
# Exploit Title: Winn Guestbook v2.4.8c Stored XSS # Date: 12/29/11 # Author: G13 # Software Link: http://code.google.com/p/winn-guestbook/, http://www.winn.ws # Version: 2.4.8c # Category: webapps (php) # CVE: 2011-5026 # Vulnerability # There is no sanitation on the input of the name

[Full-disclosure] DoS in TI Golden Gateway MXP Debug Application

2011-12-30 Thread will
### Will Urbanski Application:Texas Instruments Golden Gateway MXP Debug Application http://www.ti.com Vuln ID:SHR20111201 Version:2007

[Full-disclosure] SEC Consult SA-20111230-0 :: Critical authentication bypass in Microsoft ASP.NET Forms - CVE-2011-3416

2011-12-30 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory 20111230-0 === title: Microsoft ASP.NET Forms Authentication Bypass product: Microsoft .NET Framework vulnerable version: Microsoft .NET Framework

Re: [Full-disclosure] Vulnerabilities in plugins for MODx CMS, XOOPS, uCoz, Magento and DSP CMS

2011-12-30 Thread MustLive
Hello Antony! You are welcome. All those XSS vulnerabilities in 34 millions flash files, and all those vulnerable plugins for different engines with vulnerable swf-file, which I've wrote about during 2010-2011, including last five plugins, and those vulnerabilities in TinyMCE (on tens

[Full-disclosure] INSECT Pro - Version 3.0 Released!

2011-12-30 Thread runlvl
Great news!!! This 2012 we released the new version of INSECT PRO INSECT Pro 3.0 - Ultimate is here! This penetration security auditing and testing software solution is designed to allow organizations of all sizes mitigate, monitor and manage the latest security threats vulnerabilities and

Re: [Full-disclosure] INSECT Pro - Version 3.0 Released!

2011-12-30 Thread Gage Bystrom
Seriously, what the fuck is wrong with you? How many times have you been told that full disclosure is not the place for advertising your piece of shit software? On Dec 30, 2011 4:43 PM, runlvl run...@gmail.com wrote: Great news!!! This 2012 we released the new version of INSECT PRO INSECT Pro

Re: [Full-disclosure] INSECT Pro - Version 3.0 Released!

2011-12-30 Thread root
The presentation video is actually quite nice. Maybe you should diversify your business into graphical design. On 12/30/2011 09:37 PM, runlvl wrote: Great news!!! This 2012 we released the new version of INSECT PRO INSECT Pro 3.0 - Ultimate is here! This penetration security auditing and