Section: .. / 0605-advisories /
| /// File Name: |
bitrixXSS.txt |
Description:
|
Bitrix CMS version 4.1.x suffers from cross site scripting flaws.
| | Author: | Gogi The Georgian | | File Size: | 1344 | | Last Modified: | May 22 01:58:51 2006 |
| MD5 Checksum: | 216b94b353385b193e1fbc1e0f116b09 |
|
| /// File Name: |
whatsupwiththat.txt |
Description:
|
Ipswitch What's Up Professional 2006 is vulnerable to a spoofing attack whereby the attacker can trick the application into thinking he/she is making a request from the console (which is considered trusted). This attack will allow the attacker to bypass the authentication mechanism of the application and login without credentials.
| | Author: | Kenneth F. Belva | | Homepage: | http://www.ftusecurity.com/ | | File Size: | 1326 | | Last Modified: | May 22 01:28:39 2006 |
| MD5 Checksum: | 5ae2438411d0ab8e2e5ec1d060e2f806 |
|
| /// File Name: |
Socketmail-2.2.6.txt |
Description:
|
Socketmail versions less than or equal to 2.2.6 suffer from a remote file inclusion vulnerability.
| | Author: | Aesthetico | | Homepage: | http://www.majorsecurity.de | | File Size: | 1303 | | Last Modified: | May 29 03:22:51 2006 |
| MD5 Checksum: | 03c2f9fe77314cf91a86a1e10e6d065d |
|
| /// File Name: |
dovecotIssue.txt |
Description:
|
Dovecot 1.0 beta is susceptible to an information disclosure flaw.
| | Author: | Timo Sirainen | | File Size: | 1291 | | Last Modified: | May 21 18:16:58 2006 |
| MD5 Checksum: | 9fd3fcfccd3eca5d2326c2d8bd2b341f |
|
| /// File Name: |
MDaemon-2.txt |
Description:
|
A Heap Overflow in the MDaemon IMAP Daemon has been discovered which may result in the execution of arbitrary code.
| | Author: | kingcope | | File Size: | 1290 | | Last Modified: | May 29 18:51:00 2006 |
| MD5 Checksum: | b30a1701e137180b1e0809e495ace6b7 |
|
| /// File Name: |
TamberForum-1.9.13.txt |
Description:
|
Tamber Forum versions less than or equal to 1.9.13 suffer from multiple SQL injection vulnerabilities.
| | Author: | ajannhwt | | File Size: | 1275 | | Last Modified: | May 29 03:17:53 2006 |
| MD5 Checksum: | d20700429ec24994f94e5386e66c3ba6 |
|
| /// File Name: |
coolphpmagazine.txt |
Description:
|
Multiple XSS vulnerabilities have been discovered in coolphp magazine.
| | Author: | Black-cod3 | | File Size: | 1234 | | Last Modified: | May 29 19:46:25 2006 |
| MD5 Checksum: | 92f78dac5fe58b7b8e2779a6ecef3a65 |
|
| /// File Name: |
destiney212.txt |
Description:
|
Destiney Links Script versions 2.1.2 is susceptible to cross site scripting and full path disclosure vulnerabilities.
| | Author: | luny | | File Size: | 1188 | | Last Modified: | May 23 04:20:38 2006 |
| MD5 Checksum: | a039d66f382d4fae34e735b825c65096 |
|
| /// File Name: |
applesafari203.txt |
Description:
|
A vulnerability exists in Apple Safari 2.0.3 (417.9.3) and perhaps in prior versions which shows up the SRCOD (Spinning Rainbow Cursor Of Death).
| | Author: | Yannick von Arx | | File Size: | 1158 | | Last Modified: | May 22 02:56:11 2006 |
| MD5 Checksum: | 6604f4348ea6f9ac439211f69d37901b |
|
| /// File Name: |
phpListPro-21.txt |
Description:
|
phpListPro versions less than or equal to 2.01 suffer from a remote file inclusion vulnerability.
| | Author: | Aesthetico | | Homepage: | http://www.majorsecurity.de | | File Size: | 1145 | | Last Modified: | May 17 02:48:05 2006 |
| MD5 Checksum: | b0a8a127c25e827ac1a9c65acaaa511f |
|
| /// File Name: |
ByteHoard-2.1.txt |
Description:
|
ByteHoard versions less than or equal to 2.1 suffers from directory transversal and XSS vulnerabilities.
| | Author: | Nomenumbra | | File Size: | 1116 | | Last Modified: | May 29 03:02:51 2006 |
| MD5 Checksum: | 1e8ab96e21863358d141774ce0050f29 |
|
| /// File Name: |
sunSingle.txt |
Description:
|
Single CPU Sun systems running Solaris 7, 8, and 9 are all susceptible to a simple denial of service attack using ping.
| | Author: | Doug Hughes | | File Size: | 1111 | | Last Modified: | May 22 01:43:15 2006 |
| MD5 Checksum: | 447de24872395999371a563c3568fe1c |
|
| /// File Name: |
xine0994.txt |
Description:
|
Xine version 0.99.4 appears susceptible to format string attacks.
| | Author: | KaDaL-X | | Homepage: | http://kandangjamur.net | | File Size: | 1109 | | Last Modified: | May 2 01:29:48 2006 |
| MD5 Checksum: | 35903154c046b291fd2cf40640e4f829 |
|
| /// File Name: |
RealtyProOne.txt |
Description:
|
Realty Pro One is vulnerable to SQL injection and XSS.
| | Author: | luny | | File Size: | 1097 | | Last Modified: | May 26 19:11:36 2006 |
| MD5 Checksum: | 02cd8e84ffc63fac9fc1575b86a7ea1f |
|
| /// File Name: |
KAPDA-44.txt |
Description:
|
[KAPDA::#44] - NewsCMSLite Login ByPass by Cookie Vulnerability
| | Homepage: | http://www.KAPDA.ir | | File Size: | 1090 | | Last Modified: | May 26 19:19:39 2006 |
| MD5 Checksum: | 99a15776b3644f3be85074602efae62e |
|
| /// File Name: |
rPSA-2006-0082-1.txt |
Description:
|
rPath Security Advisory: 2006-0082-1: In previous versions of the vixie-cron package, when the /etc/security/limits.conf file has been set up with limits for any user, and that user has permission to use the cron facility, that user can use vixie-cron to run arbitrary programs as root by exceeding the limits set in /etc/security/limits.conf.
| | Author: | Justin M. Forbes | | File Size: | 1061 | | Last Modified: | May 29 01:41:41 2006 |
| MD5 Checksum: | 8a35b584bd98552a0cccc7cf1e04f69b |
|
| /// File Name: |
ASPBB-0.52.txt |
Description:
|
ASPBB versions 0.52 and prior suffer from XSS.
| | Homepage: | http://www.nukedx.com | | File Size: | 1046 | | Last Modified: | May 29 04:04:27 2006 |
| MD5 Checksum: | f8c664427c8244d8c5af61095f5a4ac7 |
|
| /// File Name: |
rPSA-2006-0084-1.txt |
Description:
|
rPath Security Advisory: 2006-0084-1 Previous versions of fetchmail, when talking to a hostile (possibly compromised) mail server, are vulnerable to possible denial of service or user compromise.
| | Homepage: | http://rpath.com | | File Size: | 1044 | | Last Modified: | May 29 03:47:42 2006 |
| MD5 Checksum: | 7da148d0dd58c3d807e8a6e160239dc6 |
|
| /// File Name: |
rPSA-2006-0083-1.txt |
Description:
|
rPath Security Advisory: 2006-0083-1: Previous versions of the enscript package have weaknesses that may enable vulnerabilities in other applications; in particular, some print filters may call enscript while allowing the user to provide arbitrary filenames or options.
| | Homepage: | http://rpath.com | | File Size: | 1007 | | Last Modified: | May 29 03:46:50 2006 |
| MD5 Checksum: | 3d5c741ca9883e95d4b8140850a7092e |
|
| /// File Name: |
HackernetworkMail.txt |
Description:
|
Hackernetwork Mail suffers from XSS in the search parameter.
| | Author: | ajannhwt | | File Size: | 962 | | Last Modified: | May 26 18:13:44 2006 |
| MD5 Checksum: | b4f626249f8b4e3f0691cec28a533e8f |
|
| /// File Name: |
msinfotech.txt |
Description:
|
Microsoft Infotech Storage System Library (itss.dll) is prone to a heap corruption vulnerability. This issue is due to the failure of the library to properly check a specially crafted CHM file. The successful exploitation of this flaw would allow to execute arbitrary code.
| | Homepage: | http://www.reversemode.com | | Related Exploit: | ONE.zip | | File Size: | 947 | | Last Modified: | May 21 13:59:22 2006 |
| MD5 Checksum: | 105a2e8e5a135685edc33b473a809b2e |
|
| /// File Name: |
iFdatev1.2.txt |
Description:
|
iFdate v1.2 suffers from XSS
| | Author: | luny | | File Size: | 940 | | Last Modified: | May 26 19:16:36 2006 |
| MD5 Checksum: | 0f4a0a87e44e29af66c949b547e1455c |
|
| /// File Name: |
KAPDA-46.txt |
Description:
|
KAPDA advisory #46: Nukedit v4.9.6 and prior - Unauthorized Admin Add vulnerability
| | Homepage: | http://www.KAPDA.ir | | File Size: | 928 | | Last Modified: | May 29 20:01:17 2006 |
| MD5 Checksum: | d03faddc98dc7d04304fab0d12351ad6 |
|
| /// File Name: |
frontrange.txt |
Description:
|
A vulnerability has been found in FrontRange's iHeat product that allows users to gain access to the host machine through a logged on session or execute arbitrary code while using the active-x version of the product.
| | Author: | mcdanielar | | File Size: | 906 | | Last Modified: | May 22 00:53:45 2006 |
| MD5 Checksum: | 3930de7b6639f468bad899da506e7944 |
|
|
|
|
|