 |
|
|
|
| IIS BlackIce PC Protection file lock protection bypass | | Published: |  | 16.10.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 6723 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | It's possible to delete file and spoof deleted with new copy by direct call to ZwDeleteFile() API. |
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 16.10.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 6722 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. |
| Original document |  | BUGZILLA, Security Advisory for Bugzilla 2.18.5, 2.20.2, 2.22, and 2.23.2 (16.10.2006) |
| |  | SYMANTEC, SYMSA-2006-010: Directory Traversal in IronWebMail (16.10.2006) |
| |  | MILW0RM, webSPELL <= 4.01.01 (getsquad) Remote SQL Injection Exploit (16.10.2006) |
| |  | SHiKaA-_(at)_hotmail.com, DigitalHive <= v2.0 RC2 (page) Remote File Inclusion Exploit (16.10.2006) |
| |  | SHiKaA-_(at)_hotmail.com, Def-Blog <= v1.0.1 (article) Remote SQL Injection Exploit (16.10.2006) |
| |  | SHiKaA-_(at)_hotmail.com, Def-Blog <= v1.0.1 (article) Remote SQL Injection Exploit (16.10.2006) |
| |  | security_(at)_nruns.com, [Full-disclosure] Asbru HardCore Web Content Editor - Command Injection (16.10.2006) |
| |  | SHANKAR, многочисленные уязвимости в WoltLab Burning Book <=1.1.2 (16.10.2006) |
Multiple ClamAV antivirus security vulnerabilities updated since 16.10.2006 | | Published: |  | 19.10.2006 | | Source: |  | SECUNIA | | SecurityVulns ID: |  | 6725 | | Type: |  | remote | | Level: |  | 7/10 | | Description: |  | Buffer overflow on PE files parsing, DoS on CHM parsing. |
Apple MacOS X Xcode OpenBase SQL privilege escalation updated since 16.10.2006 | | Published: |  | 08.11.2006 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 6724 | | Type: |  | local | | Level: |  | 6/10 | | Description: |  | On executing tar from suid root application TAR_OPTIONS environment variable is not unset, making it possible to execute any application with root privileges. External application are executed with relative path. Dynamic libraries are loaded with relative path. Symbolic links problem. |
|
|
|
|
|
|
|
|