<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bugtraq</title>
    <link>http://seclists.org/#bugtraq</link>
    <atom:link href="http://seclists.org/rss/bugtraq.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!</description>
    <pubDate>Thu, 02 Sep 2010 16:30:12 GMT</pubDate>
    <lastBuildDate>Thu, 02 Sep 2010 16:30:12 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Vulnerabilities in CMS WebManager-Pro</title>
    <link>http://seclists.org/bugtraq/2010/Sep/16</link>
    <description>&lt;p&gt;Posted by MustLive on Sep 02&lt;/p&gt;Hello Bugtraq!&lt;br&gt;
&lt;br&gt;
I want to warn you about SQL Injection and Redirector (URL Redirector Abuse)&lt;br&gt;
vulnerabilities in CMS WebManager-Pro (SecurityVulns ID:11108). It's&lt;br&gt;
Ukrainian commercial CMS.&lt;br&gt;
&lt;br&gt;
SQL Injection:&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://site/c.php?id=1%20and%20version&quot;&gt;http://site/c.php?id=1%20and%20version&lt;/a&gt;()=5&lt;br&gt;
&lt;br&gt;
Redirector:&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://site/c.php?id=1&amp;amp;url=http://websecurity.com.ua&quot;&gt;http://site/c.php?id=1&amp;amp;url=http://websecurity.com.ua&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Affected products: both systems CMS WebManager-Pro from two developers.&lt;br&gt;
Vulnerable are versions CMS WebManager-Pro up to 8.1...&lt;br&gt;</description>
    <pubDate>Thu, 02 Sep 2010 16:15:24 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/16</guid>
  </item>
  <item>
    <title>{PRL} Novell Netware OpenSSH Remote Stack Overflow</title>
    <link>http://seclists.org/bugtraq/2010/Sep/15</link>
    <description>&lt;p&gt;Posted by Francis Provencher on Sep 02&lt;/p&gt;#####################################################################################&lt;br&gt;
&lt;br&gt;
Application:   Novell Netware OpenSSH Remote Stack Overflow&lt;br&gt;
&lt;br&gt;
Platforms:  Netware 6.5&lt;br&gt;
&lt;br&gt;
Exploitation:   Remote code execution&lt;br&gt;
&lt;br&gt;
CVE Number:&lt;br&gt;
&lt;br&gt;
Novell TID:   7006756&lt;br&gt;
&lt;br&gt;
ZeroDayInitiative: ZDI-10-169&lt;br&gt;
&lt;br&gt;
Author:   Francis Provencher (Protek Research Lab's)&lt;br&gt;
&lt;br&gt;
Blog:   &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.protekresearchlab.com/&quot;&gt;http://www.protekresearchlab.com/&lt;/a&gt;...&lt;br&gt;</description>
    <pubDate>Thu, 02 Sep 2010 16:07:17 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/15</guid>
  </item>
  <item>
    <title>Moovida Media Player version 2.0.0.15 Insecure DLL Hijacking Vulnerability (libc.dll,quserex.dll)</title>
    <link>http://seclists.org/bugtraq/2010/Sep/14</link>
    <description>&lt;p&gt;Posted by YGN Ethical Hacker Group on Sep 02&lt;/p&gt;1. OVERVIEW&lt;br&gt;
&lt;br&gt;
The Moovida Media Player application is vulnerable to Insecure DLL&lt;br&gt;
Hijacking Vulnerability. Similar terms that describe this&lt;br&gt;
vulnerability&lt;br&gt;
have been come up with Remote Binary Planting, Unsafe Library Loading,&lt;br&gt;
and Insecure DLL Loading/Injection/Hijacking/Preloading.&lt;br&gt;
&lt;br&gt;
2. PRODUCT DESCRIPTION&lt;br&gt;
&lt;br&gt;
Moovida Media Player is a free and open source media center that&lt;br&gt;
allows you to enjoy all of your music, video and pictures&lt;br&gt;
in an awsome...&lt;br&gt;</description>
    <pubDate>Thu, 02 Sep 2010 16:05:23 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/14</guid>
  </item>
  <item>
    <title>[ MDVSA-2010:168 ] openssl</title>
    <link>http://seclists.org/bugtraq/2010/Sep/13</link>
    <description>&lt;p&gt;Posted by security on Sep 02&lt;/p&gt; _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Mandriva Linux Security Advisory                         MDVSA-2010:168&lt;br&gt;
 &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.mandriva.com/security/&quot;&gt;http://www.mandriva.com/security/&lt;/a&gt;&lt;br&gt;
 _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Package : openssl&lt;br&gt;
 Date    : September 1, 2010&lt;br&gt;
 Affected: 2010.1&lt;br&gt;
 _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Problem Description:&lt;br&gt;
&lt;br&gt;
 A vulnerability has been found...&lt;br&gt;</description>
    <pubDate>Thu, 02 Sep 2010 15:57:39 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/13</guid>
  </item>
  <item>
    <title>[ MDVSA-2010:169 ] mozilla-thunderbird</title>
    <link>http://seclists.org/bugtraq/2010/Sep/12</link>
    <description>&lt;p&gt;Posted by security on Sep 02&lt;/p&gt; _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Mandriva Linux Security Advisory                         MDVSA-2010:169&lt;br&gt;
 &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.mandriva.com/security/&quot;&gt;http://www.mandriva.com/security/&lt;/a&gt;&lt;br&gt;
 _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Package : mozilla-thunderbird&lt;br&gt;
 Date    : September 2, 2010&lt;br&gt;
 Affected: 2008.0, 2009.0, 2010.0, 2010.1&lt;br&gt;
 _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Problem...&lt;br&gt;</description>
    <pubDate>Thu, 02 Sep 2010 15:37:52 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/12</guid>
  </item>
  <item>
    <title>[USN-982-1] Wget vulnerability</title>
    <link>http://seclists.org/bugtraq/2010/Sep/11</link>
    <description>&lt;p&gt;Posted by Marc Deslauriers on Sep 02&lt;/p&gt;===========================================================&lt;br&gt;
Ubuntu Security Notice USN-982-1         September 02, 2010&lt;br&gt;
wget vulnerability&lt;br&gt;
CVE-2010-2252&lt;br&gt;
===========================================================&lt;br&gt;
&lt;br&gt;
A security issue affects the following Ubuntu releases:&lt;br&gt;
&lt;br&gt;
Ubuntu 6.06 LTS&lt;br&gt;
Ubuntu 8.04 LTS&lt;br&gt;
Ubuntu 9.04&lt;br&gt;
Ubuntu 9.10&lt;br&gt;
Ubuntu 10.04 LTS&lt;br&gt;
&lt;br&gt;
This advisory also applies to the corresponding versions of&lt;br&gt;
Kubuntu, Edubuntu, and Xubuntu.&lt;br&gt;
&lt;br&gt;
The problem...&lt;br&gt;</description>
    <pubDate>Thu, 02 Sep 2010 15:19:28 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/11</guid>
  </item>


  <item>
    <title>XSS vulnerability in ArtGK CMS</title>
    <link>http://seclists.org/bugtraq/2010/Sep/10</link>
    <description>&lt;p&gt;Posted by advisory on Sep 01&lt;/p&gt;Vulnerability ID: HTB22588&lt;br&gt;
Reference: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.htbridge.ch/advisory/xss_vulnerability_in_artgk_cms_1.html&quot;&gt;http://www.htbridge.ch/advisory/xss_vulnerability_in_artgk_cms_1.html&lt;/a&gt;&lt;br&gt;
Product: ArtGK CMS&lt;br&gt;
Vendor: ArtGK ( &lt;a  rel=&quot;nofollow&quot; href=&quot;http://artgk-cms.ru/&quot;&gt;http://artgk-cms.ru/&lt;/a&gt; ) &lt;br&gt;
Vulnerable Version: 2009-08-28 16:00:00 and Probably Prior Versions&lt;br&gt;
Vendor Notification: 18 August 2010 &lt;br&gt;
Vulnerability Type: XSS (Cross Site Scripting)&lt;br&gt;
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response&lt;br&gt;
Risk level: Medium &lt;br&gt;
Credit: High-Tech Bridge SA - Ethical Hacking &amp;amp;...&lt;br&gt;</description>
    <pubDate>Wed, 01 Sep 2010 16:22:09 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/10</guid>
  </item>
  <item>
    <title>Online Binary Planting Exposure Test</title>
    <link>http://seclists.org/bugtraq/2010/Sep/9</link>
    <description>&lt;p&gt;Posted by ACROS Lists on Sep 01&lt;/p&gt;ACROS Security has made the Online Binary Planting Exposure Test publicly accessible&lt;br&gt;
for the benefit of all Windows users. This test should make it easy for users and&lt;br&gt;
administrators to assess their exposure to binary planting attacks originating from&lt;br&gt;
the Internet.&lt;br&gt;
&lt;br&gt;
URL: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.binaryplanting.com/test.htm&quot;&gt;http://www.binaryplanting.com/test.htm&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Note that this test is NOT meant to answer whether you're vulnerable (at this point&lt;br&gt;
where so many binary planting vulnerabilities exist out...&lt;br&gt;</description>
    <pubDate>Wed, 01 Sep 2010 15:49:10 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/9</guid>
  </item>
  <item>
    <title>XSS vulnerability in Rumba CMS tags</title>
    <link>http://seclists.org/bugtraq/2010/Sep/8</link>
    <description>&lt;p&gt;Posted by advisory on Sep 01&lt;/p&gt;Vulnerability ID: HTB22591&lt;br&gt;
Reference: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.htbridge.ch/advisory/xss_vulnerability_in_rumba_cms.html&quot;&gt;http://www.htbridge.ch/advisory/xss_vulnerability_in_rumba_cms.html&lt;/a&gt;&lt;br&gt;
Product: Rumba CMS&lt;br&gt;
Vendor: Rumba Netware Ltd. ( &lt;a  rel=&quot;nofollow&quot; href=&quot;http://rumbacms.com&quot;&gt;http://rumbacms.com&lt;/a&gt; ) &lt;br&gt;
Vulnerable Version: 2.4 and Probably Prior Versions&lt;br&gt;
Vendor Notification: 18 August 2010 &lt;br&gt;
Vulnerability Type: Stored XSS (Cross Site Scripting)&lt;br&gt;
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response&lt;br&gt;
Risk level: Medium &lt;br&gt;
Credit: High-Tech Bridge SA - Ethical Hacking...&lt;br&gt;</description>
    <pubDate>Wed, 01 Sep 2010 15:47:46 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/8</guid>
  </item>
  <item>
    <title>XSS vulnerability in ArtGK CMS forum</title>
    <link>http://seclists.org/bugtraq/2010/Sep/7</link>
    <description>&lt;p&gt;Posted by advisory on Sep 01&lt;/p&gt;Vulnerability ID: HTB22587&lt;br&gt;
Reference: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.htbridge.ch/advisory/xss_vulnerability_in_artgk_cms.html&quot;&gt;http://www.htbridge.ch/advisory/xss_vulnerability_in_artgk_cms.html&lt;/a&gt;&lt;br&gt;
Product: ArtGK CMS&lt;br&gt;
Vendor: ArtGK ( &lt;a  rel=&quot;nofollow&quot; href=&quot;http://artgk-cms.ru/&quot;&gt;http://artgk-cms.ru/&lt;/a&gt; ) &lt;br&gt;
Vulnerable Version: 2009-08-28 16:00:00 and Probably Prior Versions&lt;br&gt;
Vendor Notification: 18 August 2010 &lt;br&gt;
Vulnerability Type: XSS (Cross Site Scripting)&lt;br&gt;
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response&lt;br&gt;
Risk level: Medium &lt;br&gt;
Credit: High-Tech Bridge SA - Ethical Hacking &amp;amp;...&lt;br&gt;</description>
    <pubDate>Wed, 01 Sep 2010 15:34:18 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/7</guid>
  </item>
  <item>
    <title>XSS vulnerability in Rumba CMS</title>
    <link>http://seclists.org/bugtraq/2010/Sep/6</link>
    <description>&lt;p&gt;Posted by advisory on Sep 01&lt;/p&gt;Vulnerability ID: HTB22592&lt;br&gt;
Reference: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.htbridge.ch/advisory/xss_vulnerability_in_rumba_cms_1.html&quot;&gt;http://www.htbridge.ch/advisory/xss_vulnerability_in_rumba_cms_1.html&lt;/a&gt;&lt;br&gt;
Product: Rumba CMS&lt;br&gt;
Vendor: Rumba Netware Ltd. ( &lt;a  rel=&quot;nofollow&quot; href=&quot;http://rumbacms.com&quot;&gt;http://rumbacms.com&lt;/a&gt; ) &lt;br&gt;
Vulnerable Version: 2.4 and Probably Prior Versions&lt;br&gt;
Vendor Notification: 18 August 2010 &lt;br&gt;
Vulnerability Type: Stored XSS (Cross Site Scripting)&lt;br&gt;
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response&lt;br&gt;
Risk level: Low &lt;br&gt;
Credit: High-Tech Bridge SA - Ethical Hacking &amp;amp;...&lt;br&gt;</description>
    <pubDate>Wed, 01 Sep 2010 15:27:00 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/6</guid>
  </item>
  <item>
    <title>Tortoise SVN DLL Hijacking Vulnerability</title>
    <link>http://seclists.org/bugtraq/2010/Sep/5</link>
    <description>&lt;p&gt;Posted by nikhil_uitrgpv on Sep 01&lt;/p&gt;The Common Vulnerabilities and Exposures (CVE) project has assigned the name CVE-2010-3199 to this issue. This is a &lt;br&gt;
candidate for inclusion in the CVE list (&lt;a  rel=&quot;nofollow&quot; href=&quot;http://cve.mitre.org&quot;&gt;http://cve.mitre.org&lt;/a&gt;), which standardizes names for security problems.&lt;br&gt;</description>
    <pubDate>Wed, 01 Sep 2010 15:23:30 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/5</guid>
  </item>
  <item>
    <title>XSS vulnerability in Amiro.CMS FAQ</title>
    <link>http://seclists.org/bugtraq/2010/Sep/4</link>
    <description>&lt;p&gt;Posted by advisory on Sep 01&lt;/p&gt;Vulnerability ID: HTB22590&lt;br&gt;
Reference: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.htbridge.ch/advisory/xss_vulnerability_in_amiro_cms_1.html&quot;&gt;http://www.htbridge.ch/advisory/xss_vulnerability_in_amiro_cms_1.html&lt;/a&gt;&lt;br&gt;
Product: Amiro.CMS&lt;br&gt;
Vendor: Amiro ( &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.amiro.ru/&quot;&gt;http://www.amiro.ru/&lt;/a&gt; ) &lt;br&gt;
Vulnerable Version: 5.8.4.0 and Probably Prior Versions&lt;br&gt;
Vendor Notification: 18 August 2010 &lt;br&gt;
Vulnerability Type: Stored XSS (Cross Site Scripting)&lt;br&gt;
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response&lt;br&gt;
Risk level: Medium &lt;br&gt;
Credit: High-Tech Bridge SA - Ethical Hacking &amp;amp;...&lt;br&gt;</description>
    <pubDate>Wed, 01 Sep 2010 15:13:34 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/4</guid>
  </item>
  <item>
    <title>VMSA-2010-0013 VMware ESX third party updates for Service Console</title>
    <link>http://seclists.org/bugtraq/2010/Sep/3</link>
    <description>&lt;p&gt;Posted by VMware Security Team on Sep 01&lt;/p&gt;------------------------------------------------------------------------&lt;br&gt;
                   VMware Security Advisory&lt;br&gt;
&lt;br&gt;
Advisory ID:       VMSA-2010-0013&lt;br&gt;
Synopsis:          VMware ESX third party updates for Service Console&lt;br&gt;
Issue date:        2010-08-31&lt;br&gt;
Updated on:        2010-08-31 (initial release of advisory)&lt;br&gt;
CVE numbers:       CVE-2005-4268 CVE-2010-0624 CVE-2010-2063&lt;br&gt;
                   CVE-2010-1321 CVE-2010-1168 CVE-2010-1447...&lt;br&gt;</description>
    <pubDate>Wed, 01 Sep 2010 15:12:03 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/3</guid>
  </item>
  <item>
    <title>VMSA-2010-0013</title>
    <link>http://seclists.org/bugtraq/2010/Sep/2</link>
    <description>&lt;p&gt;Posted by VMware Security Team on Sep 01&lt;/p&gt;------------------------------------------------------------------------&lt;br&gt;
                   VMware Security Advisory&lt;br&gt;
&lt;br&gt;
Advisory ID:       VMSA-2010-0013&lt;br&gt;
Synopsis:          VMware ESX third party updates for Service Console&lt;br&gt;
Issue date:        2010-08-31&lt;br&gt;
Updated on:        2010-08-31 (initial release of advisory)&lt;br&gt;
CVE numbers:       CVE-2005-4268 CVE-2010-0624 CVE-2010-2063&lt;br&gt;
                   CVE-2010-1321 CVE-2010-1168 CVE-2010-1447...&lt;br&gt;</description>
    <pubDate>Wed, 01 Sep 2010 15:01:30 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/bugtraq/2010/Sep/2</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
