Section: .. / 0610-advisories /
| /// File Name: |
AsbruHardCore.txt |
Description:
|
Asbru HardCore Web Content Editor is vulnerable to a command injection attack vulnerability.
| | Author: | n.runs GmbH | | Homepage: | http://www.nruns.com/ | | File Size: | 3235 | | Last Modified: | Oct 20 18:24:00 2006 |
| MD5 Checksum: | b1b10c6dd09ed0642b39a6c420e53e4e |
|
| /// File Name: |
netflix-10-16-2006.txt |
Description:
|
The Netflix.com site was vulnerable to cross site request forgery, also known as hostile linking.
| | Author: | Dave Ferguson | | File Size: | 5939 | | Last Modified: | Oct 20 18:20:41 2006 |
| MD5 Checksum: | 0e5c0976e603dfc0719895feab5145c4 |
|
| /// File Name: |
ISSBlackICE-files.txt |
Description:
|
BlackICE PC Protection protects its files against manipulation by malicious software. Its critical files like its database of trusted applications or firewall configuration are protected. The list of protected files is stored in filelock.txt in the BlackICE installation directory. If this file is deleted files mentioned in filelock.txt are not protected any more and can be changed by malicious applications. The implemented protection allows malicious applications to delete this file using native API function ZwDeleteFile. This can result in a bypass of all BlackICE protection mechanisms because its internal components can be replaced with fake copies. The situation is even easier for the attacker because the component control fails to recognize fake components in BlackICE processes.
| | Author: | Matousec - Transparent security Research | | Homepage: | http://www.matousec.com/info/advisories/ | | File Size: | 1364 | | Last Modified: | Oct 20 18:05:08 2006 |
| MD5 Checksum: | f1b6a94fd588d266cf0b8bcf7573409f |
|
| /// File Name: |
ViewVC-1.0.2.txt |
Description:
|
It was discovered that ViewVC is neither sending a charset HTTP header nor specifying a charset in the HTML body. Therefore it is possible to trick several browsers into decoding ViewVC pages UTF-7. This allows attackers to inject arbitrary UTF-7 encoded Java-Script code into the output.
| | Homepage: | http://www.hardened-php.net/ | | File Size: | 3024 | | Last Modified: | Oct 20 18:02:42 2006 |
| MD5 Checksum: | 782c691f37fbc2fb4e39c1d46e5ebccf |
|
| /// File Name: |
Bugzilla-multiple.txt |
Description:
|
Security Advisory for Bugzilla 2.18.5, 2.20.2, 2.22, and 2.23.2: This advisory covers six security issues that have recently been fixed in the Bugzilla code.
| | Homepage: | http://www.bugzilla.org/ | | File Size: | 7448 | | Last Modified: | Oct 20 17:48:07 2006 |
| MD5 Checksum: | 79040ad91bd42ebe730fd28aea31b4d3 |
|
| /// File Name: |
objectpackager.txt |
Description:
|
Deatils on spoofing the security dialog in Windows object packager.
| | Author: | seejay.11 | | File Size: | 576 | | Last Modified: | Oct 20 17:41:50 2006 |
| MD5 Checksum: | 712469e63518bb27375a3f1737002e8e |
|
| /// File Name: |
Armorize-ADV-2006-0005.txt |
Description:
|
Armorize-ADV-2006-0005 discloses multiple cross-site scripting vulnerabilities that are found in Gcontact, which is a Web based address book written in Ajax/PHP offering multi-user, multi-contacts (email,phone,icq,msn,...) & multi-address for each person, birthday reminder by email, mailing-list management, Excel export, etc.
| | Author: | Armorize | | Homepage: | http://www.armorize.com | | File Size: | 1904 | | Last Modified: | Oct 20 17:32:46 2006 |
| MD5 Checksum: | 872cee9929c7a8de21cbecd0789861f8 |
|
| /// File Name: |
Armorize-ADV-2006-0003.txt |
Description:
|
Armorize-ADV-2006-0003 discloses multiple cross-site scripting vulnerabilities that are found in Zen Cart, which is a PHP e-commerce shopping program and is Built on a foundation of OScommerce GPL code. It provides an easy-to-setup and run online store.
| | Author: | Armorize | | Homepage: | http://www.armorize.com | | File Size: | 2263 | | Last Modified: | Oct 20 17:32:22 2006 |
| MD5 Checksum: | 3f431164425f059247d2ce46ba3fda1c |
|
| /// File Name: |
SYMSA-2006-010.txt |
Description:
|
Symantec Vulnerability Research SYMSA-2006-010: The web server under IronWebMail employs a simple macro language for evaluating pathname references. A loss of confidentiality occurs as a result of faulty pathname evaluation, causing unauthenticated access violation.
| | Author: | Derek Callaway | | Homepage: | http://www.symantec.com/research | | File Size: | 5992 | | Last Modified: | Oct 20 17:26:34 2006 |
| MD5 Checksum: | f80924ec3229b0f9565314e62d85fa43 |
|
| /// File Name: |
10.13.06.txt |
Description:
|
iDefense Security Advisory 10.13.06 - Remote exploitation of a format string vulnerability in the mod_tcl module for the Apache httpd v2.x could allow attackers to execute arbitrary code in the context of the httpd.
| | Homepage: | http://www.idefense.com/intelligence/vulnerabilities/ | | File Size: | 3574 | | Last Modified: | Oct 20 17:21:59 2006 |
| MD5 Checksum: | a98acf4b15148b8483385b4d7bcd4496 |
|
| /// File Name: |
sa22380.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Qt, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/22380/ | | File Size: | 2284 | | Last Modified: | Oct 20 16:09:23 2006 |
| MD5 Checksum: | 1b115525987db42a5d00f45fa75f43e3 |
|
| /// File Name: |
sa22398.txt |
Description:
|
Secunia Security Advisory - glukreal has reported a vulnerability in Casinosoft Casino Script, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/22398/ | | File Size: | 2357 | | Last Modified: | Oct 20 16:09:23 2006 |
| MD5 Checksum: | dc16841d3a5950518f69b04488a0093f |
|
| /// File Name: |
sa22407.txt |
Description:
|
Secunia Security Advisory - landseer has reported a vulnerability in dbc CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/22407/ | | File Size: | 2216 | | Last Modified: | Oct 20 16:09:23 2006 |
| MD5 Checksum: | c2a65ccb47290797e78d61ee520039bf |
|
| /// File Name: |
sa22408.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Blackberry Enterprise Server for Domino, which can be exploited by malicious users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/22408/ | | File Size: | 2436 | | Last Modified: | Oct 20 16:09:23 2006 |
| MD5 Checksum: | f5bcb8c715632438464179f4ce264688 |
|
| /// File Name: |
sa22410.txt |
Description:
|
Secunia Security Advisory - Matdhule has reported a vulnerability in OpenDock Full Core, which can be exploited by malicious users to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22410/ | | File Size: | 2266 | | Last Modified: | Oct 20 16:09:23 2006 |
| MD5 Checksum: | 2e17d6201016d910d4d98a0677d02b13 |
|
| /// File Name: |
sa22415.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in WIMS, which can be exploited by malicious users to manipulate data.
| | Homepage: | http://secunia.com/advisories/22415/ | | File Size: | 2130 | | Last Modified: | Oct 20 16:09:23 2006 |
| MD5 Checksum: | 4cf656db9fb3677d1a517f286527237d |
|
| /// File Name: |
sa22433.txt |
Description:
|
Secunia Security Advisory - disfigure has reported a vulnerability in Comdev Web Blogger, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22433/ | | File Size: | 2285 | | Last Modified: | Oct 20 16:09:23 2006 |
| MD5 Checksum: | 7469a23e775a2d8ee697d0693e4e4ad0 |
|
| /// File Name: |
sa22459.txt |
Description:
|
Secunia Security Advisory - disfigure has reported a vulnerability in Comdev Form Designer, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22459/ | | File Size: | 2291 | | Last Modified: | Oct 20 16:09:23 2006 |
| MD5 Checksum: | 2187f55c673c21b62b0004e826f0f89f |
|
| /// File Name: |
sa22462.txt |
Description:
|
Secunia Security Advisory - Mu Security has reported a vulnerability in XORP, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/22462/ | | File Size: | 2340 | | Last Modified: | Oct 20 16:09:23 2006 |
| MD5 Checksum: | 49c2e0cf30ce8797e5b27159dc4c2e74 |
|
| /// File Name: |
sa22464.txt |
Description:
|
Secunia Security Advisory - disfigure has reported a vulnerability in Comdev Forum, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22464/ | | File Size: | 2267 | | Last Modified: | Oct 20 16:09:23 2006 |
| MD5 Checksum: | 551ecfb741e47896fcfe6b5cd3f94659 |
|
| /// File Name: |
sa22467.txt |
Description:
|
Secunia Security Advisory - Rapid7 has reported some vulnerabilities in Adobe Flash Player, which can be exploited by malicious people to bypass certain restrictions.
| | Homepage: | http://secunia.com/advisories/22467/ | | File Size: | 2689 | | Last Modified: | Oct 20 16:09:23 2006 |
| MD5 Checksum: | 786156ae64359faeeffa9e3125620dfd |
|
| /// File Name: |
sa22468.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Maarch, which can be exploited by malicious users to disclose certain sensitive information.
| | Homepage: | http://secunia.com/advisories/22468/ | | File Size: | 2153 | | Last Modified: | Oct 20 16:09:23 2006 |
| MD5 Checksum: | 21f566e3ad83f420d8475dad0e1467d0 |
|
| /// File Name: |
sa22470.txt |
Description:
|
Secunia Security Advisory - disfigure has reported a vulnerability in Comdev Misc Tools, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22470/ | | File Size: | 2282 | | Last Modified: | Oct 20 16:09:23 2006 |
| MD5 Checksum: | 9bf2417fb368b3c051fc92844b1a6ca2 |
|
| /// File Name: |
sa22471.txt |
Description:
|
Secunia Security Advisory - nuffsaid has reported some vulnerabilities in phpPowerCards, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22471/ | | File Size: | 2267 | | Last Modified: | Oct 20 16:09:23 2006 |
| MD5 Checksum: | 145a95851613c6f4fbb6148d054b0cbc |
|
|
|
|
|