 |
|
|
|
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 13.02.2006 | | Source: |  | | | SecurityVulns ID: |  | 5760 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Original document |  | SECUNIA, [SA18810] Ansilove File Disclosure and File Upload Vulnerabilities (13.02.2006) |
| |  | SECUNIA, [SA18804] Siteframe "q" Cross-Site Scripting Vulnerability (13.02.2006) |
| |  | SECUNIA, [SA18805] DB_eSession "deleteSession()" Function SQL Injection (13.02.2006) |
| |  | SECUNIA, [SA18819] WebGUI User Account Creation Vulnerability (13.02.2006) |
| |  | SECUNIA, [SA18821] XMB Forums today.php Cookie Data SQL Injection (13.02.2006) |
| |  | SECUNIA, [SA18820] PHP-Nuke "pagetitle" Cross-Site Scripting Vulnerability (13.02.2006) |
| |  | SECUNIA, [SA18816] e107 Unspecified BBCode Script Insertion Vulnerabilities (13.02.2006) |
| |  | SECUNIA, [SA18803] DocMGR process.php File Inclusion Vulnerability (13.02.2006) |
| |  | God Of Death (G.O.D), [Full-disclosure] XSS in PlaySMS (13.02.2006) |
| |  | JeiAr, Linpha <= 1.0 multiple arbitrary local inclusion (13.02.2006) |
| |  | JeiAr, HiveMail <= 1.3 Multiple Vulnerabilities (13.02.2006) |
| |  | zjieb_(at)_hotmail.com, imageVue16.1 upload vulnerability (13.02.2006) |
| |  | Aliaksandr Hartsuyeu, [eVuln] phpht Topsites Multiple Vulnerabilities (13.02.2006) |
| |  | Aliaksandr Hartsuyeu, [eVuln] phphg Guestbook Multiple Vulnerabilities (13.02.2006) |
| |  | Aliaksandr Hartsuyeu, [eVuln] GuestBookHost Authentication Bypass (13.02.2006) |
| |  | rgod_(at)_autistici.org, runCMS <= 1.3a2 possible remote code execution through the integrated FCKEditor package (13.02.2006) |
| |  | Aliaksandr Hartsuyeu, [eVuln] Unknown Domain Shoutbox multiple XSS & SQL Injection Vulnerabilities (13.02.2006) |
| |  | Roman Medina, [VulnWatch] RS-2006-1: Multiple flaws in VHCS 2.x (13.02.2006) |
| |  | SecuBox fRoGGz, Invision Power Board Army System Mod <= 2.1 SQL Injection Exploit (13.02.2006) |
| |  | JeiAr, CPAINT AJAX Library Cross Site Scripting (13.02.2006) |
| BlackBerry Enterprise Server buffer overflow | | Published: |  | 13.02.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 5762 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Buffer overflow on corrupted MS Word attachments. |
| D-Link / US Robotics multiple wireless access points DoS | | Published: |  | 13.02.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 5763 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | Fragmented sequential UDP packets causes device to reboot. |
| HP Systems Insight Manager directory traversal | | Published: |  | 13.02.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 5765 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Multiple vulnerabilities allow to obtain any file from server. |
| SUSE Linux privilege escalation | | Published: |  | 13.02.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 5761 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | Multiple packages are erroneously compiled in a way dynamic libraries are loaded from current directory. |
| FortiGate application level firewall protection bypass | | Published: |  | 13.02.2006 | | Source: |  | FULL-DISCLOSURE | | SecurityVulns ID: |  | 5764 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | URL filtering may be bypassed. FTP traffic is not virus checked. |
| Multiple pam_mysql security vulnerabilities | | Published: |  | 13.02.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 5767 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | DoS and double free() bug. |
Multiple Hitachi Business Logic vulnerabilities updated since 27.12.2005 | | Published: |  | 13.02.2006 | | Source: |  | SECUNIA | | SecurityVulns ID: |  | 5575 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | SQL injection, crossite scripting, etc. |
noweb symbolic links problem updated since 21.06.2003 | | Published: |  | 13.02.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 2918 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Symbolic links problem on temporary files creation. |
Microsoft Internet Explorer Drag-and-Drop code execution updated since 13.02.2006 | | Published: |  | 14.02.2006 | | Source: |  | SECURITEAM | | SecurityVulns ID: |  | 5766 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | By spoofing target window in race period it's possible to install malware in special folder. Vulnerability may be exploited for trojaning user's machine, but requires interaction. |
|
|
|
|
|
|
|
|