Packet storm

Prenumerera på innehåll Packet Storm
Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers
Uppdaterad: 6 tim 17 min gammalt

ManageEngine ADManager Plus 5.2 Cross Site Scripting

11 tim 1 min sedan
ManageEngine ADManager Plus version 5.2 suffers from multiple cross site scripting vulnerabilities.
Kategorier: Säkerhet

Batavi 1.1.2 SQL Injection

11 tim 2 min sedan
Batavi version 1.1.2 suffers from a remote SQL injection vulnerability.
Kategorier: Säkerhet

Cyberoam Central Console 2.00.2 Local File Inclusion

11 tim 4 min sedan
Cyberoam Central Console version 2.00.2 suffers from a local file inclusion vulnerability.
Kategorier: Säkerhet

Facebook Profile Sticker SQL Injection

11 tim 6 min sedan
Facebook Profile Sticker suffers from a remote SQL injection vulnerability.
Kategorier: Säkerhet

HP Security Bulletin HPSBMU02736 SSRT100699 2

11 tim 7 min sedan
HP Security Bulletin HPSBMU02736 SSRT100699 2 - Potential security vulnerabilities have been identified with HP Business Availability Center (BAC) and Business Service Management (BSM). The vulnerabilities could be remotely exploited to allow unauthorized access to sensitive information. Revision 2 of this advisory.
Kategorier: Säkerhet

Dinama SMS Service Cross Site Scripting

11 tim 31 min sedan
Dinama SMS Service suffers from a cross site scripting vulnerability.
Kategorier: Säkerhet

eFronts Community++ 3.6.10 Cross Site Scripting

11 tim 33 min sedan
eFronts Community++ version 3.6.10 suffers from a cross site scripting vulnerability.
Kategorier: Säkerhet

VolksBank Online Banking Cross Site Scripting / Redirection

11 tim 34 min sedan
VolksBank Online Banking suffers from cross site scripting, open redirection and input validation vulnerabilities.
Kategorier: Säkerhet

SimpleGroupware 0.742 Cross Site Scripting

11 tim 37 min sedan
SimpleGroupware version 0.742 suffers from a cross site scripting vulnerability.
Kategorier: Säkerhet

Apache CXF UsernameToken Broken Validation

11 tim 39 min sedan
Apache CXF versions 2.4.5 and 2.5.1 fail to validate a WS-Security UsernameToken received as part of the security header of a SOAP request against a WS-SP UsernameToken policy.
Kategorier: Säkerhet

Fake POP3 Daemon

11 tim 40 min sedan
This is a compact fake pop3 daemon that logs password attacks.
Kategorier: Säkerhet

DEF CON 20 Capture The Flag Information

11 tim 42 min sedan
This is an newsletter that discusses information related to Capture The Flag that will be held at DEF CON 20 this year.
Kategorier: Säkerhet

Debian Security Advisory 2403-2

11 tim 43 min sedan
Debian Linux Security Advisory 2403-2 - Stefan Esser discovered that the implementation of the max_input_vars configuration variable in a recent PHP security update was flawed such that it allows remote attackers to crash PHP or potentially execute code.
Kategorier: Säkerhet

Ubuntu Security Notice USN-1356-1

11 tim 45 min sedan
Ubuntu Security Notice 1356-1 - A flaw was discovered in the XFS filesystem. If a local user mounts a specially crafted XFS image it could potential execute arbitrary code on the system. Chen Haogang discovered an integer overflow that could result in memory corruption. A local unprivileged user could use this to crash the system. A flaw was found in the linux kernels IPv4 IGMP query processing. A remote attacker could exploit this to cause a denial of service. Various other issues were also addressed.
Kategorier: Säkerhet

Another File Integrity Checker 2.20

11 tim 45 min sedan
afick is another file integrity checker, designed to be fast and fully portable between Unix and Windows platforms. It works by first creating a database that represents a snapshot of the most essential parts of your computer system. Then a user can run the script to discover all modifications made since the snapshot was taken (i.e. files added, changed, or removed). The configuration syntax is very close to that of aide or tripwire, and a graphical interface is provided.
Kategorier: Säkerhet

Whitewash 2.0

11 tim 49 min sedan
The Whitewash module allows Ruby programs to clean up any HTML document or fragment coming from an untrusted source and to remove all dangerous constructs that could be used for cross-site scripting or request forgery. All HTML tags, attribute names and values, and CSS properties are filtered through a whitelist that defines which names and what kinds of values are allowed; everything that doesn't match the whitelist is removed. The whitelist is provided externally, and the default whitelist is loaded from the whitelist.yaml shipped with Whitewash. The default is the most strict (for example, it does not allow cross-site links to images in IMG tags) and can be considered safe for all uses.
Kategorier: Säkerhet

Typsoft FTP Server 1.10 Denial Of Service

11 tim 50 min sedan
Three proof of concept exploits that demonstrate denial of service vulnerabilities in Typsoft FTP server version 1.10.
Kategorier: Säkerhet

Flyspray 0.9.9.6 Cross Site Request Forgery

11 tim 54 min sedan
Flyspray version 0.9.9.6 suffers from a cross site request forgery vulnerability.
Kategorier: Säkerhet

PS Design Web Site SQL Injection

tis, 2012-02-07 14:12
PS Design Web Site suffers from a remote SQL injection vulnerability.
Kategorier: Säkerhet

Axiatel.com Cross Site Scripting

tis, 2012-02-07 13:11
Axiatel.com suffers from a cross site scripting vulnerability.
Kategorier: Säkerhet