Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) Published: 24.01.2008 Source: BUGTRAQ SecurityVulns ID: 8598 Type: remote Level: 5/10 Description: PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Relay: SQL injection and crossite scripting.
Affected: WOLTLAB : Woltlab Burning Board 2.3 TIKIWIKI : tikiwiki 1.9 RELAY : relay 1.0 WORDPRESS : Dean’s Permalinks Migration 1.0 WEBWIZ : Web Wiz Forums 9.07 WEBWIZ : Web Wiz Rich Text Editor 4.0 WEBWIZ : Web Wiz NewsPad 1.02 CVE: CVE-2007-6529 (Multiple unspecified vulnerabilities in TikiWiki before 1.9.9 have unknown impact and attack vectors involving (1) tiki-edit_css.php, (2) tiki-list_games.php, or (3) tiki-g-admin_shared_source.php.) CVE-2007-6528 (Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) and modified filename in the movie parameter.) CVE-2007-6526 (Cross-site scripting (XSS) vulnerability in tiki-special_chars.php in TikiWiki before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via the area_name parameter.)
Original document 0in.email_(at)_gmail.com , Tiger PHP News System SQL Injection (24.01.2008 )
GENTOO , [ GLSA 200801-10 ] TikiWiki: Multiple vulnerabilities (24.01.2008 )
nbbn_(at)_gmx.net , Woltlab Burning Board 2.3.6 PL2 Remote Delete Thread XSRF Vulnerability (24.01.2008 )
admin_(at)_bugreport.ir , Web Wiz Rich Text Editor Directory traversal + HTM/HTML file creation on the server (24.01.2008 )
admin_(at)_bugreport.ir , Web Wiz NewsPad Directory traversal (24.01.2008 )
admin_(at)_bugreport.ir , Web Wiz Forums Directory traversal (24.01.2008 )
g30rg3_x , XSRF under Dean’s Permalinks Migration 1.0 (24.01.2008 )
MustLive , New vulnerabilities in Relay (24.01.2008 )
SDL_Image library buffer overflow Published: 24.01.2008 Source: BUGTRAQ SecurityVulns ID: 8599 Type: remote Level: 5/10 Description: Buffer overflow on GIF parsing.
Affected: SDLIMAGE : SDL_Image 1.2
Original document Gynvael Coldwind , SDL_Image 1.2.6 and prior GIF handling buffer overflow (24.01.2008 )
Cisco PIX / Adaptive Security Appliance DoS Published: 24.01.2008 Source: BUGTRAQ SecurityVulns ID: 8601 Type: remote Level: 5/10 Description: Crash on TTL processing if decrement-ttl enabled.
Affected: CISCO : PIX 7.2 CISCO : ASA 8.0 CVE: CVE-2008-0028
Original document CISCO , Cisco Security Advisory: Cisco PIX and ASA Time-to-Live Vulnerability (24.01.2008 )
HTTP File Serve multiple security vulnerabilities Published: 24.01.2008 Source: BUGTRAQ SecurityVulns ID: 8604 Type: remote Level: 5/10 Description: Crossite scripting, information disclosure, unauthroized files creation, log manipulation, user name spoofing.
Affected: HFS : HTTP File Server 2.2 HFS : HTTP File Server 2.3 HFS : HTTP File Server 2.0 HFS : HTTP File Server 2.1 CVE: CVE-2008-0410 CVE-2008-0409 CVE-2008-0408 CVE-2008-0407 CVE-2008-0406 CVE-2008-0405
Original document Felipe M. Aragon , Syhunt: HFS (HTTP File Server) Username Spoofing and Log Forging/Injection Vulnerability (24.01.2008 )
Felipe M. Aragon , Syhunt: HFS (HTTP File Server) Log Arbitrary File/Directory Manipulation and Denial-of-Service Vulnerabilities (24.01.2008 )
Felipe M. Aragon , Syhunt: HFS (HTTP File Server) Template Cross-Site Scripting and Information Disclosure Vulnerabilities (24.01.2008 )
ImageShack Toolbar ActiveX unauthorized access Published: 24.01.2008 Source: BUGTRAQ SecurityVulns ID: 8605 Type: client Level: 5/10 Description: Insecure method allows local files reading access.
Affected: IMAGESHACK : ImageShack Toolbar 4.5
Original document retrog_(at)_alice.it , ImageShack Toolbar FileUploader Class insecurities (24.01.2008 )
PHP safe mode bypass vulneraebility Published: 24.01.2008 Source: BUGTRAQ SecurityVulns ID: 8600 Type: local Level: 5/10 Description: It's possible to access files behind sandbox directory with cURL module.
Affected: PHP : PHP 5.2 CVE: CVE-2007-4850
Original document Maksymilian Arciemowicz , PHP 5.2.5 cURL safe_mode bypass (24.01.2008 )
Apache multiple security vulnerabilities updated since 12.01.2008Published: 24.01.2008 Source: BUGTRAQ SecurityVulns ID: 8559 Type: remote Level: 5/10 Description: mod_proxy_balancer ñrossite scripting, crossite requests forgery, memory corruption, DoS, mod_proxy_ftp and mod_status, mod_negotiation - crossite scripting.
Affected: APACHE : Apache 1.3 APACHE : Apache 2.0 APACHE : Apache 2.2 CVE: CVE-2008-0005 CVE-2007-6423 CVE-2007-6422 CVE-2007-6421 CVE-2007-6420 CVE-2007-6388
Original document Minded Security Research Labs , Apache mod_negotiation Xss and Http Response Splitting (24.01.2008 )
sp3x_(at)_securityreason.com , SecurityReason - Apache (mod_status) Refresh Header - Open Redirector (XSS) (16.01.2008 )
sp3x_(at)_securityreason.com , SecurityReason - Apache (mod_proxy_ftp) Undefined Charset UTF-7 XSS Vulnerability (12.01.2008 )
sp3x_(at)_securityreason.com , SecurityReason - Apache2 CSRF, XSS, Memory Corruption and Denial of Service Vulnerability (12.01.2008 )
Mozilla Firefox chrome: URL directory traversal Published: 24.01.2008 Source: SECURITEAM SecurityVulns ID: 8603 Type: client Level: 2/10 Description: It's possible to access local script files
Affected: MOZILLA : Firefox 2.0
Original document SECURITEAM , [NEWS] Firefox chrome: URL Handling Directory Traversal (24.01.2008 )
HP-UX ARPA transport DoS updated since 15.02.2007Published: 24.01.2008 Source: BUGTRAQ SecurityVulns ID: 7241 Type: remote Level: 5/10
Affected: HP : HP-UX 11.11 HP : HP-UX 11.23 CVE: CVE-2007-6425 CVE-2007-1994 (Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.00 allows local users to cause a denial of service via unknown vectors. NOTE: due to lack of vendor details, it is not clear whether this is the same as CVE-2007-0916.) CVE-2007-0916 (Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.)
Original document HP , [security bulletin] HPSBUX02306 SSRT071463 rev.1 - HP-UX Running ARPA Transport, Remote Denial of Service (DoS) (24.01.2008 )
HP , [security bulletin] HPSBUX02248 SSRT071437 rev.1 - HP-UX Running ARPA Transport, Remote Denial of Service (DoS) (03.08.2007 )
HP , [security bulletin] HPSBUX02247 SSRT071432 rev.1 - HP-UX Running ARPA Transport, Local Denial of Service (DoS) (03.08.2007 )
HP , HPSBUX02205 SSRT061120 rev.1 - HP-UX Running ARPA Transport, Local Denial of Service (DoS) (13.04.2007 )
HP , [security bulletin] HPSBUX02192 SSRT061233 rev.1 - HP-UX Running ARPA Transport, Local Denial of Service (DoS) (15.02.2007 )
Cisco Application Velocity System default account Published: 24.01.2008 Source: BUGTRAQ SecurityVulns ID: 8602 Type: remote Level: 6/10 Description: Password for default account is not generated during installation.