[Full-disclosure] Panda ActiveScan 2.0 remote code execution

Panda Security Response secure at pandasecurity.com
Fri Jul 4 12:02:13 BST 2008


Please allow at least one week for us to respond before public disclousure. We only received this information a few days ago.

Regards,

----------------------------------------------
Pedro Bustamante
Senior Research Advisor
Panda Security

email: pedro.bustamante at pandasecurity.com <0xC684A6F9>
vulns: secure at pandasecurity.com <0x70F3FEA0>
phone: (+34) 91-8063700
blog:  http://research.pandasoftware.com 
----------------------------------------------


 

> -----Mensaje original-----
> De: full-disclosure-bounces at lists.grok.org.uk 
> [mailto:full-disclosure-bounces at lists.grok.org.uk] En nombre 
> de Karol Wiesek
> Enviado el: Saturday, July 05, 2008 11:59 AM
> Para: full-disclosure at lists.grok.org.uk
> Asunto: [Full-disclosure] Panda ActiveScan 2.0 remote code execution
> 
> http://karol.wiesek.pl/files/panda.tgz
> 
> K.
> 
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
> 
> 




Full-Disclosure is hosted and sponsored by Secunia.