PacketStorm Security

20 Most Recent Packet Storm File Additions



wordpress-cookie-integrity.txt

April 25, 2008, 8:18 pm   [ link da copiare ]
An attacker, who is able to register a specially crafted username on a Wordpress 2.5 installation, is able to generate authentication cookies for other chosen accounts. This is not good.

MDVSA-2008-091.txt

April 25, 2008, 8:18 pm   [ link da copiare ]
Mandriva Linux Security Advisory - A few vulnerabilities were found in Wireshark, that could cause it to crash or hang under certain conditions.

ruby-nmap-parser-0.3.tgz

April 25, 2008, 8:18 pm   [ link da copiare ]
This library provides a Ruby interface to Nmap's scan data. It can run Nmap and parse its XML output directly from the scan, parse a file containing the XML data from a separate scan, parse a String of XML data from a scan, or parse XML data from an object via its read() method. This information is presented in an easy-to-use and intuitive fashion for storing and manipulating.

minibb-xsssql.txt

April 25, 2008, 8:18 pm   [ link da copiare ]
miniBB version 2.2 suffers from cross site scripting and SQL injection vulnerabilities.

postnukeschedule-sql.txt

April 25, 2008, 8:18 pm   [ link da copiare ]
The Postnuke PostSchedule module suffers from a SQL injection vulnerability.

dsa-1558-1.txt

April 25, 2008, 8:18 pm   [ link da copiare ]
Debian Security Advisory 1558-1 - It was discovered that crashes in the Javascript engine of xulrunner, the Gecko engine library, could potentially lead to the execution of arbitrary code.

sipwitch-0.1.1.tar.gz

April 25, 2008, 8:18 pm   [ link da copiare ]
GNU SIP Witch is a pure SIP-based office telephone call server that supports generic phone system features like call forwarding, hunt groups and call distribution, call coverage and ring groups, holding, and call transfer, as well as offering SIP specific capabilities such as presence and messaging. It supports secure telephone extensions for making calls over the Internet, and intercept/decrypt-free peer-to-peer audio and video extensions. It is not a SIP proxy, a multi-protocol telephone server, or an IP-PBX, and does not try to emulate Asterisk, FreeSWITCH, or Yate.

SSRT080031.txt

April 25, 2008, 8:18 pm   [ link da copiare ]
HP Security Bulletin - A potential vulnerability has been identified with the HPeDiag ActiveX control which is a component of HP Software Update running under windows. The vulnerability could be exploited to allow remote disclosure of information and execution of arbitrary code.

dsa-1534-2.txt

April 25, 2008, 8:18 pm   [ link da copiare ]
Debian Security Advisory 1534-2 - Several remote vulnerabilities have been discovered in the Iceape internet suite, an unbranded version of the Seamonkey Internet Suite. Second advisory released as a regression in mailnews handling has been fixed.

dsa-1557-1.txt

April 25, 2008, 8:18 pm   [ link da copiare ]
Debian Security Advisory 1557-1 - Several remote vulnerabilities have been discovered in phpMyAdmin, an application to administrate MySQL over the WWW. Attackers with CREATE table permissions were allowed to read arbitrary files readable by the webserver via a crafted HTTP POST request. The PHP session data file stored the username and password of a logged in user, which in some setups can be read by a local user. Cross site scripting and SQL injection were possible by attackers that had permission to create cookies in the same cookie domain as phpMyAdmin runs in.

dsa-1556-1.txt

April 25, 2008, 8:18 pm   [ link da copiare ]
Debian Security Advisory 1556-1 - It has been discovered that the Perl interpreter may encounter a buffer overflow condition when compiling certain regular expressions containing Unicode characters. This also happens if the offending characters are contained in a variable reference protected by the \Q...\E quoting construct. When encountering this condition, the Perl interpreter typically crashes, but arbitrary code execution cannot be ruled out.

nicelog-1.0.tgz

April 25, 2008, 8:18 pm   [ link da copiare ]
logtamper is a modified version of wtmpclean that also modifies UTMP and lastlog related entries.

[1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15]