Computer Security
[EN] securityvulns.ru
no-pyccku



Symbolic links problem in NetPBM
Published:19.01.2004
Source:BUGTRAQ
SecurityVulns ID:3376
Type:local
Level:5/10
Description:Symlink problem during temporary files creation.
Affected:NETPBM : netpbm 9.20
Original documentdocumentDEBIAN, [Full-Disclosure] [SECURITY] [DSA 426-1] New netpbm-free packages fix insecure temporary file creation (19.01.2004)
Discuss:Read or add your comments to this news (0 comments)

Pablo FTP file existance information leak
Published:19.01.2004
Source:BUGTRAQ
SecurityVulns ID:3377
Type:remote
Level:5/10
Description:It's possible to check file existance with DEL command.
Affected:pablo1 : Pablo FTP 1.7
Original documentdocumentSecuriteinfo.com, [Full-Disclosure] Pablo Sofware Solutions FTP server can detect if a file exists outside the FTP root directory (19.01.2004)
Discuss:Read or add your comments to this news (0 comments)

UltraVNC privilege escalation
Published:19.01.2004
Source:BUGTRAQ
SecurityVulns ID:3378
Type:local
Level:5/10
Description:For online help Internet Explorer is launched with system privileges.
Affected:ULTRAVNC : Ultr@VNC 1.0
Original documentdocumentKevin Finisterre, [Full-Disclosure] SRT2004-01-17-0425 - Ultr@VNC local SYSTEM access. (19.01.2004)
Discuss:Read or add your comments to this news (0 comments)

CGI bugs
updated since 19.01.2004
Published:23.01.2004
Source:
SecurityVulns ID:3379
Type:remote
Level:5/10
Affected:MAMBOSERVER : Mambo Server 4.5
 METADOT : MetaDot 5.6
 YABB : YaBB 1.5
 MAMBOSERVER : Mambo Server 4.6
 DUWARE : DUcalendar 1.1
 DUWARE : DUclassified 4.1
 DUWARE : DUdirectory 3.0
 DUWARE : DUdownload 1.0
 DUWARE : DUgallery 3.3
 DUWARE : DUpics 3.0
 DUWARE : DUportal 3.0
 DUWARE : DUarticle 1.0
 DUWARE : DUclassmate 1.0
 DUWARE : DUpoll 3.0
 DUWARE : DUnews 1.0
 DUWARE : DUamazon 3.0
 DUWARE : DUpaypal 3.0
 DUWARE : DUfaq 1.0
 DUWARE : DUforum 3.0
 CONFYMI : ConfYmI 2.3
 QUADCOMM : Q-Shop
Original documentdocumentS-Quadra Security Research, [Full-Disclosure] QuadComm Q-Shop ASP Shopping Cart Software multiple security vulnerabilities (23.01.2004)
 documentvLad aka vlbag, SQL injection в конференции ConfYmI (23.01.2004)
 documentSecurity Corporation Security Advisory, [SCSA-026] DUWARE Products Admin Access and Arbitrary File Upload Vulnerability (22.01.2004)
 documentFraMe, Mambo OS v4.5/v4.6: remote command execution (20.01.2004)
 documentbackspace, Yabb SE SQL Injection (20.01.2004)
 documentSECURITEAM, [UNIX] Multiple Vulnerabilities MetaDot Portal Server (19.01.2004)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru