Computer Security
[EN] securityvulns.ru
no-pyccku



Buffer overflow in multiple OS telnetd
updated since 19.07.2001
Published:19.09.2004
Source:BUGTRAQ
SecurityVulns ID:1344
Type:remote
Level:10/10
Description:It's possible to overflow buffer with AYT telnet protocol command.
Affected:FREEBSD : FreeBSD 5.0
 SUN : Solaris 2.8
 SGI : IRIX 6.5
 NETBSD : NetBSD 1.5
 SCO : OpenServer 5.0
 FREEBSD : FreeBSD 4.3
 OPENBSD : OpenBSD 2.9
 APPLE : MacOS X 10.0
 BSDI : BSD/OS 4.2
 LINUX : Linux netkit-telnetd 0.13
 DEBIAN : Debian netkit-telnetd 0.17
Original documentdocumentMichal Zalewski, [Full-Disclosure] Debian netkit telnetd vulnerability (19.09.2004)
 documentZenith Parsec, ADV/EXP: netkit <=0.17 in.telnetd remote buffer overflow (12.08.2001)
 documentCERT, Advisory CA-2001-21 (25.07.2001)
 documentSebastian, multiple vendor telnet daemon vulnerability (19.07.2001)
Files:telnetd exploit code
 Telnetd AYT overflow scanner, by Security Point(R)
 Proof of concept netkit-0.17-7 local root exploit.
Discuss:Read or add your comments to this news (0 comments)

CGI bugs
updated since 06.09.2004
Published:19.09.2004
Source:
SecurityVulns ID:3980
Type:remote
Level:5/10
Affected:PHPBB : phpBB 2.02
 VBULLETIN : vBulletin 3.0
 MAMBOSERVER : Mambo Server 4.5
 PHPNUKE : PHP-Nuke 7.4
 TUTTINOVA : Tutti Nova
 YABBSE : YaBB SE 1.5
 EZ : eZphotoshare 1.2
 EZ : eZphotoshare 3.4
 PSNEWS : PsNews 1.1
 BBS2000 : BBS E-Market Professional 1.3
 FOCALMEDIA : Turbo Seek
 POSTNUKE : Subjects 2.0
 MERAK : Merak Mail Server 7.5
 ICEWARP : IceWarp Web Mail 5.2
 PERLDESK : PerlDesk
 SNIPSNAP : SnipSnap 0.5
 SNITZ : Snitz Forums 2000 3.4
Original documentdocumentJon Koffe, exploit in PHPBB 2010 (19.09.2004)
 documentkhoaimi, Mambo Portal lasted version 4.5.1 (1.09) and lower vesion : SQL injection Vulnerability. (18.09.2004)
 documentMaestro De-Seguridad, ADVISORY: security hole (http response splitting) in snitz forums 2000 (17.09.2004)
 documentMaestro De-Seguridad, ADVISORY: http response splitting in snipsnap (15.09.2004)
 documentbima tampan, [XSS]/SQL Injection PHP-Nuke Edit/Save Message(s) Bug (15.09.2004)
 documentSSR Team, [Full-Disclosure] STG Security Advisory: [SSA-20040915-07] BBS E-Market Professional multiple vulnerabilities (15.09.2004)
 documentSECURITEAM, [UNIX] vBulletin SQL Injection While Verifying Subscription Information (14.09.2004)
 documentNikyt0x Argentina, Posible Inclusion File in Perl Desk (14.09.2004)
 documentShineShadow, Multiple vulnerabilities in Icewarp Web Mail 5.2.7 (11.09.2004)
 documentCriolabs, SQL-Injection in Subjects 2.0 for Postnuke (11.09.2004)
 documentdurito, Просмотр файлов в Search Engine & Directory Powered by Turbo Seek от FocalMedia.Net (10.09.2004)
 documentahmad muammar, Multiple vulnerabilities 1n BBS E-Market Professional (10.09.2004)
 documentbima tampan, [XSS]/SQL Injection PHP-Nuke Delete Message(s) Bug (09.09.2004)
 documentMichal Blaszczak, Bug XSS in PsNews 1.1 (08.09.2004)
 documentPierquinto Manco, PHP-Nuke 7.4 Multiple XSS Vulnerabilities Patch (08.09.2004)
 documentPierquinto Manco, Good Patch to Multiple [XSS] Vulnerabilities in PHP-Nuke 7.4 (08.09.2004)
 documentPierquinto Manco, [XSS] PHP-Nuke 7.4 AddMsg Bug (08.09.2004)
 documentPierquinto Manco, [XSS] PHP-Nuke 7.4 Newsletter Injection Bug (08.09.2004)
 documentSECUNIA, [SA12460] eZ / eZphotoshare Multiple Connection Denial of Service Vulnerability (06.09.2004)
 documentahmad muammar, FUll Path Disclosure in YABBSE (06.09.2004)
 documentPierquinto Manco, [XSS] PHP-Nuke 7.4 DelAdmin Bug (06.09.2004)
 documentPierquinto Manco, [XSS] PHP-Nuke 7.4 ViewAdmin Bug (06.09.2004)
 documentSECUNIA, [SA12467] Tutti Nova Unspecified Vulnerabilities (06.09.2004)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru