lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20090409103510.21274.qmail@securityfocus.com> Date: 9 Apr 2009 10:35:10 -0000 From: nospam@...il.it To: bugtraq@...urityfocus.com Subject: Geeklog <=1.5.2 'SESS_updateSessionTime()' vulnerability As the vendor stated, see: http://www.geeklog.net/article.php/geeklog-1.5.2sr2 geeklog is also vulnerable to this: http://www.securityfocus.com/bid/34361/info actually this should be renamed in glFusion 'SESS_updateSessionTime()' SQL Injection Vulnerability