Computer Security
[EN] securityvulns.ru
no-pyccku



CGI bugs
updated since 11.03.2003
Published:16.03.2003
Source:SECURITEAM
SecurityVulns ID:2645
Type:remote
Level:5/10
Affected:THUNDERSTONE : Texis
 PHPNUKE : PHP-Nuke 6.0
 CIRCLE : Guestbook 1.1
 JACOBUDDY : Jacobuddy 3.0
 LXR : Cross-Referencing Linux 0.9
 PHPNUKE : PHP-Nuke 6.5
 SQUIRRELMAIL : VPOPMail Account Administration 0.9
 UKFSN : Business::OnlinePayment::WorldPay::Junior 1.05
 RSA : ClearTrust
Original documentdocumentSir Mordred The Traitor, @(#)Mordred Security Labs - RSA ClearTrust Cross Site Scripting issues (16.03.2003)
 documentJason Clifford, Remote Exploit in Business::OnlinePayment::WorldPay::Junior (16.03.2003)
 documentflur, Guestbook v1.1.3 CSS Vuln (15.03.2003)
 documentSir Mordred The Traitor, @(#)Mordred Labs advisory - Texis sensitive information leak (15.03.2003)
 documentmaninthemiddle_(at)_hushmail.com, GiantRat Mailer exposes PoP password (15.03.2003)
 documenterror, VPOPMail Account Administration (squirrel mail) version 0.9.7 (13.03.2003)
 documentfrog frog, PHP-Nuke 6.0 & 6.5RC2 SQL Injection Again (11.03.2003)
 documentRipe, Cross-Referencing Linux vulnerability (11.03.2003)
 documentSECURITEAM, [UNIX] Sourceforge Jacobuddy Cross Site Scripting (XSS) and Upload Exploit (11.03.2003)
Discuss:Read or add your comments to this news (0 comments)

Multiple bugs in Samba
updated since 16.03.2003
Published:16.03.2003
Source:BUGTRAQ
SecurityVulns ID:2661
Type:remote
Level:9/10
Description:Buffer overflow on SMB/CIFS packet re-assembly, chown race conditions.
Affected:SAMBA : Samba 2.2
 SAMBATNG : Samba-TNG 0.3
Original documentdocumentnoir sin, samba 2.x call_trans2open() exploit (10.04.2003)
 documentErik Parker, Samba-TNG 0.3.1 Security Release (fwd) (24.03.2003)
 documentDEBIAN, [SECURITY] [DSA-262-1] samba security fix (16.03.2003)
Files:samba 2.x call_trans2open() exploit
 Samba v2.2.x call_trans2open() Remote Overrun exploit for XxxxBSD
 Mass Samba Exploit by Schizoprenic
Discuss:Read or add your comments to this news (0 comments)

QPopper timing attack
Published:16.03.2003
Source:BUGTRAQ
SecurityVulns ID:2662
Type:remote
Level:4/10
Description:Differet timing interval are used for error message in case of wrong username and wrong password.
Affected:QUALCOMM : qpopper 4.0
 QUALCOMM : qpopper 3.1
Original documentdocumentDennis Lubert, qpopper timing analysis on to determine if a username exists on a system (16.03.2003)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru