Backup E-mails!   Data Recovery   Avast Antivirus Pro!

Archive for the 'Vulnerabilities DataBase' Category

Exploit: EasyGallery is prone to multiple input-validation vulnerabilities

Thursday, March 13th, 2008

EasyGallery is prone to multiple input-validation vulnerabilities, including an SQL-injection issue and two cross-site scripting issues, because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
These issues affect EasyGallery 5.0tr; other […]

Security: MS Office Outlook Remote Code Execution Vulnerability …

Wednesday, March 12th, 2008

Hello all,
This Security alert just came across my desk. There is a new exploit inside of microsoft office.
iDefense Security Advisory 03.11.08
http://labs.idefense.com/intelligence/vulnerabilities/
Mar 11, 2008
I. BACKGROUND
Microsoft Outlook provides an integrated solution for managing and
organizing e-mail messages, schedules, tasks, notes, contacts, and
other information. More information is available at the following URL.
http://office.microsoft.com/outlook/
II. DESCRIPTION

Sec: Joomla! and Mambo ‘Candle’ Component ‘cID’ Parameter SQL Injection Vulnerability

Wednesday, March 12th, 2008

The ‘Candle’ component for Joomla! and Mambo is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects Candle 1.0.0; other […]