<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Bugtraq | Bugtraq</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>25 Nov  2009 05:36:24 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Bugtraq | Bugtraq</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>rPSA-2008-0018-1 mysql mysql-bench mysql-server</title>
<description>rPath Security Advisory: 2008-0018-1 Published: 2008-01-17 Products:   rPath Linux 1 Rating: Major Exposure Level Classification:   Local Determi</description>
<pubDate>17 Jan  2008 07:32:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26774</link>
</item><item>
<title>[SECURITY] [DSA 1465-1] New apt-listchanges packages fix arbitrary code execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>17 Jan  2008 06:38:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26771</link>
</item><item>
<title>[security bulletin] HPSBMA02133 SSRT061201 rev.7 - HP Oracle for OpenView (OfO) Critical Patch Update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c00727143 Version: 7 HPSBMA02133 SSRT061201 re</description>
<pubDate>17 Jan  2008 05:30:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26770</link>
</item><item>
<title>Clever Copy &amp;lt;=3.0 Multiple Remote Vulnerabilities</title>
<description>####################################################################  #                                 #  #</description>
<pubDate>17 Jan  2008 00:54:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26777</link>
</item><item>
<title>PHPEchoCMS Multible remote vulnerabilitis</title>
<description>Hello,, PHPEchoCMS Multible remote vulnerabilitis Discovered By : HACKERS PAL Copy rights : HACKERS PAL Website : http://www.soqor.net Email Address</description>
<pubDate>16 Jan  2008 21:07:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26773</link>
</item><item>
<title>JoomlaFlash Component Multiple Remote File Inclusion</title>
<description>Autore: Smasher Sito: http://warwolfz.altervista.org Tipo: Remote File Inclusion Rischio: Alto A remote attacker can gain access to your website thro</description>
<pubDate>16 Jan  2008 16:06:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26772</link>
</item><item>
<title>[ MDVSA-2008:016 ] - Updated apache 2.2.x packages fix multiple vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>16 Jan  2008 15:30:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26775</link>
</item><item>
<title>[USN-570-1] boost vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-570-1      January 16, 2008 boost vulnerabilities CVE-200</description>
<pubDate>16 Jan  2008 14:45:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26768</link>
</item><item>
<title>[ MDVSA-2008:015 ] - Updated apache 2.0.x packages fix multiple vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>16 Jan  2008 14:29:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26769</link>
</item><item>
<title>[ MDVSA-2008:014 ] - Updated apache 1.3.x packages fix multiple vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>16 Jan  2008 14:16:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26767</link>
</item><item>
<title>Gradman &amp;lt;= 0.1.3 (agregar_info.php?tabla=) Local File Inclusion Exploit</title>
<description>[+] Info: [~] Software: Gradman &amp;lt;= 0.1.3 [~] HomePage: http://gradman.xe1ido.com.mx/ [~] Exploit: Local File Inclusion [High] [~] Where: agregar_info</description>
<pubDate>16 Jan  2008 13:11:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26766</link>
</item><item>
<title>SQL scalar function to convert big int to dot notation</title>
<description>For those of you logging ISA (or whatever) to SQL, you&amp;#039;ll have no doubt noted that the source and destination IP&amp;#039;s are logged as long integers, and no</description>
<pubDate>16 Jan  2008 12:20:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26764</link>
</item><item>
<title>[waraxe-2008-SA#062] - Multiple Sql Injections in MyBB 1.2.10</title>
<description>[waraxe-2008-SA#062] - Multiple Sql Injections in MyBB 1.2.10 =============================================================================== Author:</description>
<pubDate>16 Jan  2008 12:19:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26762</link>
</item><item>
<title>[waraxe-2008-SA#061] - Remote Code Execution in MyBB 1.2.10</title>
<description>[waraxe-2008-SA#061] - Remote Code Execution in MyBB 1.2.10 =============================================================================== Author: J</description>
<pubDate>16 Jan  2008 12:18:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26765</link>
</item><item>
<title>TPTI-08-02: Cisco Call Manager CTLProvider Heap Overflow Vulnerability</title>
<description>TPTI-08-02: Cisco Call Manager CTLProvider Heap Overflow Vulnerability http://dvlabs.tippingpoint.com/advisory/TPTI-08-02 January 16, 2008 -- CVE ID:</description>
<pubDate>16 Jan  2008 12:12:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26763</link>
</item><item>
<title>Country by Country Computer Sets now available for ISA 2004</title>
<description>I&amp;#039;ve updated the HoG site to include Country-by-country sets for ISA 2004 for those still using that version of the product. http://hammerofgod.com/d</description>
<pubDate>16 Jan  2008 12:00:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26761</link>
</item><item>
<title>Peers static overflow in BitTorrent 6.0 and uTorrent 1.7.5</title>
<description>#######################################################################                Luigi Auriemma Applications: BitTorrent and uTo</description>
<pubDate>16 Jan  2008 10:47:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26760</link>
</item><item>
<title>mcGuestbook v1.2 Remote File Inc.</title>
<description>Author: BLaSTER a.K.a Gokhan Title: mcGuestbook v1.2 Remote File Inc. Download: http://www.hotscripts.com/jump.php?listing_id=13439&amp;amp;jump_type=1 Contac</description>
<pubDate>16 Jan  2008 10:44:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26759</link>
</item><item>
<title>Cisco Security Advisory: Cisco Unified Communications Manager CTL Provider Heap Overflow</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Cisco Security Advisory: Cisco Unified Communications Manager CTL Provider Heap Overflow Document ID:</description>
<pubDate>16 Jan  2008 08:15:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26758</link>
</item><item>
<title>RichStrong CMS (showproduct.asp?cat=) Remote SQL Injection Exploit</title>
<description>[+] Info: [~] Software: RichStrong CMS [~] HomePage: http://www.hzrich.cn [~] Exploit: Remote Sql Injection [High] [~] Where: showproduct.asp?cat= [~</description>
<pubDate>16 Jan  2008 03:36:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26748</link>
</item><item>
<title>[DSECRG-08-003] blogcms 4.2.1b Multiple Security Vulnerabilities</title>
<description>Digital Security Research Group [DSecRG] Advisory    #DSECRG-08-003  Application:          Blogcms Versions Affected:       Blogc</description>
<pubDate>16 Jan  2008 03:02:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26747</link>
</item><item>
<title>[DSECRG-08-002] Local File Include in arias 0.99-6</title>
<description>Digital Security Research Group [DSecRG] Advisory    #DSECRG-08-002  Application:          aria-0.99-6 (Web based ERP) Versions Affected</description>
<pubDate>16 Jan  2008 02:37:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26753</link>
</item><item>
<title>cPanel Hosting Manager (dohtaccess.html)</title>
<description>Aria-Security Team http://Aria-Security.Net ----------------------------------- Vendor: http://cPanel.com cPanel Hosting Manager (dohtaccess.html) Cro</description>
<pubDate>15 Jan  2008 20:09:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26750</link>
</item><item>
<title>[Aria-Security.Net] Real Estate Web SQL Injection</title>
<description>Aria-Security Team, http://Aria-Security.net ------------------------------- Shout Outs: Vendor: http://www.site2nite.com/ Google Search: Website Dev</description>
<pubDate>15 Jan  2008 19:42:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26756</link>
</item><item>
<title>8e6 Technologies R3000 Internet Filter Bypass by Request Split</title>
<description>8e6 Technologies R3000 Internet Filter Bypass by Request Split  Product: 8e6 Technologies R3000 Internet Filter http://www.8e6.com/network-security/</description>
<pubDate>15 Jan  2008 18:55:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26755</link>
</item><item>
<title>[SECURITY] [DSA 1464-1] New syslog-ng packages fix denial of service</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>15 Jan  2008 15:47:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26746</link>
</item><item>
<title>iDefense Security Advisory 01.15.08: Apple QuickTime Macintosh Resource Processing Heap Corruption Vulnerability</title>
<description>iDefense Security Advisory 01.15.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jan 15, 2008 I. BACKGROUND Quicktime is Apple&amp;#039;s media pla</description>
<pubDate>15 Jan  2008 15:15:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26757</link>
</item><item>
<title>TPTI-08-01: Apple Quicktime Image File IDSC Atom Memory Corruption Vulnerability</title>
<description>TPTI-08-01: Apple Quicktime Image File IDSC Atom Memory Corruption  Vulnerability http://www.zerodayinitiative.com/advisories/TPTI-08-01.html January</description>
<pubDate>15 Jan  2008 15:02:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26754</link>
</item><item>
<title>rPSA-2008-0017-1 libxml2</title>
<description>rPath Security Advisory: 2008-0017-1 Published: 2008-01-15 Products:   rPath Appliance Platform Linux Service 1   rPath Linux 1 Rating: Minor Exp</description>
<pubDate>15 Jan  2008 14:54:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26752</link>
</item><item>
<title>rPSA-2008-0016-1 postgresql postgresql-server</title>
<description>rPath Security Advisory: 2008-0016-1 Published: 2008-01-15 Products:   rPath Linux 1 Rating: Minor Exposure Level Classification:   Remote Determ</description>
<pubDate>15 Jan  2008 14:53:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26751</link>
</item><item>
<title>rPSA-2008-0015-1 cairo</title>
<description>rPath Security Advisory: 2008-0015-1 Published: 2008-01-15 Products:   rPath Linux 1 Rating: Major Exposure Level Classification:   Indirect User</description>
<pubDate>15 Jan  2008 14:52:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26749</link>
</item><item>
<title>iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTServer Multiple Untrusted Loop Bounds Vulnerabilities</title>
<description>iDefense Security Advisory 01.15.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jan 15, 2008 I. BACKGROUND TIBCO SmartSockets is a messag</description>
<pubDate>15 Jan  2008 11:18:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26743</link>
</item><item>
<title>iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTserver Multiple Untrusted Pointer Offset Vulnerabilities</title>
<description>iDefense Security Advisory 01.15.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jan 15, 2008 I. BACKGROUND TIBCO SmartSockets is a messag</description>
<pubDate>15 Jan  2008 11:12:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26742</link>
</item><item>
<title>iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTServer Multiple Untrusted Pointer Vulnerabilities</title>
<description>iDefense Security Advisory 01.15.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jan 15, 2008 I. BACKGROUND TIBCO SmartSockets is a messag</description>
<pubDate>15 Jan  2008 11:04:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26741</link>
</item><item>
<title>iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTserver Heap Overflow Vulnerability</title>
<description>iDefense Security Advisory 01.15.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jan 15, 2008 I. BACKGROUND TIBCO SmartSockets is a messag</description>
<pubDate>15 Jan  2008 11:01:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26740</link>
</item><item>
<title>Pipe to FOR Crashes CMD</title>
<description>Pipe the output of a command to FOR in (), and you crash the Windows Vista Windows Command Processor (CMD.exe) with a DEP violation. I expect it works</description>
<pubDate>15 Jan  2008 07:41:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26732</link>
</item><item>
<title>MicroNews Admin Direct Access vulnerability</title>
<description># MicroNews Authentication Bypass # Homepage: http://phptoys.com/ # Download: http://www.phptoys.com/download.php?view.31 # Found by Xcross87 | xcross</description>
<pubDate>15 Jan  2008 07:33:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26731</link>
</item><item>
<title>Max&amp;#039;s File Uploader File Upload Vulnerability</title>
<description># Max&amp;#039;s File Uploader File Upload Vulnerability # Homepage: http://www.phpf1.com/ # Download: http://www.phpf1.com/download.html?item=9 # Dork: intitl</description>
<pubDate>15 Jan  2008 07:12:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26730</link>
</item><item>
<title>[security bulletin] HPSBST02304 SSRT080003 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-001 to MS08-002</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01325239 Version: 1 HPSBST02304 SSRT080003 re</description>
<pubDate>15 Jan  2008 06:10:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26712</link>
</item><item>
<title>[security bulletin] HPSBUX02303 SSRT071468 rev.1 - HP-UX Running X Font Server (xfs) Software, Remote Execution of Arbitrary Code</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01323725 Version: 1 HPSBUX02303 SSRT071468 re</description>
<pubDate>15 Jan  2008 06:09:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26711</link>
</item><item>
<title>Article DashBoard all version SQL Injection Vulnerability</title>
<description>########################################################################## # ArticleDashBoard all version SQL Injection Vulnerability        #</description>
<pubDate>15 Jan  2008 05:36:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26729</link>
</item><item>
<title>SecurityReason - Apache (mod_status) Refresh Header - Open Redirector (XSS)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [SecurityReason - Apache (mod_status) Refresh Header - Open Redirector (XSS)] Author: sp3x Date: - -</description>
<pubDate>15 Jan  2008 00:33:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26727</link>
</item><item>
<title>Exploiting the SpamBam plugin for wordpress</title>
<description>The attached exploit demonstrates that the WordPress SpamBam plugin can be bypassed due to relying on the client for security. Vulnerable software: S</description>
<pubDate>14 Jan  2008 22:01:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26721</link>
</item><item>
<title>Defeating audio captcha systems</title>
<description>Hi all, Some days ago I wrote an advisory which demonstrates how the Peter&amp;#039;s Math Antispam Spinoff plugin for wordpress (http://www.theblog.ca/math-a</description>
<pubDate>14 Jan  2008 22:01:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26719</link>
</item><item>
<title>[USN-569-1] libxml2 vulnerability</title>
<description>=========================================================== Ubuntu Security Notice USN-569-1      January 14, 2008 libxml2 vulnerability CVE-200</description>
<pubDate>14 Jan  2008 16:13:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26717</link>
</item><item>
<title>FreeBSD Security Advisory FreeBSD-SA-08:02.libc</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ============================================================================= FreeBSD-SA-08:02.libc</description>
<pubDate>14 Jan  2008 15:09:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26716</link>
</item><item>
<title>FreeBSD Security Advisory FreeBSD-SA-08:01.pty</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ============================================================================= FreeBSD-SA-08:01.pty</description>
<pubDate>14 Jan  2008 15:09:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26715</link>
</item><item>
<title>[ MDVSA-2008:013 ] - Updated python packages fix vulnerability in imageop module</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>14 Jan  2008 15:04:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26714</link>
</item><item>
<title>[ MDVSA-2008:012 ] - Updated python packages fix vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>14 Jan  2008 14:56:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26713</link>
</item><item>
<title>Country by Country ISA Computer Sets</title>
<description>Recently, David Litchfield asked me to help him out a bit with a research project he was working on by having me set up a network capture in my DMZ to</description>
<pubDate>14 Jan  2008 14:20:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26720</link>
</item><item>
<title>[USN-568-1] PostgreSQL vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-568-1      January 14, 2008 postgresql vulnerabilities CV</description>
<pubDate>14 Jan  2008 13:31:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26709</link>
</item><item>
<title>[SECURITY] [DSA 1463-1] New postgresql-7.4 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>14 Jan  2008 10:51:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26706</link>
</item><item>
<title>ZDI-08-001: IBM Tivoli Storage Manager Express Backup Server Heap Overflow Vulnerability</title>
<description>ZDI-08-001: IBM Tivoli Storage Manager Express Backup Server Heap Overflow  Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-08-001.htm</description>
<pubDate>14 Jan  2008 10:51:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26705</link>
</item><item>
<title>Binn SBuilder (nid) Remote Blind Sql Injection Vulnerabily</title>
<description>[+] Info: [~] Software: Binn SBuilder [~] HomePage: http://www.cms.ge/ [~] Exploit: Blind Sql Injection [High] [~] Where: full_text.php?nid= [~] Bug</description>
<pubDate>14 Jan  2008 08:59:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26701</link>
</item><item>
<title>Re: [Full-disclosure] Buffer-overflow in Quicktime Player 7.3.1.70</title>
<description>Marcello Barnaba (void) &amp;lt;vjt@openssl.it&amp;gt; wrote: &amp;gt; By the way, even with &amp;quot;Transport setup&amp;quot; -&amp;gt; &amp;quot;Automatic&amp;quot;, the software &amp;gt; doesn&amp;#039;t crash nor loops after</description>
<pubDate>14 Jan  2008 06:56:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26686</link>
</item><item>
<title>F5 BIG-IP Web Management List Search XSS</title>
<description>F5 BIG-IP Web Management List Search XSS  Product: F5 BIG-IP http://www.f5.com/products/big-ip/  The F5 BIG-IP web management interface contains a c</description>
<pubDate>14 Jan  2008 06:36:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26678</link>
</item><item>
<title>SQID v0.3 - SQL Injection Digger.</title>
<description>SQL injection digger is a command line program that looks for SQL injections and common errors in websites. This version now can perform the following</description>
<pubDate>14 Jan  2008 06:17:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26685</link>
</item><item>
<title>Re: [Full-disclosure] what is this?</title>
<description>Dear crazy frog crazy frog,  Clear your computer from trojan, change FTP password for you site  hosting access, because it&amp;#039;s stolen, access</description>
<pubDate>14 Jan  2008 01:34:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26682</link>
</item><item>
<title>[SECURITY] [DSA 1462-1] New hplip packages fix privilege escalation</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>13 Jan  2008 09:14:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26675</link>
</item><item>
<title>[SECURITY] [DSA 1461-1] New libxml2 packages fix denial of service</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>13 Jan  2008 08:57:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26710</link>
</item><item>
<title>what is this?</title>
<description>Hi, Recently on opening one of my site,my antivirus pops up saying that it has found on malicious script.the url is random and i have managed to get</description>
<pubDate>13 Jan  2008 08:01:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26676</link>
</item><item>
<title>[SECURITY] [DSA 1460-1] New postgresql-8.1 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>13 Jan  2008 07:45:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26681</link>
</item><item>
<title>[SECURITY] [DSA 1459-1] New gforge packages fix SQL injection</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>13 Jan  2008 07:07:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26693</link>
</item><item>
<title>Hacking The Interwebs</title>
<description>http://www.gnucitizen.org/blog/hacking-the-interwebs When the victim visits a malicious SWF file, a 4 step ATTACK will silently execute in the backgr</description>
<pubDate>13 Jan  2008 00:27:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26704</link>
</item><item>
<title>[ MDVSA-2008:009-1 ] - Updated autofs packages fix insecure hosts configuration</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>12 Jan  2008 14:06:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26679</link>
</item><item>
<title>Garment Center (index.cgi) Local File Inclusion</title>
<description>[+] Discovered by Smasher [+] WarWolfz Crew. [+] http://warwolfz.altervista.org/ Hey wassup....i&amp;#039;ve found a vulnerability in Garmentcenter in index.</description>
<pubDate>12 Jan  2008 08:44:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26674</link>
</item><item>
<title>Safari 2 Denial of Service</title>
<description>##############################################################            - S21Sec Advisory - ############################################</description>
<pubDate>12 Jan  2008 07:30:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26671</link>
</item><item>
<title>[ MDVSA-2008:011 ] - Updated rsync packages fix restrictions bypass vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>11 Jan  2008 17:19:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26670</link>
</item><item>
<title>[ MDVSA-2008:010 ] - Updated libxml2 packages fix DoS vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>11 Jan  2008 17:05:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26669</link>
</item><item>
<title>Cross site scripting (XSS) in Moodle 1.8.3</title>
<description>Source URL of this announcement: http://int21.de/cve/CVE-2008-0123-moodle.html References http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0123</description>
<pubDate>11 Jan  2008 15:51:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26668</link>
</item><item>
<title>[ MDVSA-2008:009 ] - Updated autofs packages fix insecure hosts configuration</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>11 Jan  2008 15:00:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26672</link>
</item><item>
<title>[ MDVSA-2008:008 ] - Updated kernel packages fix multiple vulnerabilities and bugs</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>11 Jan  2008 13:56:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26673</link>
</item><item>
<title>RE: At long last - Extra Outlooks!</title>
<description>FYI - this works for 2007, not 2003. We&amp;#039;re seeing about writing one for 2003, but it may be a few weeks. Thanks! t &amp;gt; -----Original Message----- &amp;gt; F</description>
<pubDate>11 Jan  2008 11:07:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26688</link>
</item><item>
<title>Naymz multiple XSS</title>
<description>Naymz is a online profile system with positive and accurate information that you want others to find when they search for you online.  Community Sear</description>
<pubDate>11 Jan  2008 09:11:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26665</link>
</item><item>
<title>Member Area System (MAS) Remote File Include Vulnerability (view_func.php)</title>
<description>---------------------------------------------------------------------- Member Area System (MAS) Remote File Include Vulnerability (view_func.php) --</description>
<pubDate>11 Jan  2008 03:12:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26663</link>
</item><item>
<title>CFP: EuroSec Workshop (March 31st, 2008)</title>
<description>[. Our anticipate apologies if you receive this call for paper more than once! ] CALL FOR PAPERS - EUROSEC WORKSHOP  EuroSec (http://www.cs.vu.nl/eu</description>
<pubDate>11 Jan  2008 01:12:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26662</link>
</item><item>
<title>At long last -- Extra Outlooks!</title>
<description>As long as Outlook has been around, people have been trying to get two instances running at the same time. Not multiple profiles that you can load whe</description>
<pubDate>10 Jan  2008 22:28:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26656</link>
</item><item>
<title>[ MDVSA-2008:007 ] - Updated madwifi-source, wpa_supplicant packages fix vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>10 Jan  2008 21:44:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26657</link>
</item><item>
<title>re-resting of zzuf results</title>
<description>I&amp;#039;ve also posted this to my blog: http://hboeck.de/archives/578-How-long-does-it-take-to-fix-a-crash-bug.html   About one year ago, Sam Hocevar pos</description>
<pubDate>10 Jan  2008 21:06:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26655</link>
</item><item>
<title>ImageAlbum Remote SQL Injection Vulnerabilities</title>
<description>ImageAlbum Remote SQL Injection Vulnerabilities ------------------------------------------------------------------------- Product: ImageAlbum Version</description>
<pubDate>10 Jan  2008 19:09:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26664</link>
</item><item>
<title>SecurityReason - Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [SecurityReason - Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability] Author: sp3x Date</description>
<pubDate>10 Jan  2008 15:30:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26658</link>
</item><item>
<title>SecurityReason - Apache2 CSRF, XSS, Memory Corruption and Denial of Service Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [Apache2 CSRF, XSS, Memory Corruption and Denial of Service Vulnerability ] Author: sp3x Date: - - Wr</description>
<pubDate>10 Jan  2008 15:29:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26660</link>
</item><item>
<title>[USN-567-1] Dovecot vulnerability</title>
<description>=========================================================== Ubuntu Security Notice USN-567-1      January 10, 2008 dovecot vulnerability CVE-200</description>
<pubDate>10 Jan  2008 14:01:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26653</link>
</item><item>
<title>[SECURITY] [DSA 1458-1] New openafs packages fix denial of service vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>10 Jan  2008 12:47:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26650</link>
</item><item>
<title>[ MDVSA-2008:006 ] - Updated exiv2 packages fix vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>10 Jan  2008 12:06:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26651</link>
</item><item>
<title>Buffer-overflow in Quicktime Player 7.3.1.70</title>
<description>#######################################################################                Luigi Auriemma Application: Quicktime Player</description>
<pubDate>10 Jan  2008 10:45:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26648</link>
</item><item>
<title>MTCMS &amp;lt;=2.0 SQL Injection Vulnerbility</title>
<description>########################################################################       #</description>
<pubDate>10 Jan  2008 10:18:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26649</link>
</item><item>
<title>Word 2007 Email as PDF path disclosure flaw</title>
<description>Intro: Word 2007 is the latest installment of Microsoft&amp;#039;s word processing program Bug: Word 2007 with the &amp;quot;save as pdf&amp;quot; add-on is vulnerable to a pat</description>
<pubDate>10 Jan  2008 08:07:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26647</link>
</item><item>
<title>BT Home Flub: Pwnin the BT Home Hub (5) - exploiting IGDs remotely via UPnP</title>
<description>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-5 It&amp;#039;s known that UPnP [1] is inherently insecure for a very simple reason: adminis</description>
<pubDate>10 Jan  2008 04:20:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26646</link>
</item><item>
<title>PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager</title>
<description>PR07-06, PR07-07, PR07-08, PR07-09, PR07-10, PR07-12: Several XSS, Cross-domain Redirection and Frame Injection on Sun Java System Identity Manager</description>
<pubDate>10 Jan  2008 04:00:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26642</link>
</item><item>
<title>uCon 2008 call for participation - Recife, Brazil</title>
<description>.--.    : .--&amp;#039; .-..-.: :  .--. ,-.,-. : :; :: :__ &amp;#039; .; :: ,. : `.__.&amp;#039;`.__.&amp;#039;`.__.&amp;#039;:_;:_;           CALL FOR PARTICIPATION uCon 2008, 1st</description>
<pubDate>10 Jan  2008 03:02:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26640</link>
</item><item>
<title>Digital Armaments January-February Hacking Challenge: Special 20.000$ Prize - Windows Vulnerabilities and Exploit</title>
<description>Digital Armaments January-February Hacking Challenge: Special 20.000$ Prize - Windows Vulnerabilities and Exploit Challenge pubblication is 01.04.200</description>
<pubDate>10 Jan  2008 02:36:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26644</link>
</item><item>
<title>Simple Machines Forum Cross-Site Scripting Vulnerabilities</title>
<description>[HSC] Simple Machines Forum XSS Vulnerabilities  Simple Machines Forum allows attackers to exploiting this vulnerability by cross-site scripting and</description>
<pubDate>09 Jan  2008 18:12:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26641</link>
</item><item>
<title>[USN-566-1] OpenSSH vulnerability</title>
<description>=========================================================== Ubuntu Security Notice USN-566-1      January 09, 2008 openssh vulnerability CVE-200</description>
<pubDate>09 Jan  2008 18:00:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26643</link>
</item><item>
<title>[ GLSA 200801-06 ] Xfce: Multiple vulnerabilities</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory            GLSA 200801-06:02 - - -</description>
<pubDate>09 Jan  2008 15:26:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26645</link>
</item><item>
<title>[ MDVSA-2008:005 ] - Updated libexif packages fix multiple vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>09 Jan  2008 14:56:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26638</link>
</item><item>
<title>[USN-565-1] Squid vulnerability</title>
<description>=========================================================== Ubuntu Security Notice USN-565-1      January 09, 2008 squid vulnerability CVE-2007-</description>
<pubDate>09 Jan  2008 14:22:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26636</link>
</item><item>
<title>[ GLSA 200801-05 ] Squid: Denial of Service</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisor</description>
<pubDate>09 Jan  2008 14:17:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26635</link>
</item><item>
<title>[SECURITY] [DSA 1457-1] New dovecot packages fix information disclosure</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>09 Jan  2008 14:15:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26639</link>
</item><item>
<title>[SECURITY] [DSA 1456-1] New fail2ban packages fix denial of service</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>09 Jan  2008 14:02:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26634</link>
</item>
</channel>
</rss>
