<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Full Disclosure | Full-Disclosure</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>13 Feb  2012 01:42:56 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Full Disclosure | Full-Disclosure</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>[ MDVSA-2012:017 ] firefox</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>12 Feb  2012 12:23:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85020</link>
</item><item>
<title>Trustwave and Mozilla</title>
<description>Hi All, https://www.infoworld.com/d/security/trustwave-admits-issuing-man-in-the-middle-digital-certificate-185972 In case folks are interested in t</description>
<pubDate>12 Feb  2012 02:54:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85009</link>
</item><item>
<title>eFront Community++ v3.6.10 - SQL Injection Vulnerability</title>
<description>Title: ====== eFront Community++ v3.6.10 - SQL Injection Vulnerability  Date: ===== 2012-02-11  References: =========== http://www.vulnerability-lab</description>
<pubDate>11 Feb  2012 10:53:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85011</link>
</item><item>
<title>Yahoo! Messenger v11.5 - Buffer Overflow Vulnerability</title>
<description>Title: ====== Yahoo! Messenger v11.5 - Buffer Overflow Vulnerability  Date: ===== 2012-02-11  References: =========== http://www.vulnerability-lab.c</description>
<pubDate>11 Feb  2012 10:51:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85010</link>
</item><item>
<title>[Announcement] ClubHack Mag - Call for Articles</title>
<description>Hello All, ClubHack Magazine is seeking submissions for next issue, Issue 26 - March 2012. Topics:- 1. Web App Sec 2. OS Exploitation and Security 3</description>
<pubDate>10 Feb  2012 22:22:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85004</link>
</item><item>
<title>[ MDVSA-2012:016 ] glpi</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>10 Feb  2012 11:00:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84998</link>
</item><item>
<title>New Android Malware Botnet Reversed/Uncovered</title>
<description>Hello, one of InfoSec Institute&amp;#039;s security researchers reverse engineered a new botnet that is active for the Android platform. RootSmart has some uni</description>
<pubDate>10 Feb  2012 10:56:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84997</link>
</item><item>
<title>[Off-Spanish] Webinario gratuito - Ataques DoS en latino america</title>
<description>Fecha y hora: Sabado, Febrero 11 2012 - 18:00 PM ( Hora Argentina GMT - 3:00 ) En el webinario veremos de forma practica y teorica como se ejecutan l</description>
<pubDate>10 Feb  2012 10:24:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84996</link>
</item><item>
<title>Multiple CSRF, DoS and XSS vulnerabilities in D-Link DAP 1150</title>
<description>Hello list! I want to warn you about new security vulnerabilities in D-Link DAP 1150 (Wi-Fi Access Point and Router). These are Cross-Site Request</description>
<pubDate>10 Feb  2012 10:21:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84995</link>
</item><item>
<title>Yahoo Messenger - Buffer Overflow Vulnerability [Video]</title>
<description>Title: ====== Yahoo Messenger - Buffer Overflow Vulnerability [Video]  Date: ===== 2012-02-10  References: =========== Download:    http://www.vu</description>
<pubDate>10 Feb  2012 09:41:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85005</link>
</item><item>
<title>Zen-Cart Admin CSRF/XSRF - Delete / Disable Products | UPS-2011-0018 | CVE-2011-4403</title>
<description>*Advisory Information* Title: Zen-Cart Admin CSRF/XSRF - Delete / Disable Products Date published: 2012-02-10 01:59:45 AM upSploit Ref: UPS-2011-0018</description>
<pubDate>10 Feb  2012 08:10:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84993</link>
</item><item>
<title>CubeCart 3.0.20 (3.0.x) and lower | Open URL Redirection Vulnerability</title>
<description>1. OVERVIEW The CubeCart 3.0.20 and lower versions are vulnerable to Open URL Redirection.  2. BACKGROUND CubeCart is an &amp;quot;out of the box&amp;quot; ecommerce</description>
<pubDate>10 Feb  2012 08:01:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84992</link>
</item><item>
<title>Linux Kloxo LxCenter Server CP v6.1.10 - Multiple Web Vulnerabilities</title>
<description>Title: ====== Kloxo LxCenter Server CP v6.1.10 - Multiple Web Vulnerabilities  Date: ===== 2012-02-10  References: =========== http://www.vulnerabil</description>
<pubDate>10 Feb  2012 06:25:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84988</link>
</item><item>
<title>Indianapolis Superbowl 2012 - SQL Injection Vulnerabilities</title>
<description>Title: ====== Indianapolis Superbowl 2012 - SQL Injection Vulnerabilities  Date: ===== 2012-02-06  VL-ID: ===== 418  Abstract: ========= Alexander</description>
<pubDate>10 Feb  2012 03:28:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84984</link>
</item><item>
<title>Astaro Security Gateway - bypass using whitelist domain pattern weakness</title>
<description>*Advisory Information* Title: Astaro Security Gateway - bypass using whitelist domain pattern weakness upSploit Ref: UPS-2011-0041  *Advisory Summ</description>
<pubDate>10 Feb  2012 03:00:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84985</link>
</item><item>
<title>Dolibarr CMS v3.2.0 Alpha - SQL Injection Vulnerabilities</title>
<description>Title: ====== Dolibarr CMS v3.2.0 Alpha - SQL Injection Vulnerabilities  Date: ===== 2012-02-09  References: =========== http://www.vulnerability-la</description>
<pubDate>10 Feb  2012 02:54:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84982</link>
</item><item>
<title>OnxShop CMS v1.5.0 - Multiple Web Vulnerabilities</title>
<description>Title: ====== OnxShop CMS v1.5.0 - Multiple Web Vulnerabilities  Date: ===== 2012-02-08  References: =========== http://www.vulnerability-lab.com/ge</description>
<pubDate>10 Feb  2012 02:53:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84981</link>
</item><item>
<title>Dolibarr CMS v3.2.0 Alpha - File Include Vulnerabilities</title>
<description>Title: ====== Dolibarr CMS v3.2.0 Alpha - File Include Vulnerabilities  Date: ===== 2012-02-07  References: =========== http://www.vulnerability-lab</description>
<pubDate>10 Feb  2012 02:51:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84980</link>
</item><item>
<title>CVE-2012-1037: GLPI &amp;lt;= 0.80.61 LFI/RFI</title>
<description>CVE-2012-1037: GLPI &amp;lt;= 0.80.61 LFI/RFI Severity: Important Vendor: GLPI - http://www.glpi-project.org Versions Affected ================= All vers</description>
<pubDate>10 Feb  2012 02:40:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84979</link>
</item><item>
<title>Celebrate with PenTest Magazine</title>
<description>Celebrate with PenTest Magazine To celebrate the transformation of PenTest StarterKit edition into Auditing &amp;amp; Standards PenTest, we&amp;#039;ve decided to gi</description>
<pubDate>10 Feb  2012 02:32:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84977</link>
</item><item>
<title>Linksys Routers still Vulnerable to Wps vulnerability.</title>
<description>Don&amp;#039;t buy Linksys Routers they are vulnerable to Wifi unProtected Setup Pin registrar Brute force attack. No patch or workaround exist at the making o</description>
<pubDate>09 Feb  2012 23:40:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84976</link>
</item><item>
<title>What&amp;#039;s up with the ImmunityInc forums?</title>
<description>Hey, anyone know why it&amp;#039;s taking so long for the ImmunityInc forums to come back up? It&amp;#039;s been weeks, man. __________________________________________</description>
<pubDate>09 Feb  2012 15:45:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84974</link>
</item><item>
<title>eFront Community++ v3.6.10 - Multiple Web Vulnerabilities</title>
<description>Title: ====== eFront Community++ v3.6.10 - Multiple Web Vulnerabilities  Date: ===== 2012-02-09  References: =========== http://www.vulnerability-la</description>
<pubDate>09 Feb  2012 10:01:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84973</link>
</item><item>
<title>[SECURITY] CVE-2011-4367 Apache MyFaces information disclosure vulnerability</title>
<description>-------------------------------------------------------------------------------------------------- CVE-2011-4367: Apache MyFaces information disclosu</description>
<pubDate>09 Feb  2012 07:54:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84972</link>
</item><item>
<title>List Charter</title>
<description>[Full-Disclosure] Mailing List Charter John Cartwright &amp;lt;johnc@grok.org.uk&amp;gt;  - Introduction &amp;amp; Purpose - This document serves as a charter for the [F</description>
<pubDate>09 Feb  2012 07:43:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84971</link>
</item>
</channel>
</rss>

