Computer Security
[EN] securityvulns.ru
no-pyccku



3COM TippingPoint intrusion prevension system DoS
Published:25.04.2007
Source:BUGTRAQ
SecurityVulns ID:7634
Type:remote
Level:5/10
Description:Packets flood to TCP/80 port leads to resources exhaustion.
Original documentdocumentmike20061005_(at)_webmail.co.za, 3Com's TippingPoint Denial of Service (25.04.2007)
Discuss:Read or add your comments to this news (0 comments)

Apache unfiltered HTTP methods
Published:25.04.2007
Source:BUGTRAQ
SecurityVulns ID:7637
Type:remote
Level:4/10
Description:HTTP request method is not checked for RFC2616 complience. Under specific conditions it may lead, for example, to crossite scripting.
Original documentdocumentMichal Majchrowicz, [Full-disclosure] Apache/PHP REQUEST_METHOD XSS Vulnerability (25.04.2007)
Discuss:Read or add your comments to this news (0 comments)

Asterisk multiple security vulnerabilities
Published:25.04.2007
Source:FULL-DISCLOSURE
SecurityVulns ID:7638
Type:remote
Level:7/10
Description:Multiple buffer overflows on T.38 SDP SIP channels parsing. DoS in administration interface. Multiple security vulnerabilities in parsing SIP replies.
Affected:ASTERISK : Asterisk 1.2
 ASTERISK : Asterisk 1.4
 ASTERISK : Asterisk 1.3
 ASTERISK : Asterisk Appliance Developer Kit 0.4
Original documentdocumentASTERISK, [Full-disclosure] ASA-2007-011: Multiple problems in SIP channel parser handling response codes (25.04.2007)
Discuss:Read or add your comments to this news (0 comments)

Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
Published:25.04.2007
Source:BUGTRAQ
SecurityVulns ID:7633
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:DCPPORTAL : DCP-Portal 6.1
 WORDPRESS : WordPress 2.1
 PLOGGER : Plogger 2.0
 PROGRESS : Webspeed 3.1
 LABS4 : HTMLeditbox 2.2
 PROACTECH : netbingo 2000
 DYNATRACKER : DynaTracker 1.5
Original documentdocumentalijsb_(at)_yahoo.com, netbingo v 2000 >> RFI (25.04.2007)
 documentalijsb_(at)_yahoo.com, HTMLeditbox & 2.2 >> RFI (25.04.2007)
 documents433d_only_linux_(at)_yahoo.de, WordPress v2.1.3 >> remote file include~ (25.04.2007)
 documentalijsb_(at)_yahoo.com, HYIP Manager Pro Script >> Remote file Include (25.04.2007)
 documentalijsb_(at)_yahoo.com, MyNewsGroups >> RFI in include.php (25.04.2007)
 documentsuresync_(at)_gmail.com, Progress Webspeed exploit for all releases (25.04.2007)
 documentIrene Abezgauz, Security Advisory: CA CleverPath SQL Injection (25.04.2007)
 documents433d_only_linux_(at)_yahoo.de, dcp-portal v611 >> RFi (25.04.2007)
 documentAesthetico, [MajorSecurity Advisory #46]Plogger - Session fixation Issue (25.04.2007)
 documentokan alp, Ahhp(php)-Portal Remote File Inclusion (25.04.2007)
Discuss:Read or add your comments to this news (0 comments)

HP StorageWorks unauthorized access
Published:25.04.2007
Source:BUGTRAQ
SecurityVulns ID:7636
Type:local
Level:5/10
Affected:HP : StorageWorks Command View Advanced Edition 5.0
 HP : StorageWorks Command View Advanced Edition 5.1
 HP : StorageWorks Command View Advanced Edition 5.5
 HP : StorageWorks XP Replication Monitor 1.1
 HP : StorageWorks XP Replication Monitor 5.0
 HP : StorageWorks XP Replication Monitor 5.5
 HP : StorageWorks XP Tiered Storage Manager 1.1
 HP : StorageWorks XP Tiered Storage Manager 5.0
 HP : StorageWorks XP Tiered Storage Manager 5.5
Original documentdocumentHP, [security bulletin] HPSBST02200 SSRT071330 rev.1 - HP StorageWorks Command View Advanced Edition for XP, Local Unauthorized Access (25.04.2007)
Discuss:Read or add your comments to this news (0 comments)

Cisco Network Services NetFlow Collection Engine default account
Published:25.04.2007
Source:BUGTRAQ
SecurityVulns ID:7639
Type:remote
Level:5/10
Description:Account with hardcoded password is used for NetFlow information gathering.
Affected:CISCO : NetFlow Collection Engine 5.0
Original documentdocumentCISCO, Cisco Security Advisory: Default Passwords in NetFlow Collection Engine (25.04.2007)
Discuss:Read or add your comments to this news (0 comments)

CA BrightStor ARCserve backup system multiple buffer overflows
updated since 25.04.2007
Published:17.05.2007
Source:BUGTRAQ
SecurityVulns ID:7635
Type:remote
Level:6/10
Description:Multiple buffer overflows in RPC-based Media Server service.
Affected:CA : Brightstor ARCserve Backup 11.1
 CA : BrightStor ARCserve Backup 9.01
 CA : BrightStor Enterprise Backup 10.5
 CA : Brightstor ARCserve Backup 11.5
 CA : CA Server Protection Suite 2
 CA : CA Business Protection Suite 2
 CA : BrightStor ARCserve Backup 11
CVE:CVE-2007-2139 (Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, allow remote attackers to execute arbitrary code via malformed RPC strings, a different vulnerability than CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785.)
 CVE-2007-1785 (The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as demonstrated using the 191 (0xbf) RPC request.)
Original documentdocumentCA, CA BrightStor ARCserve Backup Mediasvr.exe and caloggerd.exe Vulnerabilities (17.05.2007)
 documentCA, [CAID 35198, 35276]: CA BrightStor ARCserve Backup Media Server Vulnerabilities (27.04.2007)
 documentZDI, ZDI-07-022: CA BrightStor ArcServe Media Server Multiple Buffer Overflow Vulnerabilities (25.04.2007)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server