<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bugtraq</title>
    <link>http://seclists.org/#bugtraq</link>
    <atom:link href="http://seclists.org/rss/bugtraq.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!</description>
    <pubDate>Fri, 19 Mar 2010 15:15:25 GMT</pubDate>
    <lastBuildDate>Fri, 19 Mar 2010 15:15:25 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>There are lost of xss vul in PHPWind v6.0 !</title>
    <link>http://seclists.org/bugtraq/2010/Mar/157</link>
    <description>&lt;p&gt;Posted by lis cker on Mar 19&lt;/p&gt;I found the PHPWind v6.0 just filter the xss code when the visitors login in, but it doesnt do it when login off. &lt;br&gt;
 &lt;br&gt;
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the &lt;br&gt;
context of the affected site. &lt;br&gt;
&lt;br&gt;
This flaw makes its all the parameters in all the pages have the xss flaws when we login off!&lt;br&gt;
&lt;br&gt;
Like &amp;quot;hack.php&amp;quot; &amp;quot;search.php&amp;quot; &amp;quot;read.php&amp;quot;...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 15:03:02 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/157</guid>
  </item>
  <item>
    <title>CA20100318-01: Security Notice for CA ARCserve Backup</title>
    <link>http://seclists.org/bugtraq/2010/Mar/156</link>
    <description>&lt;p&gt;Posted by Kotas, Kevin J on Mar 19&lt;/p&gt;CA20100318-01: Security Notice for CA ARCserve Backup&lt;br&gt;
&lt;br&gt;
Issued: March 18, 2010&lt;br&gt;
&lt;br&gt;
CA's support is alerting customers to security risks with CA ARCserve&lt;br&gt;
Backup. The version of JRE shipped with ARCserve Backup is&lt;br&gt;
potentially susceptible to multiple vulnerabilities and has also&lt;br&gt;
reached end of life. Support is providing JRE 1.6 upgrades as&lt;br&gt;
remediation.&lt;br&gt;
&lt;br&gt;
Risk Rating&lt;br&gt;
&lt;br&gt;
High&lt;br&gt;
&lt;br&gt;
Platform&lt;br&gt;
&lt;br&gt;
Windows&lt;br&gt;
&lt;br&gt;
Affected Products&lt;br&gt;
&lt;br&gt;
CA ARCserve Backup r12.5&lt;br&gt;
CA ARCserve Backup...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 14:51:10 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/156</guid>
  </item>


  <item>
    <title>CORE-2010-0311 - eFront-learning PHP file inclusion vulnerability</title>
    <link>http://seclists.org/bugtraq/2010/Mar/155</link>
    <description>&lt;p&gt;Posted by CORE Security Technologies Advisories on Mar 17&lt;/p&gt;         eFront-learning PHP file inclusion vulnerability&lt;br&gt;
&lt;br&gt;
1. *Advisory Information*&lt;br&gt;
&lt;br&gt;
Title: eFront-learning PHP file inclusion vulnerability&lt;br&gt;
Advisory Id: CORE-2010-0311&lt;br&gt;
Advisory URL:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.coresecurity.com/content/efront-php-file-inclusion&quot;&gt;http://www.coresecurity.com/content/efront-php-file-inclusion&lt;/a&gt;&lt;br&gt;
Date published: 2010-03-16&lt;br&gt;
Date of last update: 2010-03-16&lt;br&gt;
Vendors contacted: Vendor name&lt;br&gt;
Release mode: Coordinated release&lt;br&gt;
&lt;br&gt;
2. *Vulnerability Information*&lt;br&gt;
&lt;br&gt;
Class: PHP file inclusion [CWE-98]&lt;br&gt;
Impact: Code...&lt;br&gt;</description>
    <pubDate>Wed, 17 Mar 2010 20:40:25 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/155</guid>
  </item>
  <item>
    <title>Sahana 0.6.2.2 Authentication Bypass</title>
    <link>http://seclists.org/bugtraq/2010/Mar/154</link>
    <description>&lt;p&gt;Posted by Christopher on Mar 17&lt;/p&gt;Ability to completely disable authentication via stream.php and commented&lt;br&gt;
out module authentication code within it.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://victim/&quot;&gt;http://victim/&lt;/a&gt;&amp;lt;sahana_path&amp;gt;/index.php?mod=admin&amp;amp;act=acl_enable_acl&lt;br&gt;
Authenticates correctly.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://victim/&quot;&gt;http://victim/&lt;/a&gt;&amp;lt;sahana_path&amp;gt;/stream.php?mod=admin&amp;amp;act=acl_enable_acl&lt;br&gt;
Does not.&lt;br&gt;</description>
    <pubDate>Wed, 17 Mar 2010 19:37:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/154</guid>
  </item>
  <item>
    <title>Secunia Research: Quicksilver Forums &quot;mysqldump&quot; Password Disclosure</title>
    <link>http://seclists.org/bugtraq/2010/Mar/153</link>
    <description>&lt;p&gt;Posted by Secunia Research on Mar 17&lt;/p&gt;====================================================================== &lt;br&gt;
&lt;br&gt;
                     Secunia Research 17/03/2010&lt;br&gt;
&lt;br&gt;
        - Quicksilver Forums &amp;quot;mysqldump&amp;quot; Password Disclosure -&lt;br&gt;
&lt;br&gt;
====================================================================== &lt;br&gt;
Table of Contents&lt;br&gt;
&lt;br&gt;
Affected Software....................................................1&lt;br&gt;
Severity.............................................................2&lt;br&gt;
Vendor's Description...&lt;br&gt;</description>
    <pubDate>Wed, 17 Mar 2010 19:24:45 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/153</guid>
  </item>
  <item>
    <title>Secunia Research: Quicksilver Forums Cross-Site Request Forgery Vulnerability</title>
    <link>http://seclists.org/bugtraq/2010/Mar/152</link>
    <description>&lt;p&gt;Posted by Secunia Research on Mar 17&lt;/p&gt;====================================================================== &lt;br&gt;
&lt;br&gt;
                     Secunia Research 17/03/2010&lt;br&gt;
&lt;br&gt;
   - Quicksilver Forums Cross-Site Request Forgery Vulnerability -&lt;br&gt;
&lt;br&gt;
====================================================================== &lt;br&gt;
Table of Contents&lt;br&gt;
&lt;br&gt;
Affected Software....................................................1&lt;br&gt;
Severity.............................................................2&lt;br&gt;
Vendor's Description of...&lt;br&gt;</description>
    <pubDate>Wed, 17 Mar 2010 19:09:15 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/152</guid>
  </item>
  <item>
    <title>Secunia Research: Quicksilver Forums Backup Information Disclosure</title>
    <link>http://seclists.org/bugtraq/2010/Mar/151</link>
    <description>&lt;p&gt;Posted by Secunia Research on Mar 17&lt;/p&gt;====================================================================== &lt;br&gt;
&lt;br&gt;
                     Secunia Research 17/03/2010&lt;br&gt;
&lt;br&gt;
         - Quicksilver Forums Backup Information Disclosure -&lt;br&gt;
&lt;br&gt;
====================================================================== &lt;br&gt;
Table of Contents&lt;br&gt;
&lt;br&gt;
Affected Software....................................................1&lt;br&gt;
Severity.............................................................2&lt;br&gt;
Vendor's Description of...&lt;br&gt;</description>
    <pubDate>Wed, 17 Mar 2010 18:57:07 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/151</guid>
  </item>
  <item>
    <title>CORE-2009-0803: Virtual PC Hypervisor Memory Protection Vulnerability</title>
    <link>http://seclists.org/bugtraq/2010/Mar/150</link>
    <description>&lt;p&gt;Posted by CORE Security Technologies Advisories on Mar 17&lt;/p&gt;      Core Security Technologies - CoreLabs Advisory&lt;br&gt;
           &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.coresecurity.com/corelabs/&quot;&gt;http://www.coresecurity.com/corelabs/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
   Virtual PC Hypervisor Memory Protection Vulnerability&lt;br&gt;
&lt;br&gt;
1. *Advisory Information*&lt;br&gt;
&lt;br&gt;
Title: Virtual PC Hypervisor Memory Protection Vulnerability&lt;br&gt;
Advisory Id: CORE-2009-0803&lt;br&gt;
Advisory URL:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.coresecurity.com/content/virtual-pc-2007-hypervisor-memory-protection-bug&quot;&gt;http://www.coresecurity.com/content/virtual-pc-2007-hypervisor-memory-protection-bug&lt;/a&gt;&lt;br&gt;
Date published: 2010-03-16&lt;br&gt;
Date of last update: 2010-03-16&lt;br&gt;
Vendors...&lt;br&gt;</description>
    <pubDate>Wed, 17 Mar 2010 18:24:26 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/150</guid>
  </item>
  <item>
    <title>Miranda IM silent TLS failure</title>
    <link>http://seclists.org/bugtraq/2010/Mar/149</link>
    <description>&lt;p&gt;Posted by Jan Schejbal on Mar 17&lt;/p&gt;Summary:&lt;br&gt;
Under certain conditions, Miranda ignores the &amp;quot;Use TLS&amp;quot; setting in &lt;br&gt;
Jabber accounts and uses an unencrypted connection.&lt;br&gt;
&lt;br&gt;
Affected: Miranda IM (instant messenger), at least versions 0.8.16, &lt;br&gt;
0.9.0 alpha build #6 Unicode and SVN rev. 11383&lt;br&gt;
&lt;br&gt;
Description:&lt;br&gt;
If the following conditions are met:&lt;br&gt;
  - &amp;quot;Use TLS&amp;quot; is enabled in the jabber account settings (Network - &lt;br&gt;
Jabber - Account),&lt;br&gt;
&lt;br&gt;
  - &amp;quot;Validate SSL certificates&amp;quot; is...&lt;br&gt;</description>
    <pubDate>Wed, 17 Mar 2010 16:53:31 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/149</guid>
  </item>
  <item>
    <title>Vulnerabilities in VXDate for Joomla</title>
    <link>http://seclists.org/bugtraq/2010/Mar/148</link>
    <description>&lt;p&gt;Posted by MustLive on Mar 17&lt;/p&gt;Hello Bugtraq!&lt;br&gt;
&lt;br&gt;
I want to warn you about vulnerabilities in component VXDate for Joomla.&lt;br&gt;
&lt;br&gt;
-----------------------------&lt;br&gt;
Advisory: Vulnerabilities in VXDate for Joomla&lt;br&gt;
-----------------------------&lt;br&gt;
URL: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://websecurity.com.ua/3849/&quot;&gt;http://websecurity.com.ua/3849/&lt;/a&gt;&lt;br&gt;
-----------------------------&lt;br&gt;
Timeline:&lt;br&gt;
&lt;br&gt;
10.05.2009 - found the vulnerabilities.&lt;br&gt;
12.01.2010 - announced at my site.&lt;br&gt;
18.01.2010 - informed developers.&lt;br&gt;
13.03.2010 - disclosed at my site.&lt;br&gt;
-----------------------------...&lt;br&gt;</description>
    <pubDate>Wed, 17 Mar 2010 16:33:11 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/148</guid>
  </item>
  <item>
    <title>[CORELAN-10-13] - Windisc Local Stack BOF</title>
    <link>http://seclists.org/bugtraq/2010/Mar/147</link>
    <description>&lt;p&gt;Posted by Security on Mar 17&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-013-windisc-buffer-overflow-bnz&quot;&gt;http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-013-windisc-buffer-overflow-bnz&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
|------------------------------------------------------------------|&lt;br&gt;
|                         __               __                      |&lt;br&gt;
|   _________  ________  / /___ _____     / /____  ____ _____ ___  |&lt;br&gt;
|  / ___/ __ \/ ___/ _ \/ / __ `/ __ \   / __/ _ \/ __ `/ __ `__ \ |&lt;br&gt;
| / /__/ /_/ / /  /  __/ / /_/ / / / /  / /_/  __/ /_/ / / / / / /...&lt;br&gt;</description>
    <pubDate>Wed, 17 Mar 2010 16:09:50 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/147</guid>
  </item>
  <item>
    <title>[security bulletin] HPSBGN02511 SSRT100022 rev.2 - HP Small Form Factor or Microtower PC with Broadcom Integrated NIC Firmware, Remote Execution of Arbitrary Code</title>
    <link>http://seclists.org/bugtraq/2010/Mar/146</link>
    <description>&lt;p&gt;Posted by security-alert on Mar 17&lt;/p&gt;SUPPORT COMMUNICATION - SECURITY BULLETIN&lt;br&gt;
&lt;br&gt;
Document ID: c02048471&lt;br&gt;
Version: 2&lt;br&gt;
&lt;br&gt;
HPSBGN02511 SSRT100022 rev.2 - HP Small Form Factor or Microtower PC with Broadcom Integrated NIC Firmware, Remote &lt;br&gt;
Execution of Arbitrary Code&lt;br&gt;
&lt;br&gt;
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.&lt;br&gt;
&lt;br&gt;
Release Date: 2010-03-15&lt;br&gt;
Last Updated: 2010-03-16&lt;br&gt;
&lt;br&gt;
Potential Security Impact: Remote execution of arbitrary code&lt;br&gt;
&lt;br&gt;
Source:...&lt;br&gt;</description>
    <pubDate>Wed, 17 Mar 2010 15:48:19 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/146</guid>
  </item>
  <item>
    <title>[USN-913-1] libpng vulnerabilities</title>
    <link>http://seclists.org/bugtraq/2010/Mar/145</link>
    <description>&lt;p&gt;Posted by Marc Deslauriers on Mar 16&lt;/p&gt;===========================================================&lt;br&gt;
Ubuntu Security Notice USN-913-1             March 16, 2010&lt;br&gt;
libpng vulnerabilities&lt;br&gt;
CVE-2009-2042, CVE-2010-0205&lt;br&gt;
===========================================================&lt;br&gt;
&lt;br&gt;
A security issue affects the following Ubuntu releases:&lt;br&gt;
&lt;br&gt;
Ubuntu 6.06 LTS&lt;br&gt;
Ubuntu 8.04 LTS&lt;br&gt;
Ubuntu 8.10&lt;br&gt;
Ubuntu 9.04&lt;br&gt;
Ubuntu 9.10&lt;br&gt;
&lt;br&gt;
This advisory also applies to the corresponding versions of&lt;br&gt;
Kubuntu, Edubuntu, and Xubuntu....&lt;br&gt;</description>
    <pubDate>Wed, 17 Mar 2010 04:34:28 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/145</guid>
  </item>
  <item>
    <title>Last Call for Papers, CONFidence 2010, 25-26May, Last Call for Papers</title>
    <link>http://seclists.org/bugtraq/2010/Mar/144</link>
    <description>&lt;p&gt;Posted by Andrzej Targosz on Mar 16&lt;/p&gt;CONFidence 2010 Last Call for Papers&lt;br&gt;
####################################&lt;br&gt;
&lt;br&gt;
Calling all practitioners in the field of IT security! The 7th edition&lt;br&gt;
of CONFidence 2010, is taking place in Krakow on May 25/26, 2010.&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://2010.confidence.org.pl&quot;&gt;http://2010.confidence.org.pl&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
We invite all to send the proposed topic and abstracts of presentation&lt;br&gt;
till the 25th of March. Please, remember that CONFidence is an open,&lt;br&gt;
international conference and all presentations should be given in...&lt;br&gt;</description>
    <pubDate>Wed, 17 Mar 2010 03:29:19 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/144</guid>
  </item>


  <item>
    <title>ZDI-10-032: SAP MaxDB Malformed Handshake Request Remote Code Execution Vulnerability</title>
    <link>http://seclists.org/bugtraq/2010/Mar/143</link>
    <description>&lt;p&gt;Posted by ZDI Disclosures on Mar 16&lt;/p&gt;ZDI-10-032: SAP MaxDB Malformed Handshake Request Remote Code Execution Vulnerability&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.zerodayinitiative.com/advisories/ZDI-10-032&quot;&gt;http://www.zerodayinitiative.com/advisories/ZDI-10-032&lt;/a&gt;&lt;br&gt;
March 16, 2010&lt;br&gt;
&lt;br&gt;
-- Affected Vendors:&lt;br&gt;
SAP&lt;br&gt;
&lt;br&gt;
-- Affected Products:&lt;br&gt;
SAP MaxDB&lt;br&gt;
&lt;br&gt;
-- TippingPoint(TM) IPS Customer Protection:&lt;br&gt;
TippingPoint IPS customers have been protected against this&lt;br&gt;
vulnerability by Digital Vaccine protection filter ID 9403. &lt;br&gt;
For further product information on the TippingPoint IPS, visit:...&lt;br&gt;</description>
    <pubDate>Tue, 16 Mar 2010 19:30:19 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Mar/143</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
