Computer Security
[EN] securityvulns.ru
no-pyccku



Agnitum Outpost privilege escalation
Published:20.01.2004
Source:BUGTRAQ
SecurityVulns ID:3380
Type:local
Level:6/10
Description:It's possible to obtain local system privileges with help or adding new filter.
Affected:AGNITUM : Outpost Firewall 2.0
Original documentdocumentKevin Finisterre, Happy belated Personal Firewall day - SRT2004-01-17-0628 - Agnitum Optpost firewall allows Local SYSTEM access (20.01.2004)
Discuss:Read or add your comments to this news (0 comments)

Networker symlink problem
Published:20.01.2004
Source:BUGTRAQ
SecurityVulns ID:3381
Type:local
Level:5/10
Description:Symlink problem in shutdown script.
Affected:NETWORKER : Networker 6.0
Original documentdocumentRene, Networker 6.0 - possible symlink attack (20.01.2004)
Discuss:Read or add your comments to this news (0 comments)

GoAhead DoS
Published:20.01.2004
Source:BUGTRAQ
SecurityVulns ID:3382
Type:remote
Level:5/10
Description:Invalid Content-Length processing in POST request.
Affected:GOAHEAD : GoAhead Webserver 2.1
Original documentdocumentLuigi Auriemma, Resources consumption in Goahead webserver <= 2.1.8 (20.01.2004)
Discuss:Read or add your comments to this news (0 comments)

GetWare DoS
Published:20.01.2004
Source:BUGTRAQ
SecurityVulns ID:3383
Type:remote
Level:5/10
Description:Problem with Content-Length: processing in POST request.
Affected:WEBCAM : WebCam Live 2.01
 PHOTOHOST : Photohost 4.0
Original documentdocumentLuigi Auriemma, Denial of service in Getware's built-in webserver (Webcam Live and Photohost) (20.01.2004)
Discuss:Read or add your comments to this news (0 comments)

J2EE code execution
updated since 17.12.2003
Published:20.01.2004
Source:BUGTRAQ
SecurityVulns ID:3322
Type:library
Level:5/10
Description:It's possible to execute external application in SQL request to pointbase database.
Affected:SUN : j2ee 1.4
Original documentdocumentMarc Schönefeld, Proof-Of-Concept Denial-Of-Service Pointbase 4.6 Java SQL-DB (20.01.2004)
 documentMarc Schönefeld, J2EE 1.4 reference implementation: database component allows remote code execution (17.12.2003)
Discuss:Read or add your comments to this news (0 comments)

GoAhead script source leak
updated since 18.12.2003
Published:20.01.2004
Source:BUGTRAQ
SecurityVulns ID:3324
Type:remote
Level:5/10
Description:It's possible to obtain content of .asp or cgi-bin file by adding special characters to filename.
Affected:GOAHEAD : GoAhead Webserver 2.1
Original documentdocumentLuigi Auriemma, Directories management bypassing in Goahead webserver <= 2.1.8 (20.01.2004)
 documentLuigi Auriemma, Server side scripts viewing in Goahead webserver <= 2.1.7 (18.12.2003)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru