Computer Security
[EN] securityvulns.ru
no-pyccku



Clarkconnect information leakage
Published:26.02.2003
Source:BUGTRAQ
SecurityVulns ID:2618
Type:remote
Level:4/10
Description:On the port TCP/10005 system information is leaked without authorization.
Affected:CLARKCONNECT : ClarkConnect linux 1.2
Original documentdocumentKnud Erik Højgaard, clarkconnect(d) information disclosure (26.02.2003)
Discuss:Read or add your comments to this news (0 comments)

Information leakage via key file duplication during nCipher import
Published:26.02.2003
Source:BUGTRAQ
SecurityVulns ID:2619
Type:local
Level:5/10
Description:generatekey utility creates temporary PEM file and fails to delete it.
Original documentdocumentNCIPHER, nCipher Advisory #7: Unexpected copies of imported software keys (26.02.2003)
Discuss:Read or add your comments to this news (0 comments)

VERITAS Bare Metal Restore privelege escalation
Published:26.02.2003
Source:BUGTRAQ
SecurityVulns ID:2620
Type:local
Level:5/10
Affected:VERITAS : Bare Metal Restore 3.1
 VERITAS : Bare Metal Restore 3.2
Original documentdocumentVERITAS, VERITAS Software Technical Advisory (26.02.2003)
Discuss:Read or add your comments to this news (0 comments)

Directory traversal in multiple FTP servers
updated since 01.03.2001
Published:26.02.2003
Source:BUGTRAQ
SecurityVulns ID:1018
Type:remote
Level:5/10
Description:It's possible to leave outside FTP root.
Affected:WAR : WarFTPd 1.67
 WHITSOFT : SlimServe FTP v1.0
 DATAWIZARD : FtpXQ Server 2.0
 TYPSOFT : TYPSoft FTP Server 0.85
 NETWIN : SurgeFTP 1.0
 PLAYSTATION2 : RaidenFTPD 2.1
 ALEX : Alex's Ftp Server 0.7
 CRUSHFTP : CrushFTP Server 2.1
 TYPSOFT : TYPsoft FTP server 0.95
 G6 : G6 FTP Server 2.0
 BISON : Bison FTP Server 4
 GHETTO : Ghetto FTP Server 1.0
 GUILD : GuildFTPD 0.97
 ACLOGIC : CesarFTP 0.98
 EFTP : eftp 2.0
 PI-SOFT : SpoonFTP 1.1
 COOLSOFT : PowerFTP 2.03
 TYPSOFT : TYPsoft FTP server 0.97
 MOLLENSOFT : Hyperion Ftp Server 2.8
 KUNANI : Kunani FTP Server 1.0
 PLATINUMFTP : PlatinumFTPServer 1.0
 BSOUTHAM : BRS WebWeaver 1.01
 XYNPTH : Xynph FTP Server 1.0
 NITESERVER : NiteServer 1.83
Original documentdocumentPui Kin Ser, Vulnerability for Platinum FTP version 1.0.11 (26.02.2003)
 documentImmune Advisory, [immune advisory] Mulitple vulnerabilities found in BisonFTP (17.02.2003)
 documentmatrix_(at)_infowarfare.dk, Directory traversal vulnerabilities found in NITE ftp-server version 1.83 (15.01.2003)
 documentZero-X ScriptKiddy, Vulnerabilties in Xynph FTP Server 1.0 (13.01.2003)
 documenteuronymous, BRS WebWeaver FTP Server vulnerabilities (11.01.2003)
 documentmatrix_(at)_infowarfare.dk, [VulnWatch] Multible Vulns in PlatinumFTP server (06.01.2003)
 documentDennis Rand, Multiple vulnerabilities found in PlatinumFTPserver V1.0.6 (31.12.2002)
 documentZero-X ScriptKiddy, KunaniFTP-Server v.1.0.10 allows dictionary traversal (11.12.2002)
 documentTamer Sahin, [SecurityOffice] Hyperion Ftp Server v2.8.1 Directory Traversal Vulnerability (12.11.2002)
 documentKistler Ueli, Typsoft FTP Server: yet another directory traversal vulnerability (09.04.2002)
 documentErtan Kurt, EFTP 2.0.8.346 directory content disclosure (14.12.2001)
 documental3x hernandez, PowerFTP-server-Bugs&Exploits-Remotes (29.11.2001)
 documentjoetesta_(at)_HUSHMAIL.COM, Vulnerability in SpoonFTP (21.09.2001)
 documentandreas junestam, def-2001-27: GuildFTPD Buffer Overflow and Memory Leak DoS (29.05.2001)
 documentByteRage, CesarFTP v0.98b triple dot Directory Traversal / Weak password encryption (29.05.2001)
 documentByteRage, GuildFTPD v0.97 Directory Traversal / Weak password encryption (27.05.2001)
 documentHEXYN, Hexyn / Securax Advisory #17 - Bison FTP Server Directory Traversal (14.05.2001)
 documentHEXYN, Hexyn / Securax Advisory #17 - Bison FTP Server Directory Traversal (14.05.2001)
 documentHEXYN, Hexyn / Securax Advisory #15 - G6 FTP Full Installation Path (14.05.2001)
 documentSosPiro, Vulnerabilty in TYPsoft FTP server (12.05.2001)
 documentjoetesta_(at)_HUSHMAIL.COM, Vulnerabilities in CrushFTP Server (04.05.2001)
 documentjoetesta_(at)_HUSHMAIL.COM, Vulnerabilities in Alex's FTP Server (03.05.2001)
 documentjoetesta_(at)_HUSHMAIL.COM, Vulnerabilities in RaidenFTPD Server (26.04.2001)
 documentse00020_(at)_LION.CC, Warftp 1.67b04 Directory Traversal (11.03.2001)
 documentSNS, SurgeFTP Denial of Service (01.03.2001)
 documentjoetesta_(at)_HUSHMAIL.COM, Vulnerability in TYPSoft FTP Server (01.03.2001)
 documentjoetesta_(at)_HUSHMAIL.COM, Vulnerability in FtpXQ Server (01.03.2001)
 documentjoetesta_(at)_HUSHMAIL.COM, Vulnerability in SlimServe FTPd (01.03.2001)
Discuss:Read or add your comments to this news (0 comments)

Multiple glftpd bugs
Published:26.02.2003
Source:BUGTRAQ
SecurityVulns ID:2616
Type:remote
Level:6/10
Description:Directory traversal in messaging system, archive extraction, effective uid problem.
Affected:GLFTPD : Glftpd 1.25 PoC remote root exploit
Original documentdocumentKarol Wiêsek, multiple vulnerabilities in glftpd (26.02.2003)
Discuss:Read or add your comments to this news (0 comments)

Internet explorer HTML embedded .exe file code execution
updated since 26.02.2003
Published:10.11.2003
Source:BUGTRAQ
SecurityVulns ID:2621
Type:client
Level:8/10
Description:By combining Content-Location: file:///xxx.exe with codebase property of <object> tag it's possible to execute .exe file embedded into HTML.
Affected:MICROSOFT : Internet Explorer 5.5
 MICROSOFT : Internet Explorer 6.0
Original documentdocumenthttp-equiv@excite.com, POS#1 Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part III (10.11.2003)
 documenthttp-equiv_(at)_excite.com, Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part II (26.02.2003)
Discuss:Read or add your comments to this news (0 comments)

QuickTime/Darwin Streaming Server multiple bugs
updated since 26.02.2003
Published:24.02.2004
Source:BUGTRAQ
SecurityVulns ID:2617
Type:remote
Level:6/10
Description:Multiple bugs including uncommented shell characters, buffer overflows, etc.
Affected:APPLE : Darwin Streaming Server 4.1
 APPLE : QuickTime Streaming Server 4.1
Original documentdocumentIDEFENSE, [Full-Disclosure] iDEFENSE Security Advisory 02.23.04: Darwin Streaming Server Remote Denial of Service Vulnerability (24.02.2004)
 documentRapid 7 Security Advisories, [Full-Disclosure] R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server (23.07.2003)
 documentJoe Testa, Re: QuickTime/Darwin Streaming Server security issues (24.05.2003)
 documentSir Mordred The Traitor, QuickTime/Darwin Streaming Server security issues (23.05.2003)
 documentJoe Testa, Re: QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities (03.03.2003)
 documentL0PHT, QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities (26.02.2003)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru