Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] Re: WebCalendar Multiple Vulnerabilities |
|---|---|
| Date: | Wed, 30 Nov 2005 15:10:41 +0100 |
I too tried contacting the vendor but received no response. Your timing of vendor notice and vul'n release are fast unfortunately. Taking a look, simple functions in PHP can be called upon to fix those issues.
thanks Paul for the cooperation : )
i'm sorry i hadn't updated the advisory but now i done
* * * *
VI. VENDOR RESPONSE
We had a response from Craig Knudsen, the project leader, on 20051128 night. The same day the fast Craig resolved 3 of the 4 issues in the REL_1_0_0 branch of CVS, so soon a new version (probably 1.0.2) will be released to the public.
* * * *
also on the sourceforge project site there are these posts related to this advisory (thanks Craig for the links)
http://sourceforge.net/forum/forum.php?thread_id=1392833&forum_id=11587 http://sourceforge.net/forum/forum.php?thread_id=1393468&forum_id=11587
http://sourceforge.net/mailarchive/forum.php?thread_id=9091328&forum_id=46247 http://sourceforge.net/mailarchive/forum.php?thread_id=9089995&forum_id=46247
ascii - http://www.ush.it _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] Re: WebCalendar Multiple Vulnerabilities, Paul Laudanski |
|---|---|
| Next by Date: | Re: [Full-disclosure] SOX whistleblowers' clause Compliance, Michael Holstein |
| Previous by Thread: | [Full-disclosure] Re: WebCalendar Multiple Vulnerabilities, Paul Laudanski |
| Next by Thread: | [Full-disclosure] SCOSA-2005.52 OpenServer 6.0.0 : KAME Racoon Daemon Denial of Service Vulnerability, security |
| Indexes: | [Date] [Thread] [Top] [All Lists] |