.:[ packet storm ]:.
                               
notoriously trustworthy
notoriously trustworthy

 Section:  .. / Last 100 Files /

 ///  File Name:cisco-sa-20080514-cup.txt
Description:
Cisco Security Advisory - Administrators of systems running all Cisco Unified Presence versions can determine the software version by viewing the main page of the Cisco Unified Presence Administration interface. The software version can be determined by running the command show version active via the Command Line Interface (CLI).
Homepage:http://www.cisco.com/
File Size:11779
Related CVE(s):CVE-2008-1740, CVE-2008-1741
Last Modified:May 15 04:28:20 2008
MD5 Checksum:fddfe8a3e45e0c202a50e5bc67fa484a

 ///  File Name:cisco-sa-20080514-cucmdos.txt
Description:
Cisco Security Advisory - Cisco Unified Communications Manager, formerly Cisco CallManager, contains multiple denial of service (DoS) vulnerabilities that may cause an interruption in voice services, if exploited. These vulnerabilities were discovered internally by Cisco.
Homepage:http://www.cisco.com/
File Size:23251
Related CVE(s):CVE-2008-1742, CVE-2008-1743, CVE-2008-1744, CVE-2008-1745, CVE-2008-1747, CVE-2008-1748, CVE-2008-1746
Last Modified:May 15 04:27:01 2008
MD5 Checksum:f01d649c7340d9b0d53c17cf1ce68606

 ///  File Name:cisco-sa-20080514-csm.txt
Description:
Cisco Security Advisory - The Cisco Content Switching Module (CSM) and Cisco Content Switching Module with SSL (CSM-S) contain a memory leak vulnerability that can result in a denial of service condition. The vulnerability exists when the CSM or CSM-S is configured for layer 7 load balancing. An attacker can trigger this vulnerability when the CSM or CSM-S processes TCP segments with a specific combination of TCP flags while servers behind the CSM/CSM-S are overloaded and/or fail to accept a TCP connection.
Homepage:http://www.cisco.com/
File Size:17388
Related CVE(s):CVE-2008-1749
Last Modified:May 15 04:25:13 2008
MD5 Checksum:0a7dfcd9f771e114ed6eafdd02388931

 ///  File Name:debian-sploit.txt
Description:
A nice walk through discussing step by step how to brute force ssh logins using the recent Debian OpenSSL random number generator vulnerability.
Author:Markus Mueller
File Size:1649
Last Modified:May 15 04:21:12 2008
MD5 Checksum:bc660b433dce3c75055028112f9966d3

 ///  File Name:EC2ND-2008-CFP.txt
Description:
Call For Papers for EC2ND. The fourth annual EC2ND conference will take place on December 11th and 12th 2008 in the Faculty of Engineering and Computing at Dublin City University.
Homepage:http://2008.ec2nd.org/
File Size:4073
Last Modified:May 15 04:19:00 2008
MD5 Checksum:25512bf60111f41dda218b3da90bc361

 ///  File Name:sqlfuzzer.py.txt
Description:
SQL Injector version 1.0 is a fuzzing utility written in Python.
Author:Beenu Arora
File Size:775
Last Modified:May 15 04:17:36 2008
MD5 Checksum:30658df42570e5cc8bf5a21363643df6

 ///  File Name:xsschecker.py.txt
Description:
Cross site scripting fuzzing utility written in Python.
Author:Beenu Arora
File Size:1945
Last Modified:May 15 04:16:34 2008
MD5 Checksum:87e7d424c10d56a7fc8c08dc5f96dc2a

 ///  File Name:msie-crosszone.txt
Description:
Microsoft Internet Explorer is prone to a cross-zone scripting vulnerability in its Print Table of Links feature.
Author:Aviv Raff
Homepage:http://aviv.raffon.net/
File Size:2188
Last Modified:May 15 04:14:42 2008
MD5 Checksum:ac941e58ffb4c9380b7ee22bd963676f

 ///  File Name:idautomation-activex.txt
Description:
The IDAutomation Bar Code ActiveX controller suffers from multiple vulnerabilities.
Author:shinnai
Homepage:http://shinnai.altervista.org/
File Size:3110
Last Modified:May 15 04:11:59 2008
MD5 Checksum:bd0a4833bf16133cc511ff0451fd6589

 ///  File Name:AD20080514.txt
Description:
The Microsoft Malware Protection Engine is susceptible to two denial of service vulnerabilities.
Author:Sowhat
Homepage:http://www.nevisnetworks.com/
File Size:2282
Related CVE(s):CVE-2008-1437, CVE-2008-1438
Last Modified:May 15 03:54:53 2008
MD5 Checksum:349d87c5c46ed91f4800ece0f2e55999

 ///  File Name:win32-generator.txt
Description:
win32 Download and Execute shellcode generator (browsers edition).
Author:YAG KOHHA
File Size:2830
Last Modified:May 15 03:52:57 2008
MD5 Checksum:3f071fcc1f92a0892c3107f22313a641

 ///  File Name:dsa-1577-1.txt
Description:
Debian Security Advisory 1577-1 - Stephen Gran and Mark Hymers discovered that some scripts run by GForge, a collaborative development tool, open files in write mode in a potentially insecure manner. This may be exploited to overwrite arbitrary files on the local system.
Homepage:http://www.debian.org/security
File Size:5237
Related CVE(s):CVE-2008-0167
Last Modified:May 15 03:51:39 2008
MD5 Checksum:81f578fa45368e855560e91c2dd60d4e

 ///  File Name:dsa-1576-1.txt
Description:
Debian Security Advisory 1576-1 - The recently announced vulnerability in Debian's openssl package (DSA-1571-1, CVE-2008-0166) indirectly affects OpenSSH. As a result, all user and host keys generated using broken versions of the openssl package must be considered untrustworthy, even after the openssl update has been applied.
Homepage:http://www.debian.org/security
File Size:15197
Related CVE(s):CVE-2008-0166
Last Modified:May 15 03:50:46 2008
MD5 Checksum:a79fd4e6e656f73f69d8c73cf16f3723

 ///  File Name:glsa-200805-16.txt
Description:
Gentoo Linux Security Advisory GLSA 200805-16 - Multiple vulnerabilities have been reported in OpenOffice.org, possibly allowing for user-assisted execution of arbitrary code. Versions less than 2.4.0 are affected.
Homepage:http://security.gentoo.org
File Size:4479
Related CVE(s):CVE-2007-4770, CVE-2007-4771, CVE-2007-5745, CVE-2007-5746, CVE-2007-5747, CVE-2008-0320
Last Modified:May 15 03:50:03 2008
MD5 Checksum:c5ac7f6c3461ccefbfb9d489ee5db5b6

 ///  File Name:glsa-200805-15.txt
Description:
Gentoo Linux Security Advisory GLSA 200805-15 - Kentaro Oda reported an infinite loop in the file field.c when parsing an MP3 file with an ID3_FIELD_TYPE_STRINGLIST field that ends in '\0'. Versions less than 0.15.1b-r2 are affected.
Homepage:http://security.gentoo.org
File Size:2415
Related CVE(s):CVE-2008-2109
Last Modified:May 15 03:49:12 2008
MD5 Checksum:a924bb8eeda8ff0dbe39e3cd31978d5e

 ///  File Name:USN-612-6.txt
Description:
Ubuntu Security Notice 612-6 - USN-612-3 addressed a weakness in OpenSSL certificate and keys generation in OpenVPN by adding checks for vulnerable certificates and keys to OpenVPN. A regression was introduced in OpenVPN when using TLS and multi-client/server which caused OpenVPN to not start when using valid SSL certificates. It was also found that openssl-vulnkey from openssl-blacklist would fail when stderr was not available. This caused OpenVPN to fail to start when used with applications such as NetworkManager. A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH, OpenVPN and SSL certificates. This vulnerability only affects operating systems which (like Ubuntu) are based on Debian. However, other systems can be indirectly affected if weak keys are imported into them.
Homepage:http://security.ubuntu.com/
File Size:8081
Related CVE(s):CVE-2008-0166
Last Modified:May 15 03:47:36 2008
MD5 Checksum:1b121b32f5b219bf781da551ba98e314

 ///  File Name:USN-612-5.txt
Description:
Ubuntu Security Notice 612-5 - Matt Zimmerman discovered that entries in ~/.ssh/authorized_keys with options (such as "no-port-forwarding" or forced commands) were ignored by the new ssh-vulnkey tool introduced in OpenSSH (see USN-612-2). This could cause some compromised keys not to be listed in ssh-vulnkey's output. A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH, OpenVPN and SSL certificates. This vulnerability only affects operating systems which (like Ubuntu) are based on Debian. However, other systems can be indirectly affected if weak keys are imported into them.
Homepage:http://security.ubuntu.com/
File Size:16139
Related CVE(s):CVE-2008-0166
Last Modified:May 15 03:46:36 2008
MD5 Checksum:12c2407158560e7b8cd3525552c71aec

 ///  File Name:USN-612-4.txt
Description:
Ubuntu Security Notice 612-4 - USN-612-1 fixed vulnerabilities in openssl. This update provides the corresponding updates for ssl-cert -- potentially compromised snake-oil SSL certificates will be regenerated. A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH, OpenVPN and SSL certificates. This vulnerability only affects operating systems which (like Ubuntu) are based on Debian. However, other systems can be indirectly affected if weak keys are imported into them.
Homepage:http://security.ubuntu.com/
File Size:4207
Related CVE(s):CVE-2008-0166
Last Modified:May 15 03:45:47 2008
MD5 Checksum:fbb384be18c0b97874a042383317e896

 ///  File Name:rgboard-rfixss.txt
Description:
Rgboard versions 3.0.12 and below suffer from remote file inclusion and cross site scripting vulnerabilities.
Author:e.wiZz!
File Size:1500
Last Modified:May 15 03:42:51 2008
MD5 Checksum:f28af15ada7cfa6dd19a7611e4129ee5

 ///  File Name:hordeturba-xss.txt
Description:
Horde and Turbo Contact Manager suffers from multiple cross site scripting vulnerabilities.
Author:Ivan Sanchez
Homepage:http://www.nullcode.com.ar/
File Size:1639
Last Modified:May 15 03:41:40 2008
MD5 Checksum:6eadbbe84f8cd8b298ef48dbfbf36532

 ///  File Name:feedback-sql.txt
Description:
Feedback and Rating Script version 1.0 suffers from a SQL injection vulnerability in detail.php.
Author:t0pp8uzz
File Size:1326
Last Modified:May 15 03:40:08 2008
MD5 Checksum:21f464b4844474eebe7e334da0b7af4b

 ///  File Name:freelance-sql.txt
Description:
Freelance Auction Script version 1.0 suffers from a SQL injection vulnerability in browseproject.php.
Author:t0pp8uzz
File Size:1308
Last Modified:May 15 03:39:04 2008
MD5 Checksum:4688f6564b2442e608a0e833731029b3

 ///  File Name:internetphotoshow-cookie.txt
Description:
Internet Photoshow Special Edition suffers from an insecure cooking handling vulnerability that allows for arbitrary administrative access.
Author:t0pp8uzz
File Size:1430
Last Modified:May 15 03:36:26 2008
MD5 Checksum:9c65fb8fb64e4c7c2e5da154b8c156a5

 ///  File Name:activekb-cookie.txt
Description:
ActiveKB versions 1.5 and below suffer from an insecure cooking handling vulnerability that allows for arbitrary administrative access.
Author:t0pp8uzz
File Size:1427
Last Modified:May 15 03:35:30 2008
MD5 Checksum:2e810d72d6b158782557b88d1ffe1399

 ///  File Name:asgastracker-cookie.txt
Description:
AS-GasTracker version 1.0.0 suffers from an insecure cookie handling vulnerability.
Author:t0pp8uzz
File Size:1385
Last Modified:May 15 03:34:16 2008
MD5 Checksum:94b5d6605cfcdc708076e832bbe4154d

 ///  File Name:lanaicms-upload.txt
Description:
La-Nai CMS versions 1.2.16 and below arbitrary file upload exploit.
Author:EgiX
File Size:4926
Last Modified:May 15 01:43:55 2008
MD5 Checksum:79d8311c28ed23e1e4ac9a1205284f7e

 ///  File Name:xsrf-paper.txt
Description:
Whitepaper regarding cross site request forgery attacks. Written in Spanish.
Author:Tec-n0x
Homepage:http://www.editcodex.net/
File Size:10741
Last Modified:May 15 01:31:09 2008
MD5 Checksum:8c450745dbb41e254f73345fc61d0051

 ///  File Name:officepub-corrupt.txt
Description:
A memory corruption vulnerability exists in Microsoft Office Publisher when it is parsing a PUB file. An attacker who successfully exploits this vulnerability can execute arbitrary code on the affected system.
Author:cocoruder
Homepage:http://ruder.cdut.net/
File Size:1355
Related CVE(s):CVE-2008-0119
Last Modified:May 15 01:13:56 2008
MD5 Checksum:c3c39fb97be35f9f59393df7386d6245

 ///  File Name:kostenloses-rfi.txt
Description:
Kostenloses Linkmanagementscript suffers from a remote file inclusion vulnerability.
Author:HaCkeR_EgY
Homepage:http://www.PaL-HaCker.com/
File Size:1354
Last Modified:May 15 01:12:06 2008
MD5 Checksum:fae2a293f77133d45a58586e661fd1ff

 ///  File Name:emo-sql.txt
Description:
EMO Realty Manager suffers from a SQL injection vulnerability in news.php.
Author:HaCkeR_EgY
Homepage:http://www.PaL-HaCker.com/
File Size:1599
Last Modified:May 15 01:10:54 2008
MD5 Checksum:913ecff89e5dda1d8edc211a9ecdb13a

 ///  File Name:restate-sql.txt
Description:
The Real Estate Script suffers from a SQL injection vulnerability in dpage.php.
Author:HaCkeR_EgY
Homepage:http://www.PaL-HaCker.com/
File Size:1219
Last Modified:May 15 01:09:49 2008
MD5 Checksum:3d3e7b19028a556a2e886d848b15a9a1

 ///  File Name:linkspile-sql.txt
Description:
Linkspile suffers from a remote SQL injection vulnerability in link.php.
Author:HaCkeR_EgY
Homepage:http://www.PaL-HaCker.com/
File Size:1497
Last Modified:May 15 01:06:08 2008
MD5 Checksum:24c9cae18ccfe87aa50764ad041ad946

 ///  File Name:glsa-200805-14.txt
Description:
Gentoo Linux Security Advisory GLSA 200805-14 - Alfredo Ortega (Core Security Technologies) reported a boundary error within the Read32s_64() function when processing CDF files. Versions less than 3.2.1 are affected.
Homepage:http://security.gentoo.org
File Size:3057
Related CVE(s):CVE-2008-2080
Last Modified:May 13 17:42:27 2008
MD5 Checksum:fb60597d6c2b729facceb809547eadbd

 ///  File Name:ciscobbsm-xss.txt
Description:
Cisco BBSM Captive Portal suffers from a cross site scripting vulnerability.
Author:Brad Antoniewicz
File Size:1069
Related CVE(s):CVE-2008-2165
Last Modified:May 13 17:42:20 2008
MD5 Checksum:2ca2083dc04f5038f679e2cf05a831d8

 ///  File Name:metoforum-sql.txt
Description:
Meto Forum version 1.1 suffers from multiple remote SQL injection vulnerabilities.
Author:U238
Homepage:http://noexec.blogspot.com/
File Size:1838
Last Modified:May 13 15:46:02 2008
MD5 Checksum:02d328a7a5f0480e1032bb421629f838

 ///  File Name:calogic-sql.txt
Description:
CaLogic Calendars version 1.2.2 suffers from a remote SQL injection vulnerability.
Author:His0k4
File Size:937
Last Modified:May 13 15:44:30 2008
MD5 Checksum:5fdfcd69e2d4b0ce12411c5ea8574b5a

 ///  File Name:wgcc-sql.txt
Description:
Web Group Communication Center versions 1.0.3 PreRelease #1 and below suffer from cross site scripting and SQL injection vulnerabilities.
Author:myvx
File Size:1636
Last Modified:May 13 15:43:17 2008
MD5 Checksum:0cb95f9f4ef457ba2b4bacab721211ed

 ///  File Name:TA08-134A.txt
Description:
Technical Cyber Security Alert TA08-134A - Microsoft has released updates to address vulnerabilities that affect Microsoft Windows, Office, Jet Database Engine, Windows Live OneCare, Antigen, Windows Defender, and Forefront Security as part of the Microsoft Security Bulletin Summary for May 2008. The most severe vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code. For more information, see the US-CERT Vulnerability Notes Database.
Homepage:http://www.us-cert.gov/
File Size:3749
Last Modified:May 13 15:41:07 2008
MD5 Checksum:1b674f3df657c92d13731b2e7392126e

 ///  File Name:05.13.08-1.txt
Description:
iDefense Security Advisory 05.13.08 - Remote exploitation of a memory corruption vulnerability in Microsoft Corp.'s Word could allow attackers to execute arbitrary code with the privileges of the logged in user. This vulnerability exists in the way Word handles CSS rules in an HTML document. When the number of CSS selectors is above some specific amount, an unspecified object will be corrupted causing Word to access a memory region that has already been freed. iDefense has confirmed fully patched Microsoft Word 2003 SP2, Microsoft Word XP SP3, Microsoft Word 2000 SP3 are vulnerable. Microsoft Word 2003 SP3 and Microsoft Word 2007 do not appear to be affected. Microsoft reports that all supported versions of Word, Word Viewer, and Outlook 2007 are vulnerable.
Author:Jun Mao
Homepage:http://www.idefense.com/
File Size:4164
Related CVE(s):CVE-2008-1434
Last Modified:May 13 15:39:58 2008
MD5 Checksum:fd7486dbe9fda5cc2883cbfa6ad3cc65

 ///  File Name:ZDI-08-023.txt
Description:
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page, open a malicious email, or open a malicious file. The specific flaw exists when parsing malformed RTF documents. When processing a combination of RTF tags a heap overflow occurs. Successful exploitation can lead to remote compromise of a system under the credentials of the currently logged in user.
Author:wushi
Homepage:http://www.zerodayinitiative.com/
File Size:3266
Related CVE(s):CVE-2008-1091
Last Modified:May 13 15:38:28 2008
MD5 Checksum:3a4c70d8165cb815e52e832667c68280

 ///  File Name:USN-612-3.txt
Description:
Ubuntu Security Notice 612-3 - A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of shared encryption keys and SSL/TLS certificates in OpenVPN. This vulnerability only affects operating systems which (like Ubuntu) are based on Debian. However, other systems can be indirectly affected if weak keys are imported into them.
Homepage:http://security.ubuntu.com/
File Size:7395
Related CVE(s):CVE-2008-0166
Last Modified:May 13 15:37:41 2008
MD5 Checksum:fbc9eb044bb2cb99c735320b168eeffe

 ///  File Name:TPTI-08-04.txt
Description:
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office. Exploitation requires that the target opens an Office file that contains malicious Jet DB Engine objects. The specific flaw exists within the parsing of a column structure. The DWORD value from the structure that specifies the column count is trusted. If this value is changed, an inline memcpy to the stack can overflow while reading a column name. Typically Jet DB structures are used within MDB files which are considered unsafe. However, it is possible to embed such files within a trusted format, such as an Office Document (.doc). This issue allows for remote code execution under the context of the currently logged in user.
Author:Aaron Portnoy
Homepage:http://www.tippingpoint.com/
File Size:1728
Related CVE(s):CVE-2007-6026
Last Modified:May 13 15:37:04 2008
MD5 Checksum:b0741f928fbcdfe0d4a4a46f4d209d1b

 ///  File Name:e107zogo-sql.txt
Description:
The e107 zogo-shop plugin version 1.16 Beta 13 suffers from a SQL injection vulnerability.
Author:Cr@zy_King
File Size:697
Last Modified:May 13 11:16:49 2008
MD5 Checksum:322ae457f7fde32d03fcfd45c84f7249

 ///  File Name:aih-sql.txt
Description:
Advanced Image Hosting version 2.1 remote SQL injection exploit.
Author:Stack-Terrorist
Homepage:http://v4-team.com/
File Size:4439
Last Modified:May 13 11:16:04 2008
MD5 Checksum:2fe3fbda650d07c9ad79a11a1e801859

 ///  File Name:e107blog-blindsql.txt
Description:
The e107 BLOG engine plugin version 2.2 suffers from a blind SQL injection vulnerability.
Author:Saime
File Size:1725
Last Modified:May 13 11:15:16 2008
MD5 Checksum:b05712a59df33220ff5ee6e3f89dc461

 ///  File Name:ajhyip-sql.txt
Description:
AJ HYIP ACME suffers from a remote SQL injection vulnerability in topic_detail.php.
Author:cyb3r-1st
File Size:2405
Last Modified:May 13 11:14:16 2008
MD5 Checksum:458ef9a0a2a7bbf650eacfbbef348da7

 ///  File Name:eqdkp-bypass.txt
Description:
EQDKP version 1.3.2f authentication bypass proof of concept exploit.
Author:vortfu
File Size:1545
Last Modified:May 13 11:13:10 2008
MD5 Checksum:fe7b232aa60e6af31f20bdfe14a8ecdf

 ///  File Name:USN-612-2.txt
Description:
Ubuntu Security Notice 612-2 - A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH. This vulnerability only affects operating systems which (like Ubuntu) are based on Debian. However, other systems can be indirectly affected if weak keys are imported into them. We consider this an extremely serious vulnerability, and urge all users to act immediately to secure their systems.
Homepage:http://security.ubuntu.com/
File Size:19137
Related CVE(s):CVE-2008-0166
Last Modified:May 13 11:11:26 2008
MD5 Checksum:08b7a276f7d12fdf3ce857fbdc45404e

 ///  File Name:dsa-1571-1.txt
Description:
Debian Security Advisory 1571-1 - Luciano Bello discovered that the random number generator in Debian's openssl package is predictable. This is caused by an incorrect Debian-specific change to the openssl package. As a result, cryptographic key material may be guessable. This is a Debian-specific vulnerability which does not affect other operating systems which are not based on Debian. However, other systems can be indirectly affected if weak keys are imported into them. It is strongly recommended that all cryptographic key material which has been generated by OpenSSL versions starting with 0.9.8c-1 on Debian systems is recreated from scratch. Furthermore, all DSA keys ever used on affected Debian systems for signing or authentication purposes should be considered compromised; the Digital Signature Algorithm relies on a secret random value used during signature generation.
Homepage:http://www.debian.org/security
File Size:14589
Related CVE(s):CVE-2008-0166
Last Modified:May 13 11:10:24 2008
MD5 Checksum:3519042f913d5ce265ca79a43a1d7f92

 ///  File Name:articlelive-xss.txt
Description:
Interspire ArticleLive NX is vulnerable to a cross site scripting vulnerability.
Author:SkyOut
Homepage:http://wired-security.net/
File Size:2778
Last Modified:May 13 11:07:49 2008
MD5 Checksum:9fa199b5cd48bc7fdf7cc96985762f98

 ///  File Name:major_rls52.txt
Description:
Actual Analyzer Server versions 8.37 and below, Gold versions 7.74 and below, Pro versions 6.95 and below, and Lite versions 2.78 and below all suffer from a cross site scripting vulnerability.
Author:David "Aesthetico" Vieira-Kurz
Homepage:http://www.majorsecurity.de
File Size:2066
Last Modified:May 13 11:05:32 2008
MD5 Checksum:19ba93db8b59387052a87f09e89fb657

 ///  File Name:dsa-1575-1.txt
Description:
Debian Security Advisory 1575-1 - A vulnerability has been discovered in the Linux kernel that may lead to a denial of service. Alexander Viro discovered a race condition in the fcntl code that may permit local users on multi-processor systems to execute parallel code paths that are otherwise prohibited and gain re-ordered access to the descriptor table.
Homepage:http://www.debian.org/security
File Size:36131
Related CVE(s):CVE-2008-1669
Last Modified:May 13 11:04:01 2008
MD5 Checksum:a095807a32a3fc4ee13e1e39f557b145

 ///  File Name:omerta-xss.txt
Description:
Omerta versions 2.7c and 2.8 suffer from a cross site scripting vulnerability.
Author:David Sopas Ferreira
Homepage:http://www.davidsopas.com/
File Size:1059
Last Modified:May 13 11:03:06 2008
MD5 Checksum:5dce48eef901007dbfddfcfd20143a48

 ///  File Name:USN-612-1.txt
Description:
Ubuntu Security Notice 612-1 - A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH, OpenVPN and SSL certificates. This vulnerability only affects operating systems which (like Ubuntu) are based on Debian. However, other systems can be indirectly affected if weak keys are imported into them. We consider this an extremely serious vulnerability, and urge all users to act immediately to secure their systems.
Homepage:http://security.ubuntu.com/
File Size:15288
Related CVE(s):CVE-2008-0166
Last Modified:May 13 11:01:40 2008
MD5 Checksum:4798966590d2c04dbeae52eda8904882

 ///  File Name:megafile-sql.txt
Description:
Mega File Hosting Script version 1.2 suffers from a remote SQL injection vulnerability.
Author:TurkishWarriorr
Homepage:http://1923turk.org/
File Size:861
Last Modified:May 12 18:44:39 2008
MD5 Checksum:7bfb2b315e9d54d4629ad395fd196d20

 ///  File Name:phpclassifieds-sql.txt
Description:
PHP Classifieds Script versions 05122008 and below suffer from remote SQL injection vulnerabilities.
Author:cyb3r-1st
File Size:2716
Last Modified:May 12 18:43:45 2008
MD5 Checksum:7227def1561146867845e591a1392736

 ///  File Name:cmsmadesimple-upload.txt
Description:
CMS Made Simple versions 1.2.4 and below arbitrary file upload exploit.
Author:EgiX
File Size:5466
Last Modified:May 12 18:41:34 2008
MD5 Checksum:f7c929656a32839f6177fcc805b36cb4

 ///  File Name:battlenet15x-sql.txt
Description:
Battle.net Clan Script versions 1.5.x and below remote SQL injection exploit.
Author:Stack-Terrorist
Homepage:http://v4-team.com/
Related Exploit:battlenet-sql.txt
File Size:6025
Last Modified:May 12 18:40:23 2008
MD5 Checksum:b3389cf8628c8c2e58144086ac8ba012

 ///  File Name:05.12.08-1.txt
Description:
iDefense Security Advisory 05.12.08 - Local exploitation of an input validation vulnerability within version 5.1.2600.2180 of i2omgmt.sys, as included with Microsoft Corp's Windows XP operating system, could allow an attacker to execute arbitrary code in the context of the kernel. iDefense has confirmed the existence of this vulnerability in i2omgmt.sys version 5.1.2600.2180 as installed on some Windows XP SP2 systems. All other Windows releases with this driver, including previous versions, are suspected to be vulnerable.
Author:Ruben Santamarta
Homepage:http://www.idefense.com/
File Size:4025
Related CVE(s):CVE-2008-0322
Last Modified:May 12 18:28:36 2008
MD5 Checksum:9a855b4f3e57f9d46308c1a0f2293ded

 ///  File Name:glsa-200805-13.txt
Description:
Gentoo Linux Security Advisory GLSA 200805-13 - Multiple issues were found in the teTeX 2 codebase that PTeX builds upon (GLSA 200709-17, GLSA 200711-26). PTeX also includes vulnerable code from the GD library (GLSA 200708-05), from Xpdf (GLSA 200709-12, GLSA 200711-22) and from T1Lib (GLSA 200710-12). Versions less than 3.1.10_p20071203 are affected.
Homepage:http://security.gentoo.org
File Size:3730
Last Modified:May 12 18:27:15 2008
MD5 Checksum:15830348aa8fe782c793f470674bbf22

 ///  File Name:glsa-200805-12.txt
Description:
Gentoo Linux Security Advisory GLSA 200805-12 - Stefan Cornelius (Secunia Research) reported a boundary error within the imb_loadhdr() function in in the file source/blender/imbuf/intern/radiance_hdr.c when processing RGBE images (CVE-2008-1102). Multiple vulnerabilities involving insecure usage of temporary files have also been reported (CVE-2008-1103). Versions less than 2.43-r2 are affected.
Homepage:http://security.gentoo.org
File Size:3313
Related CVE(s):CVE-2008-1102, CVE-2008-1103
Last Modified:May 12 18:26:58 2008
MD5 Checksum:448f5fac796df4e8c92d9693409be43e

 ///  File Name:glsa-200805-11.txt
Description:
Gentoo Linux Security Advisory GLSA 200805-11 - Chicken includes a copy of PCRE which is vulnerable to multiple buffer overflows and memory corruption vulnerabilities (GLSA 200711-30). Versions less than 3.1.0 are affected.
Homepage:http://security.gentoo.org
File Size:3061
Last Modified:May 12 18:26:45 2008
MD5 Checksum:d9d22fd1973d39963760ae4fd6fe5097

 ///  File Name:SSRT071403.txt
Description:
HP Security Bulletin - A potential security vulnerability has been identified with HP-UX running ftp. The vulnerability could be exploited remotely to create a Denial of Service (DoS). The Denial of Service (DoS) affects the ftp server application only.
Homepage:http://www.hp.com/
File Size:7219
Related CVE(s):CVE-2008-0713
Last Modified:May 12 16:04:01 2008
MD5 Checksum:775ab8659a58b7670f90f607b3a6d47e

 ///  File Name:ibdmicro-sql.txt
Description:
IBD Micro CMS version 3.5 suffers from a SQL injection vulnerability that allows for login bypass.
Author:SkyOut
Homepage:http://wired-security.net/
File Size:4656
Last Modified:May 12 16:03:24 2008
MD5 Checksum:81a3d19c1f162cf34b0aa3eaebddf61d

 ///  File Name:dsa-1574-1.txt
Description:
Debian Security Advisory 1574-1 - Several remote vulnerabilities have been discovered in the Icedove mail client, an unbranded version of the Thunderbird client. "moz_bug_r_a4" discovered that variants of CVE-2007-3738 and CVE-2007-5338 allow the execution of arbitrary code through XPCNativeWrapper. "moz_bug_r_a4" discovered that insecure handling of event handlers could lead to cross-site scripting. Boris Zbarsky, Johnny Stenback, and "moz_bug_r_a4" discovered that incorrect principal handling can lead to cross-site scripting and the execution of arbitrary code. Tom Ferris, Seth Spitzer, Martin Wargers, John Daggett and Mats Palmgren discovered crashes in the layout engine, which might allow the execution of arbitrary code. "georgi", "tgirmann" and Igor Bukanov discovered crashes in the Javascript engine, which might allow the execution of arbitrary code.
Homepage:http://www.debian.org/security
File Size:16567
Related CVE(s):CVE-2008-1233, CVE-2008-1234, CVE-2008-1235, CVE-2008-1236, CVE-2008-1237
Last Modified:May 12 15:57:20 2008
MD5 Checksum:88c086a46a80505846192144f8ae384e

 ///  File Name:rdesktoppdu-overflow.txt
Description:
rdesktop version 1.5.0 BSS overflow vulnerability proof of concept exploit that makes use of process_redirect_pdu().
Author:Guido Landi
Related File:05.07.08-2.txt
File Size:2739
Related CVE(s):CVE-2008-1802
Last Modified:May 12 15:53:11 2008
MD5 Checksum:4dd0d30ddab49e31e492dd01e046c7fb

 ///  File Name:bigace-rfi.txt
Description:
BIGACE version 2.4 suffers from multiple remote file inclusion vulnerabilities.
Author:BiNgZa
File Size:2924
Last Modified:May 12 15:49:59 2008
MD5 Checksum:3cf0449edfa61d072ac4cf33885c2cb1

 ///  File Name:nipper-0.11.7.tgz
Description:
nipper is a Network Infrastructure Configuration Parser. nipper takes a network infrastructure device configuration, processes the file and details security-related issues with the configuration together with detailed recommendations. nipper was previous known as CiscoParse. nipper currently supports Cisco switches (IOS), Cisco Routers (IOS), Cisco Firewalls (PIX/ASA/FWSM) and Juniper NetScreen (ScreenOS). Output is in HTML, Latex, XML and Text. Encrypted passwords can be output to a John-the-Ripper file for strength testing.
Author:Ian Ventura-Whiting
Homepage:http://nipper.titania.co.uk/
Changes:The release adds support for the CSV output of a devices network filtering rules and optional output of CheckPoint rule comments. Support for Nokia IP and Accelar devices is also enhanced. The update includes other minor updates that are detailed in the Changelog.
File Size:273091
Last Modified:May 12 10:53:09 2008
MD5 Checksum:cc6e500d2cefef2322ad8b4a1102aae1

 ///  File Name:nipper-0.11.7.zip
Description:
nipper is a Network Infrastructure Configuration Parser. nipper takes a network infrastructure device configuration, processes the file and details security-related issues with the configuration together with detailed recommendations. nipper was previous known as CiscoParse. nipper currently supports Cisco switches (IOS), Cisco Routers (IOS), Cisco Firewalls (PIX/ASA/FWSM) and Juniper NetScreen (ScreenOS). Output is in HTML, Latex, XML and Text. Encrypted passwords can be output to a John-the-Ripper file for strength testing. This is the Windows version.
Author:Ian Ventura-Whiting
Homepage:http://nipper.titania.co.uk/
Changes:The release adds support for the CSV output of a devices network filtering rules and optional output of CheckPoint rule comments. Support for Nokia IP and Accelar devices is also enhanced. The update includes other minor updates that are detailed in the Changelog.
File Size:662600
Last Modified:May 12 10:51:38 2008
MD5 Checksum:e9a5c045af4cfb8381c08ab8e4c3bec7

 ///  File Name:zeuscart-sql.txt
Description:
ZeusCart versions 2.0 and below suffers from a remote SQL injection vulnerability in category_list.php.
Author:t0pp8uzz
File Size:1227
Last Modified:May 12 10:47:59 2008
MD5 Checksum:9f56ae8de6f905649eebecbc325a0919

 ///  File Name:ajdating-sql.txt
Description:
AJ Dating version 1.0 suffers from a remote SQL injection vulnerability in view_profile.php.
Author:t0pp8uzz
File Size:1407
Last Modified:May 12 10:47:16 2008
MD5 Checksum:6ff250e2852d1741513ab401f4d86cac

 ///  File Name:ajclassifieds-sql.txt
Description:
AJ Classifieds 2008 suffers from a remote SQL injection vulnerability in index.php.
Author:t0pp8uzz
File Size:1562
Last Modified:May 12 10:46:18 2008
MD5 Checksum:269788aea5798db728097ce1c7ab5c03

 ///  File Name:ajauction-sql.txt
Description:
AJ Auctions versions 6.2.1 and below suffer from a remote SQL injection vulnerability in classifide_ad.php.
Author:t0pp8uzz
File Size:1381
Last Modified:May 12 10:45:40 2008
MD5 Checksum:76e75e0aa524213c05795e87d51fc05c

 ///  File Name:ajarticle-sql.txt
Description:
AJ Article version 1.0 suffers from a remote SQL injection vulnerability in featured_article.php.
Author:t0pp8uzz
File Size:1352
Last Modified:May 12 10:44:47 2008
MD5 Checksum:15db8e649ef149755b65e4e47c37acd1

 ///  File Name:otherlogic-sql.txt
Description:
OtherLogic suffers from a SQL injection vulnerability in vocourse.php.
Author:Breeeeh
File Size:289
Last Modified:May 12 10:43:36 2008
MD5 Checksum:5d8065f2be3cb7b5b40884d3f2d1ac72

 ///  File Name:glsa-200805-10.txt
Description:
Gentoo Linux Security Advisory GLSA 200805-10 - It has been reported that Pngcrush includes a copy of libpng that is vulnerable to a memory corruption (GLSA 200804-15). Versions less than 1.6.4-r1 are affected.
Homepage:http://security.gentoo.org
File Size:3170
Related CVE(s):CVE-2008-1382
Last Modified:May 12 10:41:29 2008
MD5 Checksum:7cfec10bfa57130b88afb7bff74c84e3

 ///  File Name:dsa-1573-1.txt
Description:
Debian Security Advisory 1573-1 - Several remote vulnerabilities have been discovered in rdesktop, a Remote Desktop Protocol client. Remote exploitation of an integer underflow vulnerability allows attackers to execute arbitrary code with the privileges of the logged-in user. Remote exploitation of a BSS overflow vulnerability allows attackers to execute arbitrary code with the privileges of the logged-in user. Remote exploitation of an integer signedness vulnerability allows attackers to execute arbitrary code with the privileges of the logged-in user.
Homepage:http://www.debian.org/security
File Size:5587
Related CVE(s):CVE-2008-1801, CVE-2008-1802, CVE-2008-1803
Last Modified:May 12 10:41:01 2008
MD5 Checksum:ba15a8cc0a3d8d809028c215d0f8f9a2

 ///  File Name:dsa-1572-1.txt
Description:
Debian Security Advisory 1572-1 - Several vulnerabilities have been discovered in PHP, a server-side, HTML-embedded scripting language. The glob function allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an invalid value of the flags parameter. Integer overflow allows context-dependent attackers to cause a denial of service and possibly have other impact via a printf format parameter with a large width specifier. Stack-based buffer overflow in the FastCGI SAPI. The escapeshellcmd API function could be attacked via incomplete multibyte chars.
Homepage:http://www.debian.org/security
File Size:40512
Related CVE(s):CVE-2007-3806, CVE-2008-1384, CVE-2008-2050, CVE-2008-2051
Last Modified:May 12 10:39:51 2008
MD5 Checksum:65c9c530978f313191386160ca68b3a9

 ///  File Name:glsa-200805-09.txt
Description:
Gentoo Linux Security Advisory GLSA 200805-09 - It has been reported that the user form processing in the file userform.py does not properly manage users when using Access Control Lists or a non-empty superusers list. Versions less than 1.6.3 are affected.
Homepage:http://security.gentoo.org
File Size:2956
Related CVE(s):CVE-2008-1937
Last Modified:May 12 10:37:50 2008
MD5 Checksum:f5912af55302350b385b5dd9c8aea1a1

 ///  File Name:MDVSA-2008-100.txt
Description:
Mandriva Linux Security Advisory - A double free vulnerability in Perl 5.8.8 and earlier versions, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a crafted regular expression containing UTF8 characters.
Homepage:http://www.mandriva.com/security/
File Size:6987
Related CVE(s):CVE-2008-1927
Last Modified:May 12 10:37:41 2008
MD5 Checksum:513fa7b59cd18f23cdf5a4d38273458e

 ///  File Name:clanlite-sqlxss.txt
Description:
ClanLite version 2.x suffers from SQL injection and cross site scripting vulnerabilities.
Author:ZoRLu
Homepage:http://www.yildirimordulari.org/
File Size:2434
Last Modified:May 12 10:36:33 2008
MD5 Checksum:efca3ad0c4a676108c64cfbd5b33cab1

 ///  File Name:joomlaxsstream-sql.txt
Description:
Remote SQL injection exploit for the xsstream-dm module version 0.01b for Joomla.
Author:H-T Team
Homepage:http://no-hack.fr/
File Size:2452
Last Modified:May 12 10:35:24 2008
MD5 Checksum:7300f264123bbdbaa1bba29c0167eae5

 ///  File Name:joomladatso-blindsql.txt
Description:
Remote blind SQL injection exploit for the com_datsogallery module version 1.6 for Joomla.
Author:+toxa+
Homepage:http://antichat.ru/
File Size:2950
Last Modified:May 12 10:34:07 2008
MD5 Checksum:20c1e597e468c6c4b7e4de029dd4c7a0

 ///  File Name:ktools-sql.txt
Description:
Ktools PhotoStore versions 3.5.2 and below suffer from multiple remote SQL injection vulnerabilities.
Author:DNX
File Size:3165
Last Modified:May 12 10:32:39 2008
MD5 Checksum:e493a4c2e2d16399af14cbc21264bed5

 ///  File Name:phpblock85-rfi.txt
Description:
PHP Block version a8.5 suffers from multiple remote file inclusion vulnerabilities.
Author:CraCkEr
File Size:4804
Last Modified:May 12 10:10:53 2008
MD5 Checksum:e8c8a6373faf3e78bda48f06da3d9d1f

 ///  File Name:alm-sql.txt
Description:
Advanced Links Management version 1.52 suffers from a remote SQL injection vulnerability.
Author:His0k4
File Size:787
Last Modified:May 12 10:09:25 2008
MD5 Checksum:c278efde166d49766cb85c9dfdcf4447

 ///  File Name:hispah-sql.txt
Description:
HispaH Model Search suffers from a remote SQL injection vulnerability in cat.php.
Author:cyb3r-1st
File Size:963
Last Modified:May 9 20:06:40 2008
MD5 Checksum:56372410603357c087d00006cb931d71

 ///  File Name:sazcart-sql.txt
Description:
SazCart versions 1.5.1 and below remote SQL injection exploit.
Author:JosS
Homepage:http://www.spanish-hackers.com/
File Size:1305
Last Modified:May 9 20:05:44 2008
MD5 Checksum:4bd3e69d3bf9bc4006706b639fdfa953

 ///  File Name:admidio-disclose.txt
Description:
Admidio version 1.4.8 suffers from a remote file disclosure vulnerability.
Author:n3v3rh00d
Homepage:http://forum.antichat.ru/
File Size:1398
Last Modified:May 9 20:04:34 2008
MD5 Checksum:fb96b4a0cd332e49bb1509f593db6916

 ///  File Name:wpgallery-sql.txt
Description:
The WordPress Photo Gallery module suffers from a remote SQL injection vulnerability.
Author:THE_MILLER
File Size:405
Last Modified:May 9 13:59:35 2008
MD5 Checksum:6ad18afafb09a0396e624aa6cdc26680

 ///  File Name:glsa-200805-08.txt
Description:
Gentoo Linux Security Advisory GLSA 200805-08 - The namesx and uhnames modules do not properly validate network input, leading to a buffer overflow. Versions less than 1.1.19 are affected.
Homepage:http://security.gentoo.org
File Size:2399
Related CVE(s):CVE-2008-1925
Last Modified:May 9 13:53:32 2008
MD5 Checksum:cdb2393100a4faec5400559fd35ff0f8

 ///  File Name:glsa-200805-07.txt
Description:
Gentoo Linux Security Advisory GLSA 200805-07 - LTSP version 4.2, ships prebuilt copies of programs such as the Linux Kernel, the X.org X11 server (GLSA 200705-06, GLSA 200710-16, GLSA 200801-09), libpng (GLSA 200705-24, GLSA 200711-08), Freetype (GLSA 200705-02, GLSA 200705-22) and OpenSSL (GLSA 200710-06, GLSA 200710-30) which were subject to multiple security vulnerabilities since 2006. Please note that the given list of vulnerabilities might not be exhaustive. Versions less than 5.0 are affected.
Homepage:http://security.gentoo.org
File Size:4366
Last Modified:May 9 13:53:07 2008
MD5 Checksum:b99107d7cc4efe620d3b52050bad0f8f

 ///  File Name:glsa-200805-06.txt
Description:
Gentoo Linux Security Advisory GLSA 200805-06 - Viesturs reported that the default configuration for Gentoo's init script (/etc/conf.d/firebird) sets the ISC_PASSWORD environment variable when starting Firebird. It will be used when no password is supplied by a client connecting as the SYSDBA user. Versions less than 2.0.3.12981.0-r6 are affected.
Homepage: