<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Bugtraq (bugtraq) Mailing List</title>
<link>http://seclists.org/#bugtraq</link>
<atom:link href="http://seclists.org/rss/bugtraq.rss" rel="self" type="application/rss+xml" />
<description>The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Re: Cross-Site Scripting vulnerabilities in Mozilla, Internet  Explorer, Opera and Chrome</title><description>Posted by Michal Zalewski on Jul 3&lt;p&gt;


&lt;p&gt;
&amp;gt; refresh: 0; URL=javascript:alert(document.cookie)
&lt;br /&gt;
&amp;gt; The code will work in context of this site.
&lt;br /&gt;
&lt;p&gt;...which happens to be covered here for half a year or so:
&lt;br /&gt;
http://code.google.com/p/browsersec/wiki/Part2#Redirection_restrictions
&lt;br /&gt;
&lt;p&gt;I can&#39;t see how this could be a vulnerability per se,...</description>
<link>http://seclists.org/bugtraq/2009/Jul/0021.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0021.html</guid>
<pubDate>Fri, 3 Jul 2009 10:07:20 -0700</pubDate></item>
<item><title>Cross-Site Scripting vulnerabilities in Mozilla, Internet Explorer, Opera and Chrome</title><description>Posted by MustLive on Jul 3&lt;p&gt;


&lt;p&gt;
Hello SecurityFocus!
&lt;br /&gt;
&lt;p&gt;I want to warn you about Cross-Site Scripting vulnerabilities in Mozilla,
&lt;br /&gt;
Internet Explorer, Opera and Chrome. I wrote about it at my site this Monday
&lt;br /&gt;
(29.06.2009) and also informed corresponding browsers developers about this
&lt;br /&gt;
vulnerability.
&lt;br /&gt;
&lt;p&gt;At 21.04.2009 there was fixed...</description>
<link>http://seclists.org/bugtraq/2009/Jul/0020.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0020.html</guid>
<pubDate>Fri, 3 Jul 2009 01:21:57 +0300</pubDate></item>
<item><title>[oCERT-2009-007] FCKeditor input sanitization errors</title><description>Posted by Andrea Barisani on Jul 3&lt;p&gt;


&lt;p&gt;
#2009-007 FCKeditor input sanitization errors
&lt;br /&gt;
&lt;p&gt;Description:
&lt;br /&gt;
&lt;p&gt;FCKeditor, a web based open source HTML text editor, suffers from a remote
&lt;br /&gt;
file upload vulnerability.
&lt;br /&gt;
&lt;p&gt;The input of several connector modules is not properly verified before being
&lt;br /&gt;
used, this leads to exposure of the contents of...</description>
<link>http://seclists.org/bugtraq/2009/Jul/0019.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0019.html</guid>
<pubDate>Fri, 3 Jul 2009 16:45:21 +0100</pubDate></item>
<item><title>[SECURITY] [DSA 1825-1] New nagios2nagios3 packages fix arbitrary code execution</title><description>Posted by Nico Golde on Jul 3&lt;p&gt;


&lt;p&gt;
&lt;p&gt;--------------------------------------------------------------------------
&lt;br /&gt;
Debian Security Advisory DSA-1825-1                    security_at_debian&amp;#46;org
&lt;br /&gt;
http://www.debian.org/security/                                 Nico Golde
&lt;br /&gt;
July 3rd, 2009                          ...</description>
<link>http://seclists.org/bugtraq/2009/Jul/0018.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0018.html</guid>
<pubDate>Fri, 3 Jul 2009 17:46:14 +0200</pubDate></item>
<item><title>One Click Ownage [White Paper and Scripts]</title><description>Posted by Ferruh Mavituna on Jul 3&lt;p&gt;


&lt;p&gt;
This is a different and more practical approach to get a reverse shell
&lt;br /&gt;
or code execution in SQL Injections (particularly in MSSQL). The idea
&lt;br /&gt;
is simple. Getting a reverse shell from an SQL Injection with one HTTP
&lt;br /&gt;
request without using an extra channel such as TFTP, FTP to upload the
&lt;br /&gt;
initial...</description>
<link>http://seclists.org/bugtraq/2009/Jul/0017.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0017.html</guid>
<pubDate>Fri, 3 Jul 2009 11:50:17 +0100</pubDate></item>
<item><title>Multiple Flaws in Axesstel MV 410R</title><description>Posted by filip.palian_at_pjwstk.edu.pl on Jul 2&lt;p&gt;


 (&#39;binary&#39; encoding is not supported, stored as-is)
Multiple Flaws in Axesstel MV 410R
&lt;br /&gt;
&lt;p&gt;by Filip Palian &amp;lt;filip (dot) palian (at) pjwstk (dot) edu (dot) pl
&lt;br /&gt;
&lt;p&gt;Description:
&lt;br /&gt;
Axesstel MV 410R is a device offered by the two leading polish telecom
&lt;br /&gt;
operators Orange and Polish Telecom to provide...</description>
<link>http://seclists.org/bugtraq/2009/Jul/0016.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0016.html</guid>
<pubDate>Thu, 2 Jul 2009 14:49:08 -0600</pubDate></item>
<item><title>[ GLSA 200907-02 ] ModSecurity: Denial of Service</title><description>Posted by Alex Legler on Jul 02&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200907-02
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2009/Jul/0015.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0015.html</guid>
<pubDate>Thu, 02 Jul 2009 21:38:32 +0200</pubDate></item>
<item><title>[ GLSA 200907-01 ] libwmf: User-assisted execution of arbitrary code</title><description>Posted by Alex Legler on Jul 02&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200907-01
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/bugtraq/2009/Jul/0014.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0014.html</guid>
<pubDate>Thu, 02 Jul 2009 21:36:57 +0200</pubDate></item>
<item><title>[USN-795-1] Nagios vulnerability</title><description>Posted by Marc Deslauriers on Jul 02&lt;p&gt;


&lt;p&gt;
===========================================================
&lt;br /&gt;
Ubuntu Security Notice USN-795-1              July 02, 2009
&lt;br /&gt;
nagios2, nagios3 vulnerability
&lt;br /&gt;
CVE-2009-2288
&lt;br /&gt;
===========================================================
&lt;br /&gt;
&lt;p&gt;A security issue affects the following Ubuntu releases:
&lt;br /&gt;
&lt;p&gt;Ubuntu...</description>
<link>http://seclists.org/bugtraq/2009/Jul/0013.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0013.html</guid>
<pubDate>Thu, 02 Jul 2009 14:29:06 -0400</pubDate></item>
<item><title>[USN-794-1] Perl vulnerability</title><description>Posted by Marc Deslauriers on Jul 02&lt;p&gt;


&lt;p&gt;
===========================================================
&lt;br /&gt;
Ubuntu Security Notice USN-794-1              July 02, 2009
&lt;br /&gt;
libcompress-raw-zlib-perl, perl vulnerability
&lt;br /&gt;
CVE-2009-1391
&lt;br /&gt;
===========================================================
&lt;br /&gt;
&lt;p&gt;A security issue affects the following Ubuntu...</description>
<link>http://seclists.org/bugtraq/2009/Jul/0012.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0012.html</guid>
<pubDate>Thu, 02 Jul 2009 14:27:30 -0400</pubDate></item>
<item><title>[ISecAuditors Security Advisories] Joomla! lt 1.5.12 Multiple XSS vulnerabilities in HTTP Headers</title><description>Posted by ISecAuditors Security Advisories on Jul 02&lt;p&gt;


&lt;p&gt;
=============================================
&lt;br /&gt;
INTERNET SECURITY AUDITORS ALERT 2009-007
&lt;br /&gt;
- Original release date: June 30th, 2009
&lt;br /&gt;
- Last revised:  July 2nd, 2009
&lt;br /&gt;
- Discovered by: Juan Galiana Lara
&lt;br /&gt;
- Severity: 6.8/10 (CVSS Base Score)
&lt;br /&gt;
=============================================
&lt;br /&gt;
&lt;p&gt;I....</description>
<link>http://seclists.org/bugtraq/2009/Jul/0011.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0011.html</guid>
<pubDate>Thu, 02 Jul 2009 17:13:50 +0200</pubDate></item>
<item><title>[oCERT-2009-009] CamlImages integer overflows</title><description>Posted by Andrea Barisani on Jul 2&lt;p&gt;


&lt;p&gt;
#2009-009 CamlImages integer overflows
&lt;br /&gt;
&lt;p&gt;Description:
&lt;br /&gt;
&lt;p&gt;CamlImages, an open source image processing library, suffers from several
&lt;br /&gt;
integer overflows which may lead to a potentially exploitable heap overflow and
&lt;br /&gt;
result in arbitrary code execution.
&lt;br /&gt;
&lt;p&gt;The vulnerability is triggered by PNG image...</description>
<link>http://seclists.org/bugtraq/2009/Jul/0010.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0010.html</guid>
<pubDate>Thu, 2 Jul 2009 14:01:24 +0100</pubDate></item>
<item><title>eAccelerator encoder files backup Vulnerability</title><description>Posted by linuxrootkit2008_at_gmail.com on Jul 2&lt;p&gt;


 (&#39;binary&#39; encoding is not supported, stored as-is)
eAccelerator encoder files backup Vulnerability
&lt;br /&gt;
&lt;p&gt;1.Description
&lt;br /&gt;
eAccelerator is a free open-source PHP accelerator, optimizer, and dynamic content cache. It increases the performance of PHP scripts by caching them in their compiled state, so that...</description>
<link>http://seclists.org/bugtraq/2009/Jul/0009.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0009.html</guid>
<pubDate>2 Jul 2009 03:19:03 -0000</pubDate></item>
<item><title>Sourcefire 3D Sensor and DC, privilege escalation vulnerability</title><description>Posted by c3rb3r_at_videotron.ca on Jul 1&lt;p&gt;


 (&#39;binary&#39; encoding is not supported, stored as-is)
Affected product
&lt;br /&gt;
----------------
&lt;br /&gt;
&lt;p&gt;Sourcefire 3D Sensor and Defense Center 4.8.x
&lt;br /&gt;
&amp;nbsp;
&lt;br /&gt;
Tested on 4.8.0.3 and 4.8.0.4, 3D Sensor 2500 &amp;amp; DC 1000
&lt;br /&gt;
All 4.8.x releases, up to and including 4.8.1, confirmed vulnerable by sourcefire.
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;...</description>
<link>http://seclists.org/bugtraq/2009/Jul/0008.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0008.html</guid>
<pubDate>Wed, 1 Jul 2009 14:44:41 -0600</pubDate></item>
<item><title>[security bulletin] HPSBUX02431 SSRT090085 rev.1 - HP-UX Running Apache Web Server Suite, Remote Denial of Service (DoS), Execution of Arbitrary Code</title><description>Posted by security-alert_at_hp.com on Jul 01&lt;p&gt;


&lt;p&gt;
&lt;p&gt;SUPPORT COMMUNICATION - SECURITY BULLETIN
&lt;br /&gt;
&lt;p&gt;Document ID: c01756421
&lt;br /&gt;
Version: 1
&lt;br /&gt;
&lt;p&gt;HPSBUX02431 SSRT090085 rev.1 - HP-UX Running Apache Web Server Suite, Remote Denial of Service (DoS), Execution of Arbitrary Code
&lt;br /&gt;
&lt;p&gt;NOTICE: The information in this Security Bulletin should be acted upon as soon as...</description>
<link>http://seclists.org/bugtraq/2009/Jul/0007.html</link><guid isPermaLink="true">http://seclists.org/bugtraq/2009/Jul/0007.html</guid>
<pubDate>Wed, 01 Jul 2009 10:59:01 -0700</pubDate></item>
</channel></rss>