Section: .. / 0605-advisories /
| /// File Name: |
CYBSEC-SAPlocal.txt |
Description:
|
CYBSEC Security Advisory - The SAP sapdba command for Informix versions prior to 700 and version 700 up to patch number 100 is susceptible to a local privilege escalation flaw.
| | Author: | Leandro Meiners | | Homepage: | http://www.cybsec.com/ | | File Size: | 3545 | | Last Modified: | May 22 02:05:02 2006 |
| MD5 Checksum: | d82e4532e460380708788cfc4db73ab1 |
|
| /// File Name: |
dieselPHP.txt |
Description:
|
When an unsuspecting user installs Diesel PHP Job Site on their webserver, all information is emailed back to the original programmers of this software. This information is sent from install.php, which includes the database host, database name, username, and password used to connect.
| | Author: | Matt Gibson | | File Size: | 1916 | | Last Modified: | May 22 02:01:53 2006 |
| MD5 Checksum: | e3087052587504a1dc573c95093ea21f |
|
| /// File Name: |
bitrixXSS.txt |
Description:
|
Bitrix CMS version 4.1.x suffers from cross site scripting flaws.
| | Author: | Gogi The Georgian | | File Size: | 1344 | | Last Modified: | May 22 01:58:51 2006 |
| MD5 Checksum: | 216b94b353385b193e1fbc1e0f116b09 |
|
| /// File Name: |
CodeScanLabs_AvatarMod.txt |
Description:
|
The Avatar MOD gives portal administrators the ability to upload avatar images to be used within the forum. CodeScan located a file upload vulnerability in the avatar_upload.asp which can be exploited by a remote user to upload any arbitrary file. Affected is Avatar MOD versions 1.3 for Snitz Forums version 3.4.
| | Author: | Paul Craig | | File Size: | 3309 | | Last Modified: | May 22 01:56:53 2006 |
| MD5 Checksum: | 5daf0932a8ea7d902524b62c1129c010 |
|
| /// File Name: |
libextho.txt |
Description:
|
libextractor versions 0.5.13 and below suffer from multiple heap overflows.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | libextho.zip | | File Size: | 4087 | | Last Modified: | May 22 01:46:33 2006 |
| MD5 Checksum: | 63f5b209f6468ef2734aa772c7fc0d41 |
|
| /// File Name: |
sunSingle.txt |
Description:
|
Single CPU Sun systems running Solaris 7, 8, and 9 are all susceptible to a simple denial of service attack using ping.
| | Author: | Doug Hughes | | File Size: | 1111 | | Last Modified: | May 22 01:43:15 2006 |
| MD5 Checksum: | 447de24872395999371a563c3568fe1c |
|
| /// File Name: |
firenull.txt |
Description:
|
Firefox version 1.5.0.3 with IE Tab version 1.0.9 on Windows XP/2k suffers from a null pointer dereference bug.
| | Author: | Debasis Mohanty | | Homepage: | http://www.hackingspirits.com/ | | File Size: | 1997 | | Last Modified: | May 22 01:39:46 2006 |
| MD5 Checksum: | 6a1ec33bcff61a4236d16d3dbce68615 |
|
| /// File Name: |
whatsupwiththat.txt |
Description:
|
Ipswitch What's Up Professional 2006 is vulnerable to a spoofing attack whereby the attacker can trick the application into thinking he/she is making a request from the console (which is considered trusted). This attack will allow the attacker to bypass the authentication mechanism of the application and login without credentials.
| | Author: | Kenneth F. Belva | | Homepage: | http://www.ftusecurity.com/ | | File Size: | 1326 | | Last Modified: | May 22 01:28:39 2006 |
| MD5 Checksum: | 5ae2438411d0ab8e2e5ec1d060e2f806 |
|
| /// File Name: |
secunia-IZArc.txt |
Description:
|
Secunia Research has discovered a vulnerability in IZArc versions 3.5 beta 3, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error in UNACEV2.DLL when extracting an ACE archive containing a file with an overly long filename. This can be exploited to cause a stack-based buffer overflow when a user extracts a specially crafted ACE archive.
| | Homepage: | http://secunia.com/ | | File Size: | 3482 | | Related CVE(s): | CVE-2005-2856 | | Last Modified: | May 22 01:25:58 2006 |
| MD5 Checksum: | c0e3ed5808f37e7343048f616bfbb1e0 |
|
| /// File Name: |
secunia-Eazel.txt |
Description:
|
Secunia Research has discovered a vulnerability in Eazel version 1.0, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error in ztvunacev2.dll (UNACEV2.DLL) when extracting an ACE archive containing a file with an overly long filename. This can be exploited to cause a stack-based buffer overflow when a user extracts a specially crafted ACE archive.
| | Homepage: | http://secunia.com/ | | File Size: | 3491 | | Related CVE(s): | CVE-2005-2856 | | Last Modified: | May 22 01:25:13 2006 |
| MD5 Checksum: | 21f7a357765104be52f1df731273dbcc |
|
| /// File Name: |
newsportal.txt |
Description:
|
A code injection vulnerability exists in NewsPortal. Upgrading to 0.37 fixes this flaw.
| | Author: | Florian Amrhein | | File Size: | 505 | | Last Modified: | May 22 01:00:00 2006 |
| MD5 Checksum: | 1acae219c7a96b149be91dedf88f004a |
|
| /// File Name: |
frontrange.txt |
Description:
|
A vulnerability has been found in FrontRange's iHeat product that allows users to gain access to the host machine through a logged on session or execute arbitrary code while using the active-x version of the product.
| | Author: | mcdanielar | | File Size: | 906 | | Last Modified: | May 22 00:53:45 2006 |
| MD5 Checksum: | 3930de7b6639f468bad899da506e7944 |
|
| /// File Name: |
yapbb_advisory.txt |
Description:
|
YapBB versions 1.2 Beta2 and below suffer from a SQL injection vulnerability in find.php.
| | Author: | x90c | | Homepage: | http://www.chollian.net/~jyj9782 | | File Size: | 1911 | | Last Modified: | May 22 00:27:48 2006 |
| MD5 Checksum: | 9def23b1d53976b37e635da9202c1436 |
|
| /// File Name: |
secunia-Abakt.txt |
Description:
|
Secunia Research has discovered a vulnerability in Abakt, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error when listing the contents of a ZIP archive. This can be exploited to cause a stack-based buffer overflow when a malicious ZIP archive containing a file with an overly long filename is opened. Versions 0.9.2 and 0.9.3-beta1 are affected.
| | Author: | Tan Chew Keong | | Homepage: | http://secunia.com/ | | File Size: | 3665 | | Related CVE(s): | CVE-2006-2161 | | Last Modified: | May 22 00:23:24 2006 |
| MD5 Checksum: | 22eead297aee1d6bebec5fb6cf470653 |
|
| /// File Name: |
novell_ndps_advisory.pdf |
Description:
|
Hustle Labs Advisory - There is an integer overflow present that affects Novell Windows clients and Novell Netware server and Novell Open Enterprise server. All versions of Novell Netware and Novell Netware Client for Windows are affected. All Netware based versions of Novell Open Enterprise Server are affected. Detailed analysis provided.
| | Author: | Ryan Smith, Alex Wheeler | | Homepage: | http://www.hustlelabs.com/ | | File Size: | 162652 | | Last Modified: | May 22 00:10:55 2006 |
| MD5 Checksum: | 319e4e8c179800f509095b52e4b52d81 |
|
| /// File Name: |
CYBSEC-SAPBC.txt |
Description:
|
CYBSEC Security Advisory - SAP BC was found to provide a vector to allow Phishing scams against the SAP BC administrator. Affected versions are SAP BC Core Fix 7 and below.
| | Author: | Leandro Meiners | | Homepage: | http://www.cybsec.com/ | | File Size: | 2896 | | Last Modified: | May 21 23:55:25 2006 |
| MD5 Checksum: | 3ad38ee6d7fe484683aa27a05eb7a06c |
|
| /// File Name: |
secunia-FilZip.txt |
Description:
|
Secunia Research has discovered a vulnerability in FilZip, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error in UNACEV2.DLL when extracting an ACE archive containing a file with an overly long filename. This can be exploited to cause a stack-based buffer overflow when a user extracts a specially crafted ACE archive. Version 3.04 is affected. Earlier versions may also be affected.
| | Homepage: | http://secunia.com/ | | File Size: | 3530 | | Related CVE(s): | CVE-2005-2856 | | Last Modified: | May 21 23:48:27 2006 |
| MD5 Checksum: | 49d915f9fa00f38f00428ca88cd5a170 |
|
| /// File Name: |
realvnc411.txt |
Description:
|
RealVNC version 4.1.1 suffers from a remote compromise flaw due to handing authentication duties client-side.
| | Author: | James Evans | | File Size: | 4339 | | Last Modified: | May 21 23:46:41 2006 |
| MD5 Checksum: | 2a926f9437c01a41f218451271499922 |
|
| /// File Name: |
azboard_advisory.txt |
Description:
|
Azboard versions 1.0 and below suffer from multiple SQL injection flaws.
| | Author: | Blu3h4t Team | | File Size: | 2223 | | Last Modified: | May 21 23:44:14 2006 |
| MD5 Checksum: | 50eaddc0235b986f4363e6a9a2f41318 |
|
| /// File Name: |
DMA-2006-0514a.txt |
Description:
|
ClamAV freshclam suffers from an incorrect privilege dropping vulnerability.
| | Author: | Kevin Finisterre | | Homepage: | http://www.digitalmunition.com/ | | File Size: | 6641 | | Last Modified: | May 21 23:41:59 2006 |
| MD5 Checksum: | 04cfa190d4ba3ec49511d88cd9e3f793 |
|
| /// File Name: |
pathdisclose.txt |
Description:
|
It appears that a slew of various programs written in PHP suffer from full path disclosure issues.
| | Author: | sirdarckcat | | File Size: | 2683 | | Last Modified: | May 21 23:18:38 2006 |
| MD5 Checksum: | ecb326286f7fed997f692b3d2f90bd7b |
|
| /// File Name: |
phpapachespi.txt |
Description:
|
A vulnerability exists in the PHP Apache SPI POST parsing code.
| | Author: | Mr Babs | | File Size: | 2062 | | Last Modified: | May 21 23:16:36 2006 |
| MD5 Checksum: | 6bc0ba0019ed5bfc7f5338985d8a380a |
|
| /// File Name: |
TA06-132A.txt |
Description:
|
Technical Cyber Security Alert TA06-132A - Apple has released Security Update 2006-003 to correct multiple vulnerabilities affecting Mac OS X, Mac OS X Server, Safari web browser, Mail, and other products. The most serious of these vulnerabilities may allow a remote attacker to execute arbitrary code. Impacts of other vulnerabilities include bypassing security restrictions and denial of service.
| | Homepage: | http://cert.org/ | | File Size: | 3858 | | Last Modified: | May 21 23:14:36 2006 |
| MD5 Checksum: | 533105a0b6c952c53d495471e639a017 |
|
| /// File Name: |
gnunet070d.txt |
Description:
|
GNUnet version 0.7.0d and below suffer from a UDP socket unreachable flaw that results in a denial of service condition.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | File Size: | 1826 | | Last Modified: | May 21 23:06:51 2006 |
| MD5 Checksum: | 9e03e588d715300c34629ba22be597ef |
|
| /// File Name: |
outgunx.txt |
Description:
|
Outgun versions 1.0.3 bot 2 and below suffer from various flaws including a buffer overflow and invalid memory access.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | outgunx.zip | | File Size: | 5266 | | Last Modified: | May 21 23:04:01 2006 |
| MD5 Checksum: | 597be3dc18c5a368a3c88ca7b4b97552 |
|
|
|
|
|