Computer Security
[EN] securityvulns.ru
no-pyccku



Web applications security vulnerabilities (PHP, ASP, CGI, Perl, etc)
updated since 31.10.2005
Published:05.11.2005
Source:
SecurityVulns ID:5396
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:PHPBB : phpBB 2.0
 VBULLETIN : vBulletin 3.0
 MAMBOSERVER : Mambo Server 4.5
 INVISION : Invision Power Board 2.0
 VCARD : vCard 2.9
 SNITZ : Snitz Forums 2000 3.4
 JPORTAL : Jportal 2.3
 CPANEL : cPanel 10.2
 MAILWATCH : MailWatch for MailScanner 1.0
 SIMPLEPHP : Simple PHP Blog 0.4
 CUREPHP : CuteNews 1.4
 INVISION : Invision Gallery 2.0
 OABOARD : OaBoard 1.0
 ELITEFORUM : Elite Forum 1.0
 SUBDREAMER : Subdreamer 2.2
 MG2 : MG2 0.5
 EYEOS : eyeOS 0.8
 BEMOORE : News2Net
 VUBB : VUBB
 RINGTAIL : CaseBook 6.1
 PHPHANDICAPPER : PHP HANDICAPPER
 MOVABLETYPE : Movable Type 3.16
 PHPWEBTHINGS : phpWebThings 0.4
 PHPWEBTHINGS : PHPWebthings 1.4
 JELSOFT : vBulletin 3.5
 CPANEL : cPanel 10.6
Original documentdocumentTim Brown, Portcullis Security Advisory - Movable Type (09.02.2007)
 documentSECUNIA, Secunia Research: cPanel Entropy Chat Script Insertion Vulnerability (05.11.2005)
 documentAnti Matter, [Full-disclosure] Invision Power Board Privilege Escalation (2.0.1 + more) (05.11.2005)
 documentSECUNIA, [SA17359] vBulletin Image Script Insertion Vulnerability (04.11.2005)
 documentSECUNIA, [SA17410] phpWebThings "forum" SQL Injection Vulnerability (04.11.2005)
 documentSECUNIA, [SA17405] MailWatch for MailScanner Two Vulnerabilities (04.11.2005)
 documenttHe cReW, [Full-disclosure] H4-CREW-000003 Advirosy: Superclick XSS via popup.php (04.11.2005)
 documentNomen Nescio, [Full-disclosure] Buggy blogging (04.11.2005)
 documentalireza hassani, Mambo Open Source, Path disclosure (04.11.2005)
 documentretrogod_(at)_aliceposta.it, CuteNews 1.4.1 remote code execution (04.11.2005)
 documentmousehack, JPORTAL Multiple SQL Injection (04.11.2005)
 documentNenad Jovanovic, Simple PHP Blog: Multiple XSS Vulnerabilities (03.11.2005)
 documentmousehack, PHP HANDICAPPER Multiple Vulnerability (03.11.2005)
 documentSECUNIA, [SA17383] Ringtail CaseBook Cross-Site Scripting and Username Enumeration (02.11.2005)
 documentSECUNIA, [SA17385] Snitz Forums 2000 "post.asp" Cross-Site Scripting Vulnerability (02.11.2005)
 documentalireza hassani, VUBB XSS & path disclosure Vulnerabilities (02.11.2005)
 documentmousehack, News2Net SQL Injection (02.11.2005)
 documentSECUNIA, [SA17105] eyeOS Script Insertion and Exposure of User Credentials (01.11.2005)
 documentSECUNIA, [SA17387] ASP Fast Forum "error" Cross-Site Scripting Vulnerability (01.11.2005)
 documentSECUNIA, [SA17378] Subdreamer Login SQL Injection Vulnerabilities (01.11.2005)
 documenth4cky0u, [Full-disclosure] HYSA-2005-009 Elite Forum 1.0.0.0 XSS Vulnerability (01.11.2005)
 documentabducter_minds_(at)_yahoo.com, SQL IN FORUM.PHP (01.11.2005)
 documentalmaster_(at)_hotmail.com, SQL In Invision Gallery 2.0.3 (01.11.2005)
 documentStefan Esser, [Full-disclosure] Advisory 17/2005: phpBB Multiple Vulnerabilities (31.10.2005)
 documentsQl_(at)_hotmail.com, uplod phpshell in PHP Advanced Transfer Manager (31.10.2005)
 documentx_(at)_hotmail.com, Remote File Inclusion in vCard :) (31.10.2005)
 documentPreben Nylokken, Vulnerability in MG2 php based Image Gallery - bypass security, view password protected images (31.10.2005)
Discuss:Read or add your comments to this news (1 comments)

Sun Java Development Toolkit DoS
Published:05.11.2005
Source:BUGTRAQ
SecurityVulns ID:5422
Type:library
Level:5/10
Description:Crash on font deserialization.
Affected:SUN : JDK 1.4
 SUN : JDK 1.5
 JBOSS : JBoss 4.0
Original documentdocumentMarc Schoenefeld, Remotely DoSing JBoss 4.0.2 with serialized java objects (05.11.2005)
Discuss:Read or add your comments to this news (0 comments)

thttpd symbolic links problem
Published:05.11.2005
Source:BUGTRAQ
SecurityVulns ID:5423
Type:remote
Level:5/10
Description:syslogtocern script insecure temporary files creation.
Affected:THTTPD : thttpd 2.21
Original documentdocumentDEBIAN, [SECURITY] [DSA 883-1] New thttpd packages fix insecure temporary file (05.11.2005)
Discuss:Read or add your comments to this news (0 comments)

SUSE linux chfn utility privilege escalation
Published:05.11.2005
Source:BUGTRAQ
SecurityVulns ID:5424
Type:local
Level:6/10
Description:Gecos field is not checked, making it possible to add records to password file.
Affected:SUSE : SUSE LINUX 9.3
 SUSE : SUSE LINUX 10.0
 SUSE : SUSE LINUX 9.2
 SUSE : SUSE LINUX 9.1
 SUSE : SUSE LINUX 9.0
 SUSE : SuSE Linux Desktop 1.0
 SUSE : SuSE Linux Enterprise Server 8
 SUSE : SUSE SLES 9
 SUSE : UnitedLinux 1.0
Original documentdocumentSUSE, SUSE Security Announcement: pwdutils, shadow (SUSE-SA:2005:064) (05.11.2005)
Discuss:Read or add your comments to this news (0 comments)

Multiple IBM Lotus Domino communication server vulnerabilities
Published:05.11.2005
Source:SECUNIA
SecurityVulns ID:5427
Type:remote
Level:5/10
Description:Array overflow on creating mail rules, buffer overflow on out-of-office autoreplies, multiple DoS conditions.
Affected:IBM : Lotus Domino 6.5
Original documentdocumentSECUNIA, [SA17429] IBM Lotus Domino Denial of Service and Unspecified Vulnerabilities (05.11.2005)
Discuss:Read or add your comments to this news (0 comments)

GpsDrive friendsd2 GPS map location service format string bug
Published:05.11.2005
Source:BUGTRAQ
SecurityVulns ID:5425
Type:remote
Level:5/10
Description:Format string bug on diagnostic message gisplaying.
Affected:GPSDRIVE : gpsdrive 2.09
Original documentdocumentKevin Finisterre, [Full-disclosure] DMA[2005-1104a] - 'GpsDrive friendsd2 format string vulnerability' (05.11.2005)
Files:GpsDrive friendsd2 format string vulnerability exploit - PPC
 GpsDrive friendsd2 format string vulnerability exploit - x86
Discuss:Read or add your comments to this news (0 comments)

Macromedia Flash Player array index overflow
updated since 05.11.2005
Published:07.11.2005
Source:FULL-DISCLOSURE
SecurityVulns ID:5426
Type:client
Level:7/10
Description:User controlled value is used as function pointers array index without boundary control.
Affected:MICROSOFT : Internet Explorer 5.5
 MICROSOFT : Internet Explorer 6.0
 MACROMEDIA : Flash Player 6.0
 NETSCAPE : Netscape 7.2
 OPERA : Opera 8.0
 NETSCAPE : Netscape 8.0
 ADOBE : Flash Player 7.0
Original documentdocumentSECUNIA, [SA17437] Opera Macromedia Flash Player SWF Arbitrary Code Execution (07.11.2005)
 documentSECUNIA, [SA17481] Internet Explorer Macromedia Flash Player SWF Arbitrary Code Execution (07.11.2005)
 documentDaniel Fabian, [Full-disclosure] SEC Consult SA-20051107-1 :: Macromedia Flash Player ActionDefineFunction Memory Corruption (07.11.2005)
 documentJuha-Matti Laurio, Netscape Flash Player Arbitrary Code Execution Vulnerability (07.11.2005)
 documentEEYE, [Full-disclosure] [EEYEB-20050627B] Macromedia Flash Player Improper Memory Access Vulnerability (05.11.2005)
Files:MPSB05-07 Flash Player ActionDefineFunction Memory Corruption test file
 Macromedia Flash Plugin - Buffer Overflow in flash.ocx
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru