|
FasterSlasher is a Perl script that displays a list of articles or headlines taken from a remote RSS or RDF file. Basically, you feed FasterSlasher the URL of an RSS file on the web & it will fetch the file, interpret the XML coding & display a nicely formatted list.
Output can be formatted for full-page display or SSI use. Other controls include the number of headlines/articles shown & whether descriptions are displayed in addition to titles.
XML parsing is handled by the Perl module XML::RSSLite. This is not a "standard" Perl module & your ISP may not support it. But it's easy to install locally in your own cgi-bin. (Details included in the download file.)
- Example A: Headline listing embedded in this page using SSI. Display of item descriptions is enabled. The number of titles is set to allow this site's RSS list to "max out"...
Bugtraq The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!
Vulnerabilities in CMS WebManager-Pro <p>Posted by MustLive on Sep 02</p>Hello Bugtraq!<br> <br> I want to warn you about SQL Injection and Redirector (URL Redirector Abuse)<br> vulnerabilities in CMS WebManager-Pro (SecurityVulns ID:11108). It's<br> Ukrainian commercial CMS.<br> <br> SQL Injection:<br> <br> <a rel="nofollow" href="http://site/c.php?id=1%20and%20version">http://site/c.php?id=1%20and%20version</a>()=5<br> <br> Redirector:<br> <br> <a rel="nofollow" href="http://site/c.php?id=1&url=http://websecurity.com.ua">http://site/c.php?id=1&url=http://websecurity.com.ua</a><br> <br> Affected products: both systems CMS WebManager-Pro from two developers.<br> Vulnerable are versions CMS WebManager-Pro up to 8.1...<br>
PRL Novell Netware OpenSSH Remote Stack Overflow <p>Posted by Francis Provencher on Sep 02</p>#####################################################################################<br> <br> Application: Novell Netware OpenSSH Remote Stack Overflow<br> <br> Platforms: Netware 6.5<br> <br> Exploitation: Remote code execution<br> <br> CVE Number:<br> <br> Novell TID: 7006756<br> <br> ZeroDayInitiative: ZDI-10-169<br> <br> Author: Francis Provencher (Protek Research Lab's)<br> <br> Blog: <a rel="nofollow" href="http://www.protekresearchlab.com/">http://www.protekresearchlab.com/</a>...<br>
Moovida Media Player version 2.0.0.15 Insecure DLL Hijacking Vulnerability (libc.dll,quserex.dll) <p>Posted by YGN Ethical Hacker Group on Sep 02</p>1. OVERVIEW<br> <br> The Moovida Media Player application is vulnerable to Insecure DLL<br> Hijacking Vulnerability. Similar terms that describe this<br> vulnerability<br> have been come up with Remote Binary Planting, Unsafe Library Loading,<br> and Insecure DLL Loading/Injection/Hijacking/Preloading.<br> <br> 2. PRODUCT DESCRIPTION<br> <br> Moovida Media Player is a free and open source media center that<br> allows you to enjoy all of your music, video and pictures<br> in an awsome...<br>
[ MDVSA-2010:168 ] openssl <p>Posted by security on Sep 02</p> _______________________________________________________________________<br> <br> Mandriva Linux Security Advisory MDVSA-2010:168<br> <a rel="nofollow" href="http://www.mandriva.com/security/">http://www.mandriva.com/security/</a><br> _______________________________________________________________________<br> <br> Package : openssl<br> Date : September 1, 2010<br> Affected: 2010.1<br> _______________________________________________________________________<br> <br> Problem Description:<br> <br> A vulnerability has been found...<br>
[ MDVSA-2010:169 ] mozilla-thunderbird <p>Posted by security on Sep 02</p> _______________________________________________________________________<br> <br> Mandriva Linux Security Advisory MDVSA-2010:169<br> <a rel="nofollow" href="http://www.mandriva.com/security/">http://www.mandriva.com/security/</a><br> _______________________________________________________________________<br> <br> Package : mozilla-thunderbird<br> Date : September 2, 2010<br> Affected: 2008.0, 2009.0, 2010.0, 2010.1<br> _______________________________________________________________________<br> <br> Problem...<br>
[USN-982-1] Wget vulnerability <p>Posted by Marc Deslauriers on Sep 02</p>===========================================================<br> Ubuntu Security Notice USN-982-1 September 02, 2010<br> wget vulnerability<br> CVE-2010-2252<br> ===========================================================<br> <br> A security issue affects the following Ubuntu releases:<br> <br> Ubuntu 6.06 LTS<br> Ubuntu 8.04 LTS<br> Ubuntu 9.04<br> Ubuntu 9.10<br> Ubuntu 10.04 LTS<br> <br> This advisory also applies to the corresponding versions of<br> Kubuntu, Edubuntu, and Xubuntu.<br> <br> The problem...<br>
XSS vulnerability in ArtGK CMS <p>Posted by advisory on Sep 01</p>Vulnerability ID: HTB22588<br> Reference: <a rel="nofollow" href="http://www.htbridge.ch/advisory/xss_vulnerability_in_artgk_cms_1.html">http://www.htbridge.ch/advisory/xss_vulnerability_in_artgk_cms_1.html</a><br> Product: ArtGK CMS<br> Vendor: ArtGK ( <a rel="nofollow" href="http://artgk-cms.ru/">http://artgk-cms.ru/</a> ) <br> Vulnerable Version: 2009-08-28 16:00:00 and Probably Prior Versions<br> Vendor Notification: 18 August 2010 <br> Vulnerability Type: XSS (Cross Site Scripting)<br> Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response<br> Risk level: Medium <br> Credit: High-Tech Bridge SA - Ethical Hacking &...<br>
Online Binary Planting Exposure Test <p>Posted by ACROS Lists on Sep 01</p>ACROS Security has made the Online Binary Planting Exposure Test publicly accessible<br> for the benefit of all Windows users. This test should make it easy for users and<br> administrators to assess their exposure to binary planting attacks originating from<br> the Internet.<br> <br> URL: <a rel="nofollow" href="http://www.binaryplanting.com/test.htm">http://www.binaryplanting.com/test.htm</a><br> <br> Note that this test is NOT meant to answer whether you're vulnerable (at this point<br> where so many binary planting vulnerabilities exist out...<br>
XSS vulnerability in Rumba CMS tags <p>Posted by advisory on Sep 01</p>Vulnerability ID: HTB22591<br> Reference: <a rel="nofollow" href="http://www.htbridge.ch/advisory/xss_vulnerability_in_rumba_cms.html">http://www.htbridge.ch/advisory/xss_vulnerability_in_rumba_cms.html</a><br> Product: Rumba CMS<br> Vendor: Rumba Netware Ltd. ( <a rel="nofollow" href="http://rumbacms.com">http://rumbacms.com</a> ) <br> Vulnerable Version: 2.4 and Probably Prior Versions<br> Vendor Notification: 18 August 2010 <br> Vulnerability Type: Stored XSS (Cross Site Scripting)<br> Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response<br> Risk level: Medium <br> Credit: High-Tech Bridge SA - Ethical Hacking...<br>
XSS vulnerability in ArtGK CMS forum <p>Posted by advisory on Sep 01</p>Vulnerability ID: HTB22587<br> Reference: <a rel="nofollow" href="http://www.htbridge.ch/advisory/xss_vulnerability_in_artgk_cms.html">http://www.htbridge.ch/advisory/xss_vulnerability_in_artgk_cms.html</a><br> Product: ArtGK CMS<br> Vendor: ArtGK ( <a rel="nofollow" href="http://artgk-cms.ru/">http://artgk-cms.ru/</a> ) <br> Vulnerable Version: 2009-08-28 16:00:00 and Probably Prior Versions<br> Vendor Notification: 18 August 2010 <br> Vulnerability Type: XSS (Cross Site Scripting)<br> Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response<br> Risk level: Medium <br> Credit: High-Tech Bridge SA - Ethical Hacking &...<br>
XSS vulnerability in Rumba CMS <p>Posted by advisory on Sep 01</p>Vulnerability ID: HTB22592<br> Reference: <a rel="nofollow" href="http://www.htbridge.ch/advisory/xss_vulnerability_in_rumba_cms_1.html">http://www.htbridge.ch/advisory/xss_vulnerability_in_rumba_cms_1.html</a><br> Product: Rumba CMS<br> Vendor: Rumba Netware Ltd. ( <a rel="nofollow" href="http://rumbacms.com">http://rumbacms.com</a> ) <br> Vulnerable Version: 2.4 and Probably Prior Versions<br> Vendor Notification: 18 August 2010 <br> Vulnerability Type: Stored XSS (Cross Site Scripting)<br> Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response<br> Risk level: Low <br> Credit: High-Tech Bridge SA - Ethical Hacking &...<br>
Tortoise SVN DLL Hijacking Vulnerability <p>Posted by nikhil_uitrgpv on Sep 01</p>The Common Vulnerabilities and Exposures (CVE) project has assigned the name CVE-2010-3199 to this issue. This is a <br> candidate for inclusion in the CVE list (<a rel="nofollow" href="http://cve.mitre.org">http://cve.mitre.org</a>), which standardizes names for security problems.<br>
XSS vulnerability in Amiro.CMS FAQ <p>Posted by advisory on Sep 01</p>Vulnerability ID: HTB22590<br> Reference: <a rel="nofollow" href="http://www.htbridge.ch/advisory/xss_vulnerability_in_amiro_cms_1.html">http://www.htbridge.ch/advisory/xss_vulnerability_in_amiro_cms_1.html</a><br> Product: Amiro.CMS<br> Vendor: Amiro ( <a rel="nofollow" href="http://www.amiro.ru/">http://www.amiro.ru/</a> ) <br> Vulnerable Version: 5.8.4.0 and Probably Prior Versions<br> Vendor Notification: 18 August 2010 <br> Vulnerability Type: Stored XSS (Cross Site Scripting)<br> Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response<br> Risk level: Medium <br> Credit: High-Tech Bridge SA - Ethical Hacking &...<br>
VMSA-2010-0013 VMware ESX third party updates for Service Console <p>Posted by VMware Security Team on Sep 01</p>------------------------------------------------------------------------<br> VMware Security Advisory<br> <br> Advisory ID: VMSA-2010-0013<br> Synopsis: VMware ESX third party updates for Service Console<br> Issue date: 2010-08-31<br> Updated on: 2010-08-31 (initial release of advisory)<br> CVE numbers: CVE-2005-4268 CVE-2010-0624 CVE-2010-2063<br> CVE-2010-1321 CVE-2010-1168 CVE-2010-1447...<br>
VMSA-2010-0013 <p>Posted by VMware Security Team on Sep 01</p>------------------------------------------------------------------------<br> VMware Security Advisory<br> <br> Advisory ID: VMSA-2010-0013<br> Synopsis: VMware ESX third party updates for Service Console<br> Issue date: 2010-08-31<br> Updated on: 2010-08-31 (initial release of advisory)<br> CVE numbers: CVE-2005-4268 CVE-2010-0624 CVE-2010-2063<br> CVE-2010-1321 CVE-2010-1168 CVE-2010-1447...<br>
View the last 25 posts.
- Example B: The link below will open a full-page display for kuro5hin.org & descriptions are provided in addition to titles...
Open a full page listing with descriptions (kuro5hin.org uses verbose descriptions!).
- Example C: The same headlines but without the descriptions & constrained to 8 headlines.
Open a full page listing without descriptions
In general, the SSI method is easier for most folks to use, since style sheets & other markups can be set conventionally. The full-page method requires some editing of the Perl source in order to incorporate style sheets or fancy formatting.
DOWNLOAD
|