 |
|
|
|
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 16.02.2007 | | Source: |  | | | SecurityVulns ID: |  | 7252 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Affected: |  | WORDPRESS : WordPress 2.0 | | |  | CEDSTAT : CedStat 1.31 | | |  | TURUNCU : Turuncu Portal 1.0 | | |  | MEGANOIDE : Meganoide's news 1.1 | | CVE: |  | CVE-2007-1057:TheNetDirect | | |  | CVE-2007-1046 (Dem_trac allows remote attackers to read log file contents via a direct request for /anc_sit.txt.) | | |  | CVE-2007-1044 (Pearson Education PowerSchool 4.3.6 allows remote attackers to list the contents of the admin folder via a URI composed of the admin/ directory name and an arbitrary filename ending in ".js.") | | |  | CVE-2007-1024 (PHP remote file inclusion vulnerability in include.php in Meganoide's news 1.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter.) | | |  | CVE-2007-1022 (SQL injection vulnerability in h_goster.asp in Turuncu Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.) | | |  | CVE-2007-1020 (Cross-site scripting (XSS) vulnerability in index.php in CedStat 1.31 allows remote attackers to inject arbitrary web script or HTML via the hier parameter.) |
| EasyMail ActiveX buffer overflow | | Published: |  | 16.02.2007 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 7253 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | Buffer overflow in IMAP4 object's Connect method. |
| Affected: |  | QUIKSOFT : EasyMail Objects 6.5 | | CVE: |  | CVE-2007-1029 (Stack-based buffer overflow in the Connect method in the IMAP4 component in Quiksoft EasyMail Objects before 6.5 allows remote attackers to execute arbitrary code via a long host name.) |
| Microsoft Word 2000 / XP 0-day vulnerability | | Published: |  | 16.02.2007 | | Source: |  | MICROSOFT | | SecurityVulns ID: |  | 7254 | | Type: |  | client | | Level: |  | 6/10 | | Description: |  | Vulnerability is used in-the-wild for malware trojan installation. |
| Affected: |  | MICROSOFT : Office 2000 | | |  | MICROSOFT : Office XP | | CVE: |  | CVE-2007-0870 (Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.) |
ActSoft DVD-Tools ActiveX buffer overflow updated since 16.02.2007 | | Published: |  | 01.04.2007 | | Source: |  | MILW0RM | | SecurityVulns ID: |  | 7251 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | Stack buffer overrun in OpenDVD method within dvdtools.ocx ActiveX class library. |
| CVE: |  | CVE-2007-0976 (Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary code via a long DVD_TOOLS.OpenDVD property value.) |
|
|
|
|
|
|
|
|