Computer Security
[EN] securityvulns.ru
no-pyccku



Mailtraq privilege escalation
Published:22.11.2004
Source:BUGTRAQ
SecurityVulns ID:4201
Type:local
Level:5/10
Description:It's possible to execute external application with LocalSystem account.
Affected:MAILTRAQ : Mailtraq 2.6
Original documentdocumentReed Arvin, Privilege escalation in Mailtraq Version 2.6.1.1677. (22.11.2004)
Discuss:Read or add your comments to this news (0 comments)

Altiris AClient privilege escalation
Published:22.11.2004
Source:BUGTRAQ
SecurityVulns ID:4202
Type:local
Level:5/10
Description:It's possible to execute external application with local system privileges.
Affected:ALTRIS : Altiris Deployment Solution 5.6
Original documentdocumentReed Arvin, Privilege escalation flaw in AClient Service for Windows (Version 5.6.181). (22.11.2004)
Discuss:Read or add your comments to this news (0 comments)

Danware NetOp information leak
Published:22.11.2004
Source:BUGTRAQ
SecurityVulns ID:4203
Type:remote
Level:4/10
Description:System information leak.
Affected:DANWARE : NetOp 7.65
Original documentdocumentadvisories, Corsaire Security Advisory - Danware NetOp Host multiple information disclosure issues (22.11.2004)
Discuss:Read or add your comments to this news (0 comments)

TC-IDE unfiltered shell characters problem
Published:22.11.2004
Source:BUGTRAQ
SecurityVulns ID:4204
Type:remote
Level:5/10
Description:Shell characters filtering problem on external program execution in multiple utilities.
Affected:W-CHANNEL : TC-IDE 1.53
Original documentdocumentECL team, [ECL] WCI TC-IDE embedded linux vulnerabilities (22.11.2004)
Discuss:Read or add your comments to this news (0 comments)

Sacred DoS
Published:22.11.2004
Source:FULL-DISCLOSURE
SecurityVulns ID:4206
Type:remote
Level:5/10
Description:Server doesn't have connection timeout and doesn't support more than 17 connections.
Affected:SACRED : Sacred 1.0
Original documentdocumentthe.soylent , [Full-Disclosure] sacred (pcgame) server flaw (22.11.2004)
Discuss:Read or add your comments to this news (0 comments)

Timbuktu DoS
updated since 21.01.2002
Published:22.11.2004
Source:VULN-DEV
SecurityVulns ID:1700
Type:remote
Level:5/10
Description:Large number of connections causes service to crash.
Affected:NETOPIA : Timbuktu 6.0
 NETOPIA : Timbuktu 7.0
Original documentdocumentadvisories, Corsaire Security Advisory - Netopia Timbuktu remote buffer overflow issue (22.11.2004)
 documentTekno pHReak, Timbuktu DoS vulnerabilty (21.01.2002)
Discuss:Read or add your comments to this news (0 comments)

CGI bugs
updated since 22.11.2004
Published:27.11.2004
Source:
SecurityVulns ID:4205
Type:remote
Level:5/10
Affected:PHPBB : phpBB 2.0
 IPB : IpbProArace 2.5
 PHPKIT : PHP KIT 1.6
 KORWEBLOG : KorWeblog
 ZWIKI : zwiki 0.36
 TWIKI : twiki 20040902
 WESMO : SecretSanta 1.0
 SUGARCRM : SugarCRM 2.0
 PHPNEWS : PHPNews 1.2
 JSPWIKI : JSPWiki 2.1
 PHPCMS : phpCMS 1.2
 PNTRESMAILER : PnTresMailer 6.03
Original documentdocumentzee_(at)_psybnc.it, Phpbb id: 10701 update and Attachmodule add-on Directory Traversal (27.11.2004)
 documentJohn Cobb, PnTresMailer code browser 6.03 Vulnerabilities (27.11.2004)
 documentCyrille Barthelemy, phpCMS <= 1.2.1 Xss Vulnerability, Information disclosure (27.11.2004)
 documentZero-X ScriptKiddy, EZshopper is still vulnerable against Directory Traversal. (27.11.2004)
 documentSECUNIA, [SA13285] JSPWiki "query" Parameter Cross-Site Scripting Vulnerability (24.11.2004)
 documentSECUNIA, [SA13300] PHPNews "mid" Parameter SQL Injection Vulnerability (24.11.2004)
 documentSECUNIA, [SA13287] SugarCRM Unspecified Security Issues (24.11.2004)
 documentSECUNIA, [SA13261] SecretSanta Security Bypass Vulnerability (24.11.2004)
 documentGENTOO, [Full-Disclosure] [ GLSA 200411-33 ] TWiki: Arbitrary command execution (24.11.2004)
 documentSSR Team, [Full-Disclosure] STG Security Advisory: [SSA-20041122-12] Zwiki XSS vulnerability (24.11.2004)
 documentSSR Team, [Full-Disclosure] STG Security Advisory: [SSA-20041122-10] KorWeblog directory traversal vulnerability (24.11.2004)
 documentSteve, PHPKIT SQL Injection, XSS (23.11.2004)
 documentaxl daivy, IpbProArace 2.5.x SQL injection. (22.11.2004)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server