Computer Security
[EN] securityvulns.ru
no-pyccku



Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
updated since 12.05.2009
Published:13.05.2009
Source:BUGTRAQ
SecurityVulns ID:9904
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:SQUIRRELMAIL : squirrelmail 1.4
 BIGACE : Bigace CMS 2.5
 FORMMAIL : FormMail 1.92
 BITWEAVER : Bitweaver 2.6
 AJAXTERM : AjaxTerm 0.10
 AAS : Application Access Server 2.0
 MAXCMS : maxcms 2.0
 FAMILYCONNECTION : Family Connections 1.9
CVE:CVE-2009-1581 (functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.)
 CVE-2009-1580 (Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie.)
 CVE-2009-1579 (The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.)
 CVE-2009-1578 (Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).)
 CVE-2009-1466 (Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which allows local users to obtain sensitive information by reading this file.)
 CVE-2009-1465 (Application Access Server (A-A-S) 2.0.48 has "wildbat" as its default password for the admin account, which makes it easier for remote attackers to obtain access.)
 CVE-2009-1464 (Multiple cross-site request forgery (CSRF) vulnerabilities in index.aas in Application Access Server (A-A-S) 2.0.48 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary programs via a command job, (2) stop services via a setservice job, or (3) terminate processes via a killprocess job.)
Original documentdocumentMANDRIVA, [ MDVSA-2009:110 ] squirrelmail (13.05.2009)
 documenty3nh4ck3r_(at)_gmail.com, (GET var 'member') BLIND SQL INJECTION EXPLOIT --FAMILY CONNECTIONS <= v1.9 --> (13.05.2009)
 documentinfo_(at)_securitylab.ir, maxcms2.0 creat new admin exploit (13.05.2009)
 documentFelipe M. Aragon, Syhunt: A-A-S (Application Access Server) Multiple Security Vulnerabilities (13.05.2009)
 documentAndrea Barisani, [oCERT-2009-004] AjaxTerm session id collision (12.05.2009)
 documenty3nh4ck3r_(at)_gmail.com, (POST var 'rating') BLIND SQL INJECTION--microTopic v1 Initial Release--> (12.05.2009)
 documentrgod, Bitweaver <= 2.6 /boards/boards_rss.php / saveFeed() remote code execution exploit (12.05.2009)
 documentascii, FormMail 1.92 Multiple Vulnerabilities (12.05.2009)
 documenty3nh4ck3r_(at)_gmail.com, User options changer (SQLi) EXPLOIT --Bigace CMS -stable release- 2.5--> (12.05.2009)
Files:maxcms2.0 create new admin exploit
 User options changer (SQLi) EXPLOIT --Bigace CMS -stable release- 2.5
 (POST var 'rating') BLIND SQL INJECTION--microTopic v1 Initial Release
 (GET var 'member') BLIND SQL INJECTION EXPLOIT --FAMILY CONNECTIONS <= v1.9
 Bitweaver <= 2.6 /boards/boards_rss.php / saveFeed() remote code execution exploit
Discuss:Read or add your comments to this news (0 comments)


Show Threads
Messages
 
Login:* (Register)
Password:*
(private) To:
(reply) Subject:*
Text:

Main Forum (Eng)

General security questions not appropriate for another forums.
3proxy Forum (Eng)

All 3proxy question must be posted to this forum.
Bugs, Vulnerabilities, PoCs and Exploits (Eng)

All vulnerability related questions, vulnerability digging and exploit creation.
Windows programming and administration (Eng)

Administering Windows and application development.
Unix programming and administation (Eng)

Administering Unix and application development.
Test forum

Please post all test messages here. All test messages from different forums will be deteted.
Main Forum (Rus)
3proxy Forum (Rus)
Bugs, Vulnerabilities, PoCs and Exploits (Rus)
Windows programming and administration (Rus)
Unix programming and administation (Rus)
About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server