Re: -==phpBB 2.0.14 Multiple Vulnerabilities==-
Paul Laudanski <[email protected]> Sat, 23 Apr 2005 18:09:13 -0400 (EDT)
| Newsgroups | gmane.comp.security.full-disclosure,gmane.comp.security.bugtraq,gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <Pine.LNX.4.44.0504231806120.20043-100000@bugsbunny.castlecops.com> |
On 23 Apr 2005, HaCkZaTaN wrote: > > > /* > -------------------------------------------------------- > [N]eo [S]ecurity [T]eam [NST]® - Advisory #14 - 17/04/05 > -------------------------------------------------------- > Program: phpBB 2.0.14 > Homepage: http://www.phpbb.com > Vulnerable Versions: phpBB 2.0.14 & Lower versions > Risk: Low Risk!! > Impact: Multiple Vulnerabilities. > > -==phpBB 2.0.14 Multiple Vulnerabilities==- Unsure if its me, but I didn't see a vendor notification here? Might be because I'm so happy being a proud new dad, but, I thought proper disclosure etiquette involved vendor notification and time to test properly, and waiting for a patch to be released? Whatever happened to that? -- Sincerely, Paul Laudanski .. Computer Cops, LLC. Microsoft MVP Windows-Security 2005 CastleCops(SM)... http://castlecops.com CC Blog ......... http://blog.castlecops.com Staff Blogs ..... http://busterbunny.castlecops.com Our Vision ...... http://castlecops.com/postt63382.html MSMVPS Blog ..... http://msmvps.com/castlecops http://cuddlesnkisses.com http://justalittlepoke.com http://zhen-xjell.com ________ Information from Computer Cops, L.L.C. ________ This message was checked by NOD32 Antivirus System for Linux Mail Server. part000.txt - is OK http://castlecops.com _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/