Join Us on IRC! Server: irc.freenode.net | Channel: #localareasecurity

Advisory and Vulnerability Report 015
Posted on 04.06.05 @ 6:59 pm (CST)

Direct Download | Stream It

Subscribe to Podcasts:

Related Links and Notes:

FreeBSD Kernel AMD64 Unprivileged Hardware Access

IBM AIX NIS Client Unspecified Remote

PHP-Nuke Web_Links Module Multiple Cross-Site Scripting

PHP-Nuke Banners.PHP Cross-Site Scripting

DameWare Mini Remote Control Server Unspecified Privilege Escalation

RunCMS Remote Arbitrary File Upload

Cisco IOS Unauthorized Security Association Establishment

Cisco IOS Easy VPN Server XAUTH Authentication Bypass

Vixie Cron Crontab File Disclosure

Active Auction House Default.ASP Multiple SQL Injection

Active Auction House ItemInfo.ASP SQL Injection

Active Auction House Sendpassword.ASP SQL Injection

HP OpenView Network Node Manager Unspecified Remote Denial of Service

MailEnable IMAP Login Request Buffer Overflow

WebWasher Conf Script Cross-Site Scripting

Active Auction House ReturnURL Multiple Cross-Site Scripting

Active Auction House Sendpassword.ASP Multiple Cross-Site Scripting

Active Auction House WatchThisItem.ASP Cross-Site Scripting

Cisco IOS Secure Shell Server V2 Remote Denial Of Service

Cisco IOS Secure Shell Server Memory Leak Denial Of Service

IBM Lotus Domino Server Web Service Remote Denial Of Service

Ocean12 Membership Manager Pro Cross-Site Scripting

PHP-Nuke Top Module SQL Injection

PopUp Plus For Miranda Instant Messenger Remote Buffer Overflow

SCSSBoard URL Tag Script Injection

PHPBB DLMan Pro Module SQL Injection

PHPBB LinksLinks Pro Module SQL Injection

LiteCommerce Multiple SQL Injection

Ocean12 Membership Manager Pro SQL Injection

CubeCart Multiple SQL Injection


Filed under: Podcast
Comments: None

Advisory and Vulnerability Report 014
Posted on 04.05.05 @ 5:59 pm (CST)

Direct Download | Stream It

Subscribe to Podcasts:

Related Links and Notes:

FreeBSD Kernel SendFile System Call Local Information Disclosure

GNU GZip CHMod File Permission Modification Race Condition Weakness

Logics Software LOG-FT Arbitrary File Disclosure

CommuniGate Pro LIST Unspecified Denial of Service

Comersus Cart Username Field HTML Injection

Gaim Gaim_Markup_Strip_HTML Remote Denial Of Service

Gaim IRC Protocol Plug-in Markup Language Injection

Gaim Jabber File Request Remote Denial Of Service

Microsoft Windows Server 2003 SMB Redirector Local Denial Of Service

Pavuk Multiple Unspecified Security Vulnerabilities

ProfitCode Software PayProCart Directory Traversal

PHP-Nuke Your_Account Module Username Cross-Site Scripting

PHP-Nuke Your_Account Module Avatarcategory Cross-Site Scripting

PHP-Nuke Downloads Module Lid Parameter Cross-Site Scripting

Computer Associates eTrust Intrusion Detection System Remote Denial of Service


Filed under: Podcast
Comments: None

Advisory and Vulnerability Report 013
Posted on 04.04.05 @ 5:59 pm (CST)

Direct Download | Stream It

Subscribe to Podcasts:

Related Links and Notes:

Remstats Local Insecure Temporary File Creation

Remstats Remote Command Execution

GNU Sharutils Unshar Local Insecure Temporary File Creation

SonicWALL SOHO Web Interface Multiple Remote Input Validation

SCO OpenServer NWPrint Command Line Argument Local Buffer Overflow

Linux Kernel Asynchronous Input/Output Local Denial Of Service

Adobe Acrobat Reader ActiveX Control LoadFile Information Disclosure

Early Impact ProductCart Multiple Input Validation

Mozilla Suite/Firefox JavaScript Lambda Replace Heap Memory Disclosure

IBM iSeries AS400 LDAP Server Remote Information Disclosure


Filed under: Podcast
Comments: None

Advisory and Vulnerability Report 012
Posted on 04.01.05 @ 8:25 pm (CST)

Direct Download | Stream It

Subscribe to Podcasts:

Related Links and Notes:

PHP Group PHP Image File Format Remote Denial Of Service

PHP Group PHP Remote JPEG File Format Remote Denial Of Service

BlueSoleil Object Push Service Bluetooth File Upload Directory Traversal

RUMBA Profile Handling Multiple Buffer Overflow

BakBone NetVault Configure.CFG Local Buffer Overflow

MaxWebPortal Events And Links Interface Multiple Input Validation

Microsoft Windows UNC Path Handling Unspecified Buffer Overflow

Linux Kernel TmpFS Driver Local Denial Of Service

AlstraSoft EPay Pro Multiple Cross-Site Scripting

AlstraSoft EPay Pro Remote File Include


Filed under: Podcast
Comments: None

Advisory and Vulnerability Report 011
Posted on 03.31.05 @ 6:59 pm (CST)

Direct Download | Stream It

Subscribe to Podcasts:

Related Links and Notes:

Linux Kernel Futex Local Deadlock Denial Of Service


Microsoft Jet Database Engine Malformed Database File Buffer Overflow

InterAKT Online MX Shop SQL Injection

ASP-DEV XM Forum IMG Tag Script Injection

Bay Technical Associates RPC3 Telnet Daemon Authentication Bypass


BZip2 CHMod File Permission Modification Race Condition Weakness


Filed under: Podcast
Comments: None

Advisory and Vulnerability Report 010
Posted on 03.30.05 @ 6:59 pm (CST)

Direct Download | Stream It

Subscribe to Podcasts:

Related Links and Notes:

Squirrelcart PHP Shopping Cart SQL Injection Vulnerabilities

PortalApp Cross-Site Scripting and SQL Injection

FastStone 4in1 Browser Web Server Directory Traversal

Chatness “user” Script Insertion Vulnerability

Cisco VPN 3000 Concentrator Denial of Service Vulnerability

Mailreader Remote HTML Injection Vulnerability

Kerio Personal Firewall Local Network Access Restriction Bypass Vulnerability

Linux Kernel File Lock Local Denial Of Service Vulnerability


Filed under: Podcast
Comments: None

« newer posts previous posts »
L.A.S. is a research group focused on information security related subjects. We are most known for L.A.S. Linux. Our live-CD security toolkit.
Read more. . .

L.A.S. Podcasts:
Podcast Page
Open Popup Flash Player
Podcast:

Main Menu
Home
About
Download
Forums
Podcast
  • News
  • FireFox Plugins

  • Store
    Contact


    Search

    InfoSec Links
  • InfoSec News


  • Featured Item
    Cool L.A.S. Shirt!

    Syndication
    Site RSS 2.0
    Podcast RSS
    Comments RSS 2.0

    Credits and Copyright
    Proudly powered by WordPress. Theme by Theron Parlin
    Hosting sunsite.dk
    and bay13.de
    DNS provided by freedns.afraid.org
    All content © 2004-2005 L.A.S


    Site Sections
    Papers/Presentations
    Latest Exploits


    Nessus Plugins
    in


    Recent Entries
  • New Site Launch
  • Site Rebuild Underway
  • Site Upgrades and Focus Change - UPDATED!
  • Seeking New Team Members!
  • Status of 0.6

  • Firefox Search Plugins
    (Click to install)
  • Install SANS RR Search Plugin SANS RR
  • Install ASTALAVISTA Search Plugin ASTALAVISTA
  • Install Help Net Security Search Plugin Help Net Security
  • Install Secunia Search Plugin Secunia
  • Install CVE (Keyword) Search Plugin CVE (Keyword)
  • Install CVE (Name) Search Plugin CVE (Name)
  • Install Snort Rules Search Plugin Snort Rules
  • Install ISECOM ports Search Plugin ISECOM Ports
  • Install Packet Storm Search Plugin Packet Storm
  • Install Bleeding Snort Search Plugin Bleeding Snort
  • Get Firefox!


    Donate