 |
|
|
|
| Asterisk DoS | | Published: |  | 24.10.2008 | | Source: |  | BLAKECORNELL | | SecurityVulns ID: |  | 9378 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Resources exhaustion on IAX request parsing. |
Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) updated since 24.10.2008 | | Published: |  | 24.10.2008 | | Source: |  | | | SecurityVulns ID: |  | 9379 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
CNCat: crossite scripting via description field. |
| Affected: |  | SMARTY : Smarty 2.6 | | |  | CNCAT : CNCat 4.1 | | |  | MYSQLQUICKADMIN : MySQL Quick Admin | | CVE: |  | CVE-2008-4121 (Multiple cross-site scripting (XSS) vulnerabilities in cpCommerce before 1.2.4 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in a search.quick action to search.php and (2) the name parameter in a sendtofriend action to sendtofriend.php.) |
Microsoft Windows code execution updated since 24.10.2008 | | Published: |  | 04.11.2008 | | Source: |  | MICROSOFT | | SecurityVulns ID: |  | 9380 | | Type: |  | remote | | Level: |  | 10/10 | | Description: |  | It's possible toexecute code without authentication with RPC request UUID 4b324fc8-1670-01d3-1278-5a47bf6ee188 to browser service via SERVER (LanmanServer) service, TCP/139, TCP/445.
Reccomendation is to disable browser service. |
|
|
|
|
|
|
|
|