New User, Welcome!     Login

web application framework

DotNetNuke Default Machine Key Exposure

===========================================================
1. Summary
===========================================================

DotNetNuke (DNN) is an open-source Web Application Framework used to create and deploy websites.  The default web.config files distributed with DNN include an embedded Machine Key value (both ValidationKey and DecryptionKey).  Under certain circumstances these values may not be updated during the installation/upgrade process, resulting in the ability for an attacker to forge arbitrary ASP.NET forms authentication tickets that can then be used to circumvent all security within a DNN installation.  This issue was confirmed to affect the production instance of DNN used on the DNN Homepage (www.dotnetnuke.com).  

The vendor (DotNetNuke Corporation) was notified of this issue on March 3, 2008.  The vendor responded by releasing version 4.8.2 on March 19, 2008 and has also issued a security bulletin (http://www.dotnetnuke.com/News/SecurityBulletins/SecurityBulletinno12/tabid/1148/Default.aspx).


===========================================================

Vulnerabilities in Dataface Web Application Framework

Hello Bugtraq!

I want to warn you about security vulnerabilities in Dataface Web
Application Framework.

-----------------------------
Advisory: Vulnerabilities in Dataface Web Application Framework
-----------------------------
URL: http://websecurity.com.ua/4276/
-----------------------------

[SECURITY] [DSA 2239-1] libmojolicious-perl security update

Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2010-4802 CVE-2010-4803 CVE-2011-1841 

Several vulnerabilities have been discovered Mojolicious, a Perl Web 
Application Framework. The link_to helper was affected by cross-site 
scripting and implementation errors in the MD5 HMAC and CGI environment 
handling have been corrected.

The oldstable distribution (lenny) doesn't include libmojolicious-perl.


Joomla! 1.7.0-RC and lower | Multiple Cross Site Scripting (XSS) Vulnerabilities

2. BACKGROUND

Joomla is a free and open source content management system (CMS) for
publishing content on the World Wide Web and intranets. It comprises a
model–view–controller (MVC) Web application framework that can also be
used independently.
Joomla is written in PHP, uses object-oriented programming (OOP)
techniques and software design patterns, stores data in a MySQL
database, and includes features such as page caching, RSS feeds,
printable versions of pages, news flashes, blogs, polls, search, and

Joomla! 1.6.3 and lower | Multiple Cross Site Scripting (XSS) Vulnerabilities

2. BACKGROUND

Joomla is a free and open source content management system (CMS) for
publishing content on the World Wide Web and intranets. It comprises a
model–view–controller (MVC) Web application framework that can also be
used independently.
Joomla is written in PHP, uses object-oriented programming (OOP)
techniques and software design patterns, stores data in a MySQL
database, and includes features such as page caching, RSS feeds,
printable versions of pages, news flashes, blogs, polls, search, and

[SECURITY] [DSA 2221-1] Mojolicious security update

Debian-specific: no
CVE ID         : CVE-2011-1589
Debian Bug     : 622952

Viacheslav Tykhanovskyi discovered a directory traversal vulnerability in 
Mojolicious, a Perl Web Application Framework.

The oldstable distribution (lenny) doesn't contain libmojolicious-perl.

For the stable distribution (squeeze), this problem has been fixed in
version 0.999926-1+squeeze1.

Joomla! 1.6.0 | Cross Site Scripting (XSS) Vulnerability

2. PRODUCT DESCRIPTION

Joomla is a free and open source content management system (CMS) for
publishing content on the World Wide Web and intranets. It comprises a
model–view–controller (MVC) Web application framework that can also be
used independently.
Joomla is written in PHP, uses object-oriented programming (OOP)
techniques and software design patterns, stores data in a MySQL
database, and includes features such as page caching, RSS feeds,
printable versions of pages, news flashes, blogs, polls, search, and

[ISecAuditors Security Advisories] Horde 3.3.5 "PHP_SELF" Cross-Site Scripting vulnerability

Horde 3.3.5 "PHP_SELF" Cross-Site Scripting vulnerability

II. BACKGROUND
-------------------------
The Horde Application Framework is a modular, general-purpose web
application framework written in PHP.  It provides an extensive array
of classes that are targeted at the common problems and tasks involved
in developing modern web applications.

III. DESCRIPTION
-------------------------

[ GLSA 200911-01 ] Horde: Multiple vulnerabilities

for arbitrary files to be overwritten and cross-site scripting attacks.

Background
==========

Horde is a web application framework written in PHP.

Affected packages
=================

    -------------------------------------------------------------------

[ GLSA 200805-01 ] Horde Application Framework: Multiple vulnerabilities

Background
==========

The Horde Application Framework is a general-purpose web application
framework written in PHP, providing classes for handling preferences,
compression, browser detection, connection tracking, MIME and more.

Affected packages
=================


Dot Net Nuke (DNN) <= 4.8.3 XSS Vulnerability

###################################################################################

####################
1. Description:
####################
        DotNetNuke is an open source web application framework ideal for creating, deploying and managing interactive web, intranet and extranet sites.

####################
2. Vulnerability:
####################
        XSS in "Default.aspx", by using "/" after the ".aspx" file. We must use another ".aspx" string, before "?" or at end of the URL.

Joomla! 1.7.0 | Multiple Cross Site Scripting (XSS) Vulnerabilities

2. BACKGROUND

Joomla is a free and open source content management system (CMS) for
publishing content on the World Wide Web and intranets. It comprises a
model–view–controller (MVC) Web application framework that can also be
used independently.
Joomla is written in PHP, uses object-oriented programming (OOP)
techniques and software design patterns, stores data in a MySQL
database, and includes features such as page caching, RSS feeds,
printable versions of pages, news flashes, blogs, polls, search, and

[SECURITY] [DSA 1470-1] New horde3 packages fix denial of service

Problem type   : remote
Debian-specific: no
CVE Id(s)      : CVE-2007-6018

Ulf Harnhammer discovered that the HTML filter of the Horde web
application framework performed insufficient input sanitising, which
may lead to the deletion of emails if a user is tricked into viewing
a malformed email inside the Imp client.

This update also provides backported bugfixes to the cross-site 
scripting filter and the user management API from the latest Horde

[SECURITY] [DSA 2259-1] rails security update

Debian-specific: no
CVE ID         : CVE-2009-3086 CVE-2009-4214
Debian Bug     : 545063 558685

Two vulnerabilities were discovered in Ruby on Rails, a web
application framework.  The Common Vulnerabilities and Exposures
project identifies the following problems:

CVE-2009-3086
        The cookie store may be vulnerability to a timing attack,
        potentially allowing remote attackers to forge message

Advisory 01/2009: Horde_Form_Type_image Arbitrary File Overwrite Vulnerability

Overview:

  Quote from http://www.horde.org
  "The Horde Application Framework is a general-purpose web application
   framework in PHP, providing classes for dealing with preferences,
   compression, browser detection, connection tracking, MIME handling,
   and more."

  During an audit of a PHP web application which is based on the Horde
  Application Framework it was discovered that form elements of the type

[SECURITY] [DSA 1897-1] New horde3 packages fix arbitrary code execution

Problem type   : remote
Debian-specific: no
Debian bug     : #547318
CVE ID         : CVE-2009-3236

Stefan Esser discovered that Horde, a web application framework providing
classes for dealing with preferences, compression, browser detection,
connection tracking, MIME, and more, is insufficiently validating and
escaping user provided input.  The Horde_Form_Type_image form element
allows to reuse a temporary filename on reuploads which are stored in a
hidden HTML field and then trusted without prior validation.  An attacker

Joomla! 1.6.0 | SQL Injection Vulnerability

2. BACKGROUND

Joomla is a free and open source content management system (CMS) for
publishing content on the World Wide Web and intranets. It comprises a
model–view–controller (MVC) Web application framework that can also be
used independently.
Joomla is written in PHP, uses object-oriented programming (OOP)
techniques and software design patterns, stores data in a MySQL
database, and includes features such as page caching, RSS feeds,
printable versions of pages, news flashes, blogs, polls, search, and

Joomla! 1.5.20 <= Cross Site Scripting (XSS) Vulnerability

2. PRODUCT DESCRIPTION

Joomla is a free and open source content management system (CMS) for
publishing content on the World Wide Web and intranets. It comprises a
model–view–controller (MVC) Web application framework that can also be
used independently.
Joomla is written in PHP, uses object-oriented programming (OOP)
techniques and software design patterns, stores data in a MySQL
database, and includes features such as page caching, RSS feeds,
printable versions of pages, news flashes, blogs, polls, search, and

Joomla! 1.6.0 | Information Disclosure/Full Path Disclosure Vulnerability

2. BACKGROUND

Joomla is a free and open source content management system (CMS) for
publishing content on the World Wide Web and intranets. It comprises a
model–view–controller (MVC) Web application framework that can also be
used independently.
Joomla is written in PHP, uses object-oriented programming (OOP)
techniques and software design patterns, stores data in a MySQL
database, and includes features such as page caching, RSS feeds,
printable versions of pages, news flashes, blogs, polls, search, and

[ GLSA 200909-14 ] Horde: Multiple vulnerabilities

or Cross-Site Scripting.

Background
==========

Horde is a web application framework written in PHP. Horde IMP, the
"Internet Messaging Program", is a Webmail module and Horde Passwd is a
password changing module for Horde.

Affected packages
=================



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!