Computer Security
[EN] securityvulns.ru
no-pyccku



Apple MacOS X Xcode OpenBase SQL privilege escalation
updated since 16.10.2006
Published:08.11.2006
Source:BUGTRAQ
SecurityVulns ID:6724
Type:local
Level:6/10
Description:On executing tar from suid root application TAR_OPTIONS environment variable is not unset, making it possible to execute any application with root privileges. External application are executed with relative path. Dynamic libraries are loaded with relative path. Symbolic links problem.
Affected:XCODE : Xcode OpenBase 9.1
 XCODE : Xcode OpenBase 10.0
Original documentdocumentKevin Finisterre, [Full-disclosure] OpenBase SQL multiple vulnerabilities Part Deux (08.11.2006)
Files:Exploits XCode OpenBase SQL symlink
 Xcode OpenBase <= 9.1.5 Local Root Exploit (OSX)
 Exploits XCode OpenBase SQL unsafe system() call
Discuss:Read or add your comments to this news (0 comments)

Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
Published:08.11.2006
Source:BUGTRAQ
SecurityVulns ID:6793
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:DIGIOZ : DigiOz Guestbook 1.7
 KAYAKO : Kayako SupportSuite 3.00
 SIMPLEPHOTOALBUM : Simple Photo Album 1.2
 C12 : C12 0.1
 DSIWARE : iWare Pro 5.0
 PHPADVENTURE : PHPAdventure 1.1
 SOHOLAUNCH : Soholaunch Pro 4.9
Original documentdocumentthe_day, [ECHO_ADV_58$2006]Cyberfolio <=2.0 RC1 $av Remote File Inclusion Vulnerability (08.11.2006)
 documentthe_day, [ECHO_ADV_57$2006]Soholaunch Pro <=4.9 r36 Multiple Remote File Inclusion Vulnerability (08.11.2006)
 documentHER0, PHPAdventure 1.1 (ad_main.php) Remote File Include Vulnerability (08.11.2006)
 documentnuffsaid, iWare Pro <= 5.0.4 (chat_panel.php) Remote Code Execution Vulnerability (08.11.2006)
 documentDr.Pantagon, vBlog / C12 0.1 (cfgProgDir) Remote File Include Vulnerabilities (08.11.2006)
 documentx0rax, iPrimal Forums Remote File Inclusion (08.11.2006)
 documentdurito, уязвимости Simple Photo Album - 1.2 и 2.5 (08.11.2006)
 documentnavairum_(at)_gmail.com, News publication system remote File include (08.11.2006)
 documentJesper Jurcenoks, DigiOz Guestbook version 1.7 Path Disclosure Vulnerability in list.php (08.11.2006)
 documentresearch_(at)_procheckup.com, Cross Site Scripting (XSS) Vulnerability in IBM WebSphere Application Server (08.11.2006)
Files:iPrimal Forums Users(ChangePass) 3xPl0!t
Discuss:Read or add your comments to this news (0 comments)

Lotus Notes information leak
Published:08.11.2006
Source:FULL-DISCLOSURE
SecurityVulns ID:6794
Type:remote
Level:6/10
Description:It's possible to check user existance and download certificate of new user with TCP/1352 port protocol.
Original documentdocumentAndrew Christensen, [Full-disclosure] Lotus Notes pre-login User.ID key leak (08.11.2006)
Files:Lotus Notes Port 1352 Pre-login Information Leakage
Discuss:Read or add your comments to this news (0 comments)

Lotus Domino tunekrnl utility buffer overflow
Published:08.11.2006
Source:FULL-DISCLOSURE
SecurityVulns ID:6795
Type:local
Level:5/10
Description:Multiple buffer overflows in suid utility.
Affected:IBM : Lotus Domino 6.5
 IBM : Lotus Domino 7.0
Original documentdocumentIDEFENSE, [Full-disclosure] iDefense Security Advisory 11.08.06: IBM Lotus Domino 7 tunekrnl Multiple Vulnerabilities (08.11.2006)
Discuss:Read or add your comments to this news (0 comments)

OmniNFS NFS server buffer overflow
Published:08.11.2006
Source:MILW0RM
SecurityVulns ID:6796
Type:remote
Level:5/10
Affected:OMNINFS : Omni-NFS Server 1.0
Files:Exploit for Omni-NFS Server stack overflow vulnerability (Metasploit)
Discuss:Read or add your comments to this news (0 comments)

Linux kernel IPv6 filtering bypass
Published:08.11.2006
Source:SECUNIA
SecurityVulns ID:6798
Type:remote
Level:6/10
Description:It's possible to bypass filtering by using fragmented packets.
Affected:LINUX : kernel 2.6
Original documentdocumentSECUNIA, [SA22731] Linux Kernel Fragmented IPv6 Packet Filtering Bypass (08.11.2006)
Discuss:Read or add your comments to this news (0 comments)

Multiple Mozilla Firefox / Thunderbird / Seamonkey security vulnerabilities
Published:08.11.2006
Source:MOZILLA
SecurityVulns ID:6797
Type:client
Level:8/10
Description:Memory corruption, javascript code spoofing, code execution. May be used for hidden malware installation.
Files:Mozilla Foundation Security Advisory 2006-64
 Mozilla Foundation Security Advisory 2006-66
 Mozilla Foundation Security Advisory 2006-67
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru