Computer Security
[EN] securityvulns.ru
no-pyccku



Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)
Published:30.03.2006
Source:
SecurityVulns ID:5959
Type:remote
Level:5/10
Description:PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Affected:PHXCONTACTS : PhxContacts 0.93
 WEBCALENDAR : Webcalendar 1.1
 XCHANGER : X-Changer 0.2
 EZASPSITE : EzASPSite 2.0
 VBOOK : VBook 2.0
 VNEWS : VNews 1.2
Original documentdocumentSECUNIA, [SA19435] VNews Multiple Vulnerabilities (30.03.2006)
 documentSECUNIA, [SA19448] VBook Multiple Vulnerabilities (30.03.2006)
 documentMustafa Can Bjorn IPEKCI, [Full-disclosure] EzASPSite <= 2.0 RC3 Remote SQL Injection Exploit Vulnerability. (30.03.2006)
 documentJerome ATHIAS, [Full-disclosure] ExplorerXP : Directory Traversal and Cross Site Scripting (30.03.2006)
 documentdabdoub-mosikar_(at)_moroccan-security.com, X-Changer <=v0.2 Demo SQL injection (30.03.2006)
 documentcrasher_(at)_kecoak.or.id, Full path disclosure in Webcalendar 1.1.0-CVS (30.03.2006)
 documentdabdoub-mosikar_(at)_moroccan-security.com, PhxContacts <= 0.93.1 beta Multiple SQL injection & xss (30.03.2006)
Discuss:Read or add your comments to this news (0 comments)

Mailman Scrubber.py DoS
Published:30.03.2006
Source:BUGTRAQ
SecurityVulns ID:5960
Type:remote
Level:5/10
Description:Malformed multipart messages parsing DoS.
Affected:MAILMAN : Mailman 2.1
Original documentdocumentMANDRIVA, [ MDKSA-2006:061 ] - Updated mailman packages fix DoS from badly formed mime multipart messages. (30.03.2006)
Discuss:Read or add your comments to this news (0 comments)

Dia biffer overflow
Published:30.03.2006
Source:BUGTRAQ
SecurityVulns ID:5961
Type:remote
Level:5/10
Description:Buffer overflow on XFig import.
Affected:DIA : Dia 0.94
Original documentdocumentlars_(at)_raeder.dk, Buffer overflows in Dia XFig import (30.03.2006)
Discuss:Read or add your comments to this news (0 comments)

Solaris Sun Cluster SunPlex Manager privilege escalation
Published:30.03.2006
Source:BUGTRAQ
SecurityVulns ID:5962
Type:remote
Level:5/10
Description:User with solaris.cluster.gui authorization can access any local files.
Affected:SUN : Sun Cluster 3.1
Original documentdocumentSECUNIA, [SA19444] Sun Cluster SunPlex Manager File Disclosure Vulnerability (30.03.2006)
Discuss:Read or add your comments to this news (0 comments)

NetBSD if_bridge information leak
Published:30.03.2006
Source:SECUNIA
SecurityVulns ID:5964
Type:local
Level:5/10
Description:ioctl call exposes content of uninitialized memory.
Affected:NETBSD : NetBSD 1.6
Original documentdocumentSECUNIA, [SA19464] NetBSD if_bridge Kernel Memory Disclosure Vulnerability (30.03.2006)
Discuss:Read or add your comments to this news (0 comments)

NetBSD mail weak permissions
Published:30.03.2006
Source:SECUNIA
SecurityVulns ID:5963
Type:local
Level:4/10
Description:Record file is created workd-readable if set record is present in .mailrc.
Affected:NETBSD : NetBSD 1.6
Original documentdocumentSECUNIA, [SA19465] NetBSD mail Insecure Record File Creation (30.03.2006)
Discuss:Read or add your comments to this news (0 comments)

Samba information leak
Published:30.03.2006
Source:SECUNIA
SecurityVulns ID:5965
Type:local
Level:5/10
Description:Machine account is logged in cleartext.
Affected:SAMBA : Samba 3.0
Original documentdocumentSAMBA, [SECURITY] Samba 3.0.21-3.0.21c: Exposure of machine account credentials in winbindd log files (30.03.2006)
 documentSECUNIA, [SA19455] Samba Exposure of Machine Account Credentials (30.03.2006)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru