Computer Security
[EN] securityvulns.ru
no-pyccku



Ikonboard crossite scripting
updated since 04.10.2002
Published:09.12.2002
Source:3APA3A
SecurityVulns ID:2327
Type:remote
Level:5/10
Description:[IMG]javascript:alert(document.cookie).gif[/IMG], Photo/javascript:alert(document.cookie) URL, Photo, X-Forwarded-For scripting.
Affected:IKONBOARD : Ikonboard 3.1
Original documentdocument3APA3A, Ikonboard 3.1.1 multiple crossite scriptings (09.12.2002)
 document3APA3A, SECURITY.NNOV: ikonboard 3.1.1 CSS (04.10.2002)
Discuss:Read or add your comments to this news (0 comments)

Multiple Microsoft Internet Explorer bugs
updated since 21.11.2002
Published:09.12.2002
Source:MICROSOFT
SecurityVulns ID:2425
Type:client
Level:7/10
Description:New cumulative patch fixes multiple bugs.
Affected:MICROSOFT : Internet Explorer 5.01
 MICROSOFT : Internet Explorer 5.5
 MICROSOFT : Internet Explorer 6.0
Original documentdocumentThor Larholm, Notes on MS02-068, extensive downplaying of severity (09.12.2002)
 documentMICROSOFT, Microsoft Security Bulletin MS02-068: Cumulative Patch for Internet Explorer (324929) (09.12.2002)
 documentMICROSOFT, Microsoft Security Bulletin MS02-066: Cumulative Patch for Internet Explorer (Q328970) (21.11.2002)
Discuss:Read or add your comments to this news (0 comments)

Microsoft Outlook DoS
Published:09.12.2002
Source:BUGTRAQ
SecurityVulns ID:2458
Type:client
Level:5/10
Description:Malformed mail headers causes Outlook to crash.
Affected:MICROSOFT : Outlook 2002
Original documentdocumentMICROSOFT, Microsoft Security Bulletin MS02-067: E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail (331866) (09.12.2002)
Discuss:Read or add your comments to this news (0 comments)

SAP privelege escalation
Published:09.12.2002
Source:BUGTRAQ
SecurityVulns ID:2459
Type:local
Level:5/10
Description:Relative path is used on external programm call.
Affected:SAP : SAP DB 7.4
Original documentdocumentKevin Finisterre, SAP database local root via symlink (09.12.2002)
Files:sapdb-server-linux-32bit-i386-7_3_0_29.tgz exploit
Discuss:Read or add your comments to this news (0 comments)

Microsoft Windows XP information leakage
Published:09.12.2002
Source:NTBUGTRAQ
SecurityVulns ID:2460
Type:remote
Level:5/10
Affected:MICROSOFT : Windows XP
Original documentdocumentSNS, [SNS Advisory No.60] Windows XP Disclosure of Registered AP Information (09.12.2002)
Discuss:Read or add your comments to this news (0 comments)

Buffer overflows in OpenLDAP2
Published:09.12.2002
Source:BUGTRAQ
SecurityVulns ID:2462
Type:library
Level:8/10
Description:Few serious buffer overflows.
Affected:OPENLDAP : OpenLDAP 2.0
Original documentdocumentSUSE, SuSE Security Announcement: OpenLDAP2 (SuSE-SA:2002:047) (09.12.2002)
Discuss:Read or add your comments to this news (0 comments)

TrendMicro InterScan VirusWall open proxy
Published:09.12.2002
Source:BUGTRAQ
SecurityVulns ID:2464
Type:remote
Level:5/10
Description:There is no limitation for CONNECT usage.
Affected:TRENDMICRO : Interscan VirusWall 3.6
Original documentdocumentVolker Tanger, Proxy vulnerability in TrendMicro InterScan-VirusWall V3.6 (09.12.2002)
Discuss:Read or add your comments to this news (0 comments)

Multiple akfingerd bugs
Published:09.12.2002
Source:BUGTRAQ
SecurityVulns ID:2465
Type:local
Level:5/10
Description:Symbolic links, undropped egid, DoS.
Affected:SYNFLOOD : akfingerd 0.5
Original documentdocumentGianni Tedesco, Multiple vulnerabilities in akfingerd (09.12.2002)
Discuss:Read or add your comments to this news (0 comments)

Sun Cobalt RaQ4 command execution
updated since 09.12.2002
Published:14.12.2002
Source:BUGTRAQ
SecurityVulns ID:2463
Type:remote
Level:7/10
Description:/cgi-bin/.cobalt/overflow/overflow.cgi allows command execution.
Affected:COBALT : RaQ4
Original documentdocumentCERT, CERT Advisory CA-2002-35 Vulnerability in RaQ 4 Servers (14.12.2002)
 documentgrazer_(at)_digit-labs.org, Cobalt RaQ4 Remote root exploit (09.12.2002)
Files:Cobalt RaQ4 Remote root exploit
Discuss:Read or add your comments to this news (0 comments)

CGI bugs
updated since 09.12.2002
Published:15.12.2002
Source:BUGTRAQ
SecurityVulns ID:2461
Type:remote
Level:5/10
Affected:JELSOFT : vBulletin 2.2
 PHPBB : phpBB 2.0
 UPB : Ultimate PHP Board 1.0
 XOOPS : Xoops RC3.0
 APBOARD : APBoard 2.02
 MAMBO : Mambo Site Server 4.0
 HALCYON : Instant ASP 1.0
 MYPHPSOFT : MyPHPLinks 2.1
 MYPHPSOFT : MyPHPLinks 2.2
Original documentdocumentVALDEUX_(at)_aol.com, Anyone can read all XOOPS private messages (14.12.2002)
 documentph33r, Advisory Title: iASP Remote Console Applet Allows Remote (14.12.2002)
 documenteuronymous, Multiple Mambo Site Server sec-weaknesses (14.12.2002)
 documentDorin Balanica, Input Validation Error in vbulletin 2.2.x (12.12.2002)
 documenteuronymous, XSS and Path Disclosure in UPB (09.12.2002)
 documentDNA ESC, APBoard-Bug (09.12.2002)
 documentFabricio Angeletti, Cross-site Scripting Vulnerability in phpBB 2.0.3 (09.12.2002)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru