Great Reviews!Need help setting up your website, installing Apache, PHP, MySQL, or PhpNuke?Need help customizing or designing scripts?Please contact me via the Contact Us option for further details and pricing.
DESCRIPTION: FiSh has discovered a vulnerability in the Cjay Content WYSIWYG IE module for Xoops, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Posted by Raven on Thursday, June 14, 2007 @ 12:50:39 EDT (478 reads) (Read More... | 1857 bytes more | Score: 0)
World Of WarCraft PHPNuke Theme released
Mars writes "PortalThemes - Warcraft PHPNuke Theme Released
WoWStone is a gorgeous fast loading PHPNuke Theme designed for a World of Warcraft Guild site.
Preview the theme at the PortalThemes PHPNuke Theme test site.
Select wowstone in the top left dropdown.
Includes a matching forum theme.
PSD file included for the header and topic icons.
IMPACT: Exposure of system information, Exposure of sensitive information, System access
WHERE: >From remote
REVISION: 1.1 originally posted 2007-06-13
SOFTWARE: PHP Real Estate Classifieds - http://secunia.com/product/14523/
DESCRIPTION: not sec group has reported a vulnerability in PHP Real Estate Classifieds, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Posted by Raven on Wednesday, June 13, 2007 @ 19:01:21 EDT (483 reads) (Read More... | 1475 bytes more | Score: 0)
IMPACT: Exposure of system information, Exposure of sensitive information, System access
WHERE: >From remote
SOFTWARE: Tiny Content 1.x (module for Xoops) - http://secunia.com/product/14527/
DESCRIPTION: Sp[L]o1T has discovered a vulnerability in the Tiny Content module for Xoops, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Posted by Raven on Wednesday, June 13, 2007 @ 18:57:29 EDT (446 reads) (Read More... | 1843 bytes more | Score: 0)
HP Help and Support Center Unspecified Vulnerability
IMPACT: Exposure of system information, Exposure of sensitive information, System access
WHERE: >From remote
SOFTWARE: Horoscope 2.x (module for Xoops) - http://secunia.com/product/14526/
DESCRIPTION: BeyazKurt has discovered a vulnerability in the Horoscope module for Xoops, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
Posted by Raven on Wednesday, June 13, 2007 @ 18:43:35 EDT (442 reads) (Read More... | 1456 bytes more | Score: 0)
DESCRIPTION: A vulnerability has been reported in OpenOffice, which can potentially be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error in the parsing of RTF files and can be exploited to cause a heap based buffer overflow via a specially crafted RTF file. Successful exploitation may allow execution of arbitrary code.
SOLUTION: Do not open untrusted RTF files.
PROVIDED AND/OR DISCOVERED BY: Reported in a Debian advisory crediting John Heasman.
ORIGINAL ADVISORY: http://www.us.debian.org/security/2007/dsa-1307
Posted by Raven on Wednesday, June 13, 2007 @ 18:39:54 EDT (367 reads) ( | Score: 0)
Microsofts IIS servers are more vulnerable to host malware than Apache servers
A recent survey by Google's Anti-Malware Team seems to confirm what many of us have believed in the past: Microsoft's IIS (Internet Information Services) servers are more vulnerable to host malware than Apache servers. The statistics come from the recently launched Google Online Security Blog whereby Google's researchers looked at 70,000 domains that were either distributing malware or hosting attack code.
Google however does make it clear in its blog that just because IIS is serving malware doesn't mean that it has been compromised; it might be possible that most 'warez' related Web sites uses IIS. This study has caused many heated discussions amongst security advocates and bloggers who claim that this might be an emerging type of gamesmanship from Google to promote Apache over another product made by its rival.
Posted by Raven on Tuesday, June 12, 2007 @ 17:43:14 EDT (386 reads) ( | Score: 0)