Computer Security
[EN] securityvulns.ru
no-pyccku



ps2text unfiltered shell characters code execution
Published:27.11.2006
Source:BUGTRAQ
SecurityVulns ID:6859
Type:local
Level:4/10
Description:Shell characters problem thorugh filename.
Affected:PSTOTEXT : pstotext 1.9
Original documentdocumentDEBIAN, [SECURITY] [DSA 1220-1] New pstotext packages fix arbitrary shell command execution (27.11.2006)
Discuss:Read or add your comments to this news (0 comments)

QBIK Wingate DoS
Published:27.11.2006
Source:BUGTRAQ
SecurityVulns ID:6861
Type:remote
Level:5/10
Description:Nedless loop on compressed DNS requests processing.
Affected:QBIK : Wingate 6.1
Original documentdocumentIDEFENSE, iDefense Security Advisory 11.26.06: Qbik WinGate Compressed Name Pointer Denial of Service Vulnerability (27.11.2006)
Discuss:Read or add your comments to this news (0 comments)

AT-TFTP / 3CTftpSvc TFTP servers buffer overflow
Published:27.11.2006
Source:BUGTRAQ
SecurityVulns ID:6860
Type:remote
Level:5/10
Description:Buffer overflows in GET and PUT commands.
Affected:ALLIEDTELESYN : AT-TFTP Server 1.9
 3COM : 3CTftpSvc TFTP Server 2.0
Original documentdocumentliuqx_(at)_nipc.org.cn, TFTP Server 3CTftpSvc Buffer Overflow Vulnerability (Long transporting mode) (27.11.2006)
 documentliuqx_(at)_nipc.org.cn, TFTP Server AT-TFTP Server v 1.9 Buffer Overflow Vulnerability (Long filename) (27.11.2006)
Files:3ctftpsvc Buffer Overflow (Long transporting mode) Vulnerability Exploit
 AT-TFTP Buffer Overflow (Long filename) Vulnerability Exploit
 Exploits 3CTftpSvc Server 2.0.1 Long Requesat Buffer Overflow (metasploit)
Discuss:Read or add your comments to this news (0 comments)

Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
Published:27.11.2006
Source:BUGTRAQ
SecurityVulns ID:6862
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:MALBUM : mAlbum 0.3
Original documentdocumentnagazakig74_(at)_hotmail.com, Siap Cms Sql Injection (login.asp) (27.11.2006)
 documentnagazakig74_(at)_hotmail.com, Wisi Portal [Sql Injection By Jesus Tovar] (27.11.2006)
 documenttux025_(at)_gmail.com, mAlbum v0.3 local file inclusion (27.11.2006)
 documentAdvisory_(at)_Aria-Security.net, ClickGallery Sql Injection (27.11.2006)
 documentAdvisory_(at)_Aria-Security.net, [Aria-Security Team] Evolve shopping cart SQL Injection Vulnerability (27.11.2006)
 documentAdvisory_(at)_Aria-Security.net, [Aria-Security Team] General Shopping Cart SQL Injection Vulnerability (27.11.2006)
 documentAdvisory_(at)_Aria-Security.net, Clickblog Sql Injection (27.11.2006)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru