Multiple Linksys/ ZyXel / Edimax / Sitecom routers UPnP problems
updated since 23.05.2006
Description:UPnP AddPortMapping request requires no authentication. It makes it possible to create mapping between any external port and internal IP/port. Additionally, insufficient paramters validation allows code execution on router itself.
Affected:LINKSYS : WRT54G
 ZYXEL : P-335WT
 EDIMAX : BR-6104K
SECUNIA, [SA22326] Linksys WRT54GXv2 Insecure Universal Plug and Play Configuration (14.10.2006)
How does the UPnP flaw works

Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:PHPBB : phpBB SpamBlocker Mod 1.0
 SPAMOBORONA : SpamOborona PHPBB Plugin
 PHPBB : phpBB Security mod 1.0
 PHPBB : phpBB news defilante horizontale mod 4.1
 PHPBB : phpBB lat2cyr mod 1.0
 PHPBB : phpBB RPG Events mod 1.0
 BUZLAS : phpBB Buzlas mod 2006-1
 BLOQ : Bloq 0.5
 MORCEGO : Morcego CMS 0.9
 PHPCARDS : PHP Cards 1.3
 mnews : MNews 2.0
 GCONTACT : Gcontact 0.6
 EXLOR : EXlor 1.0
Apache web server mod_tcl security vulnerability
SecurityVulns ID:6719
Description:Server format string vulnerabilities with HTTP request header names.
Affected:APACHE : mod_tcl 1.0
IDEFENSE, [VulnWatch] iDefense Security Advisory 10.13.06: Apache HTTP Server mod_tcl set_var Format String Vulnerability (14.10.2006)

Macromedia Breeze directory traversal
SecurityVulns ID:6720
Threat Level:
Affected:ADOBE : Macromedia Breeze 5.0
 ADOBE : Macromedia Breeze 5.1
SECUNIA, [SA22327] Macromedia Breeze URL Parsing Information Disclosure (14.10.2006)

