<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.92">
<channel>
     <title>bugtraq at insecure.org</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/date.html</link>
     <description>Latest posts to bugtraq with detailed descriptions</description>
     <managingEditor>fyodor@NOSPAMinsecure.org (fyodor)</managingEditor>
     <webMaster>djeaux@NOSPAMdjeaux.com (djeaux)</webMaster>
     <generator>Scythe 2.10</generator>
     <lastBuildDate>Fri, 3 Jul 2009 21:02:38 PDT</lastBuildDate>
     <image>
          <url>http://www.djeaux.com/images/scraped_88x31.png</url>
          <title>bugtraq at insecure.org</title>
          <link>http://www.seclists.org/lists/bugtraq/2009/Jul</link>
          <description>bugtraq scraped from insecure.org</description>
     </image>
     <language>en-us</language>

<item>
     <title>Re: Cross-Site Scripting vulnerabilities in Mozilla, Internet  Explorer, Opera and Chrome</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0021.html</link>
     <author>lcamtuf@NOSPAMcoredump.cx (Michal Zalewski)</author>
     <pubDate>Fri, 3 Jul 2009 10:07:20 -0700</pubDate>
     <description>&gt; refresh: 0; URL=javascript:alert(document.cookie) &gt; The code will work in context of this site. ...which happens to be covered here for half a year or so: I can't see how this could be a vulnerability per se, although changing the behavior offers an additional, if small, degree of ...</description>
</item>
 
<item>
     <title>Cross-Site Scripting vulnerabilities in Mozilla, Internet Explorer, Opera and Chrome</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0020.html</link>
     <author>mustlive@NOSPAMwebsecurity.com.ua (MustLive)</author>
     <pubDate>Fri, 3 Jul 2009 01:21:57 +0300</pubDate>
     <description>Hello SecurityFocus! I want to warn you about Cross-Site Scripting vulnerabilities in Mozilla, Internet Explorer, Opera and Chrome. I wrote about it at my site this Monday (29.06.2009) and also informed corresponding browsers developers about this vulnerability. At 21.04.2009 there was fixed vulnerability in Firefox 3.0.9 (), which ...</description>
</item>
 
<item>
     <title>[oCERT-2009-007] FCKeditor input sanitization errors</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0019.html</link>
     <author>lcars@NOSPAMocert.org (Andrea Barisani)</author>
     <pubDate>Fri, 3 Jul 2009 16:45:21 +0100</pubDate>
     <description>#2009-007 FCKeditor input sanitization errors Description: FCKeditor, a web based open source HTML text editor, suffers from a remote file upload vulnerability. The input of several connector modules is not properly verified before being used, this leads to exposure of the contents of arbitrary directories on the ...</description>
</item>
 
<item>
     <title>[SECURITY] [DSA 1825-1] New nagios2/nagios3 packages fix arbitrary code execution</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0018.html</link>
     <author>nion@NOSPAMdebian.org (Nico Golde)</author>
     <pubDate>Fri, 3 Jul 2009 17:46:14 +0200</pubDate>
     <description>- Debian Security Advisory DSA-1825-1 securityatdebian&#46;org Nico Golde July 3rd, 2009 - Package : nagios2, nagios3 Vulnerability : insufficient input validation Problem type : remote Debian-specific: no CVE ID : CVE-2009-2288 It was discovered that the statuswml.cgi script of nagios, a monitoring ...</description>
</item>
 
<item>
     <title>One Click Ownage [White Paper and Scripts]</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0017.html</link>
     <author>ferruh@NOSPAMmavituna.com (Ferruh Mavituna)</author>
     <pubDate>Fri, 3 Jul 2009 11:50:17 +0100</pubDate>
     <description>This is a different and more practical approach to get a reverse shell or code execution in SQL Injections (particularly in MSSQL). The idea is simple. Getting a reverse shell from an SQL Injection with one HTTP request without using an extra channel such as TFTP, FTP to upload the ...</description>
</item>
 
<item>
     <title>Multiple Flaws in Axesstel MV 410R</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0016.html</link>
     <author>filip.palian@NOSPAMpjwstk.edu.pl (filip.palian_at_pjwstk.edu.pl)</author>
     <pubDate>Thu, 2 Jul 2009 14:49:08 -0600</pubDate>
     <description>Multiple Flaws in Axesstel MV 410R by Filip Palian &lt;filip (dot) palian (at) pjwstk (dot) edu (dot) pl Description: Axesstel MV 410R is a device offered by the two leading polish telecom operators Orange and Polish Telecom to provide broadband Internet in ...</description>
</item>
 
<item>
     <title>[ GLSA 200907-02 ] ModSecurity: Denial of Service</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0015.html</link>
     <author>a3li@NOSPAMgentoo.org (Alex Legler)</author>
     <pubDate>Thu, 02 Jul 2009 21:38:32 +0200</pubDate>
     <description>- - Gentoo Linux Security Advisory GLSA 200907-02 - - - - Severity: Normal Title: ModSecurity: Denial of Service Date: July 02, 2009 Bugs: #262302 ID: 200907-02 - - Synopsis Two vulnerabilities in ModSecurity might lead to a Denial of Service. ...</description>
</item>
 
<item>
     <title>[ GLSA 200907-01 ] libwmf: User-assisted execution of arbitrary code</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0014.html</link>
     <author>a3li@NOSPAMgentoo.org (Alex Legler)</author>
     <pubDate>Thu, 02 Jul 2009 21:36:57 +0200</pubDate>
     <description>- - Gentoo Linux Security Advisory GLSA 200907-01 - - - - Severity: Normal Title: libwmf: User-assisted execution of arbitrary code Date: July 02, 2009 Bugs: #268161 ID: 200907-01 - - Synopsis libwmf bundles an old GD version which contains a &quot;use-after-free&quot; ...</description>
</item>
 
<item>
     <title>[USN-795-1] Nagios vulnerability</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0013.html</link>
     <author>marc.deslauriers@NOSPAMcanonical.com (Marc Deslauriers)</author>
     <pubDate>Thu, 02 Jul 2009 14:29:06 -0400</pubDate>
     <description>Ubuntu Security Notice USN-795-1 July 02, 2009 nagios2, nagios3 vulnerability CVE-2009-2288 A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. ...</description>
</item>
 
<item>
     <title>[USN-794-1] Perl vulnerability</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0012.html</link>
     <author>marc.deslauriers@NOSPAMcanonical.com (Marc Deslauriers)</author>
     <pubDate>Thu, 02 Jul 2009 14:27:30 -0400</pubDate>
     <description>Ubuntu Security Notice USN-794-1 July 02, 2009 libcompress-raw-zlib-perl, perl vulnerability CVE-2009-1391 A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. ...</description>
</item>
 
<item>
     <title>[ISecAuditors Security Advisories] Joomla! &lt; 1.5.12 Multiple XSS vulnerabilities in HTTP Headers</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0011.html</link>
     <author>advisories@NOSPAMisecauditors.com (ISecAuditors Security Advisories)</author>
     <pubDate>Thu, 02 Jul 2009 17:13:50 +0200</pubDate>
     <description>INTERNET SECURITY AUDITORS ALERT 2009-007 - Original release date: June 30th, 2009 - Last revised: July 2nd, 2009 - Discovered by: Juan Galiana Lara - Severity: 6.8&#47;10 (CVSS Base Score) I. VULNERABILITY Joomla! &lt; 1.5.12 Multiple XSS vulnerabilities in HTTP Headers II. BACKGROUND ...</description>
</item>
 
<item>
     <title>[oCERT-2009-009] CamlImages integer overflows</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0010.html</link>
     <author>lcars@NOSPAMocert.org (Andrea Barisani)</author>
     <pubDate>Thu, 2 Jul 2009 14:01:24 +0100</pubDate>
     <description>#2009-009 CamlImages integer overflows Description: CamlImages, an open source image processing library, suffers from several integer overflows which may lead to a potentially exploitable heap overflow and result in arbitrary code execution. The vulnerability is triggered by PNG image parsing, the readpngfile and ...</description>
</item>
 
<item>
     <title>eAccelerator encoder files backup Vulnerability</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0009.html</link>
     <author>linuxrootkit2008@NOSPAMgmail.com (linuxrootkit2008_at_gmail.com)</author>
     <pubDate>2 Jul 2009 03:19:03 -0000</pubDate>
     <description>eAccelerator encoder files backup Vulnerability 1.Description ...</description>
</item>
 
<item>
     <title>Sourcefire 3D Sensor and DC, privilege escalation vulnerability</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0008.html</link>
     <author>c3rb3r@NOSPAMvideotron.ca (c3rb3r_at_videotron.ca)</author>
     <pubDate>Wed, 1 Jul 2009 14:44:41 -0600</pubDate>
     <description>Affected product Sourcefire 3D Sensor and Defense Center 4.8.x Tested on 4.8.0.3 and 4.8.0.4, 3D Sensor 2500 &amp; DC 1000 All 4.8.x releases, up to and including 4.8.1, confirmed vulnerable by sourcefire. Vulnerability details ...</description>
</item>
 
<item>
     <title>[security bulletin] HPSBUX02431 SSRT090085 rev.1 - HP-UX Running Apache Web Server Suite, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
     <link>http://www.seclists.org/lists/bugtraq/2009/Jul/0007.html</link>
     <author>security-alert@NOSPAMhp.com (security-alert_at_hp.com)</author>
     <pubDate>Wed, 01 Jul 2009 10:59:01 -0700</pubDate>
     <description>SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01756421 Version: 1 HPSBUX02431 SSRT090085 rev.1 - HP-UX Running Apache Web Server Suite, Remote Denial of Service (DoS), Execution of Arbitrary Code NOTICE: The information in this Security Bulletin should be acted upon as soon as possible. ...</description>
</item>
 
</channel>
</rss>
