Section: .. / 0604-advisories /
| /// File Name: |
ms-hosts.txt |
Description:
|
The microsoft DNS resolver hardcodes many hostnames such as go.microsoft.com, msdn.microsoft.com, windowsupdate.com, etc preventing the use of a hosts file.
| | Author: | Dave Korn | | File Size: | 10798 | | Last Modified: | Apr 19 17:17:54 2006 |
| MD5 Checksum: | ade870cb49957c9d39449ba91231e3be |
|
| /// File Name: |
ZDI-06-009.txt |
Description:
|
ZDI-06-009: Mozilla Firefox Tag Parsing Code Execution Vulnerability This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Mozilla/Firefox web browser and Thunderbird e-mail client. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious e-mail.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2778 | | Last Modified: | Apr 19 16:52:06 2006 |
| MD5 Checksum: | eacd9e8a3aff05b35b22d3e001ce5d0e |
|
| /// File Name: |
ZDI-06-010.txt |
Description:
|
ZDI-06-010: Mozilla Firefox CSS Letter-Spacing Heap Overflow Vulnerability This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Mozilla/Firefox web browser. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2629 | | Last Modified: | Apr 19 16:47:54 2006 |
| MD5 Checksum: | dc1372944a3453f506049efaf891e979 |
|
| /// File Name: |
ZDI-06-008.txt |
Description:
|
ZDI-06-008: Novell GroupWise Messenger Accept-Language Buffer Overflow - This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Novell GroupWise Messenger. Authentication is not required to exploit this vulnerability.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2886 | | Last Modified: | Apr 19 16:47:15 2006 |
| MD5 Checksum: | d1748a847ba790d1c3889d2704435e13 |
|
| /// File Name: |
win-hlp.txt |
Description:
|
There is a heap based buffer overflow in the rendering engine of .hlp files in winhlp32.exe which will allow some attacker the possibility of modifying the internal structure of the process with a means to execute arbitrary and malicious code.
| | Author: | c0ntex | | Homepage: | http://www.open-security.org | | File Size: | 10304 | | Last Modified: | Apr 19 16:27:04 2006 |
| MD5 Checksum: | 33b60955417c926660ca43ebfc698105 |
|
| /// File Name: |
ms-fp-2.txt |
Description:
|
FrontPage Server Extensions 2002 (included in Windows Sever 2003 IIS 6.0 and available as a separate download for Windows 2000 and XP) has a web page /_vti_bin/_vti_adm/fpadmdll.dll that is used for administrative purposes. This web page is vulnerable to cross site scripting attacks allowing an attacker to run client-side script on behalf of an FPSE user. If the victim is an administrator, the attacker could take complete control of a Front Page Server Extensions 2002 server. POC exploit examples included.
| | Author: | Argeniss - Information Security | | Homepage: | http://www.argeniss.com/products.html | | File Size: | 3147 | | Last Modified: | Apr 19 16:23:32 2006 |
| MD5 Checksum: | 0893198c23d33b143d162fd79277c303 |
|
| /// File Name: |
SA-20060413-0.txt |
Description:
|
SEC-CONSULT Security Advisory 20060413-0 title: Opera Browser versions less than or equal to 8.52 CSS Attribute Integer Wrap and buffer overflow
| | Author: | Bernhard Mueller | | Homepage: | http://www.sec-consult.com | | File Size: | 4231 | | Last Modified: | Apr 19 16:21:53 2006 |
| MD5 Checksum: | b6915f0ce24926539456d5984eda7afe |
|
| /// File Name: |
TalentSoft.txt |
Description:
|
TalentSoft Web Shop v5.3.6 suffers from a full path disclosure vulnerability.
| | Author: | Revnic Vasile | | File Size: | 2051 | | Last Modified: | Apr 19 16:20:14 2006 |
| MD5 Checksum: | bc06aaf14c8228e942d7e04b4ab18af5 |
|
| /// File Name: |
SSRT061133-6.txt |
Description:
|
HPSBUX02108 SSRT061133 rev.6 - HP-UX running Sendmail, Remote Execution of Arbitrary Code
| | Homepage: | http://hp.com | | File Size: | 8811 | | Last Modified: | Apr 19 16:16:08 2006 |
| MD5 Checksum: | 039d15e78e65f4790b0131a9efa12aba |
|
| /// File Name: |
Secunia-Adobe.txt |
Description:
|
Secunia Advisory 13/04/2006 - Adobe Document Server for Reader Extensions Multiple Vulnerabilities
| | Homepage: | http://secunia.com/secunia_research/ | | File Size: | 6047 | | Last Modified: | Apr 19 16:15:31 2006 |
| MD5 Checksum: | 1a6aa333adf130c85a9d00d22bffd793 |
|
| /// File Name: |
RevoBoard-v1.8.txt |
Description:
|
Revoboard 1.8 suffers from XSS in its email tag obfuscation scheme.
| | Author: | r0xes | | Homepage: | http://criticalsecurity.net | | File Size: | 471 | | Last Modified: | Apr 19 16:14:32 2006 |
| MD5 Checksum: | 4331078e6a41765679d7438be8b75463 |
|
| /// File Name: |
Amaya9.4-2.txt |
Description:
|
Amaya versions less than or equal to 9.4 suffer from a stack overflow which could possibly lead to exploitation.
| | Author: | Thomas Waldegger | | Homepage: | http://morph3us.org/ | | File Size: | 4633 | | Last Modified: | Apr 19 16:12:48 2006 |
| MD5 Checksum: | e0ecd6f2d7b062b705970044571b4a98 |
|
| /// File Name: |
Amaya9.4.txt |
Description:
|
Amaya versions less than or equal to 9.4 suffer from a stack overflow which could possible lead to exploitation.
| | Author: | Thomas Waldegger | | Homepage: | http://morph3us.org/ | | File Size: | 5456 | | Last Modified: | Apr 19 16:09:09 2006 |
| MD5 Checksum: | 4e498829c35d6be63700ff50a2582be3 |
|
| /// File Name: |
Firefox1.5.0.1.txt |
Description:
|
It is possible to crash Mozilla Firefox versions less than or equal to 1.5.0.1 with specially crafted html.
| | Author: | Thomas Waldegger | | Homepage: | http://buha.info/board/ | | File Size: | 2225 | | Last Modified: | Apr 19 16:05:36 2006 |
| MD5 Checksum: | fe40e5ae722d9383047b07c8b48de7ec |
|
| /// File Name: |
PatroNetCMS.txt |
Description:
|
PatroNet CMS suffers from XSS.
| | Author: | Shabgard Security Team | | Homepage: | http://www.shabgard.org | | File Size: | 433 | | Last Modified: | Apr 19 16:01:22 2006 |
| MD5 Checksum: | c48df7c4fe735ba6ca512ab8f6741746 |
|
| /// File Name: |
MSIE6.0SP2.txt |
Description:
|
Multiple Vulnerabilities in MS IE 6.0 SP2: All of these bugs are located in `mshtml.dll' and are caused by incorrect handling of specially crafted HTML documents. The severity of the first security issue (mshtml.dll#7d6d2db4) is low because it is a non-exploitable Null Pointer Dereference vulnerability and leads to DoS. The second (mshtml.dll#7d519030) and third (mshtml.dll#7d529d35) vulnerability are similar and the Microsoft Security Response Center rated them as critical because, on the face of it, they could produce an exploitable memory corruption.
| | Author: | Thomas Waldegger - BuHa-Security | | Homepage: | http://buha.info/board/ | | File Size: | 2630 | | Last Modified: | Apr 19 16:00:05 2006 |
| MD5 Checksum: | 145fe60991fff2fed76b5080fa07e04b |
|
| /// File Name: |
MyBB1.10-2.txt |
Description:
|
Yet another XSS vulnerability in MyBB 1.10.
| | Author: | Shabgard Security Team | | Homepage: | http://www.shabgard.org | | File Size: | 489 | | Last Modified: | Apr 19 15:51:31 2006 |
| MD5 Checksum: | c45208a1e556c57b8ad5239aff8bf93f |
|
| /// File Name: |
phpWebSite-2.txt |
Description:
|
phpWebSite versions less than and equal to 0.10.1 suffer from an SQL injection vulnerability in topics.php.
| | Author: | SnIpEr_SA | | Homepage: | http://phpwebsite.appstate.edu/ | | File Size: | 1148 | | Last Modified: | Apr 19 15:44:22 2006 |
| MD5 Checksum: | e22d8be1249e38888eae3c6d37400a97 |
|
| /// File Name: |
ms-fp.txt |
Description:
|
The FrontPage Server Extensions 2002 (included in Windows Sever 2003 IIS 6.0 and available as a separate download for Windows 2000 and XP) has a web page /_vti_bin/_vti_adm/fpadmdll.dll that is used for administrative purposes. This web page is vulnerable to cross site scripting attacks allowing an attacker to run client-side script on behalf of an FPSE user. If the victim is an administrator, the attacker could take complete control of a Front Page Server Extensions 2002 server.
| | Author: | Argeniss | | Homepage: | qhttp://www.argeniss.com/products.html | | File Size: | 2945 | | Last Modified: | Apr 19 15:39:54 2006 |
| MD5 Checksum: | d51f3b4bed1de57eb87ba6f41c0f96c9 |
|
| /// File Name: |
yahoo-fake.txt |
Description:
|
yahoo.com suffers from a XSS vulnerability which can be used to refresh to a fake mail account.
| | Homepage: | http://WwW.SpyMasterSnake.org | | File Size: | 741 | | Last Modified: | Apr 19 15:35:10 2006 |
| MD5 Checksum: | f74898cbcb29b17db791950fd3ef9e53 |
|
| /// File Name: |
HP-management.txt |
Description:
|
CompaqHTTPServer/9.9 and HP System Management Homepage 2.1.3.132 and above suffer from a remote authentication bypass vulnerability.
| | Author: | SRC Telindus | | File Size: | 2767 | | Last Modified: | Apr 19 15:32:10 2006 |
| MD5 Checksum: | 16349be1116b48ce658d8dc729237b25 |
|
| /// File Name: |
sa19641.txt |
Description:
|
Secunia Security Advisory - r0t has reported some vulnerabilities in ModernBill, which can be exploited by malicious users to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/19641/ | | File Size: | 2002 | | Last Modified: | Apr 19 15:19:57 2006 |
| MD5 Checksum: | 0378df9c9872c44f8ef6ee5a7528cced |
|
| /// File Name: |
sa19645.txt |
Description:
|
Secunia Security Advisory - Rusydi Hasan M has reported two vulnerabilities in MODx, which can be exploited by malicious people to conduct cross-site scripting attacks and disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/19645/ | | File Size: | 2060 | | Last Modified: | Apr 19 15:19:57 2006 |
| MD5 Checksum: | 93f7e80a2a373c6f4071f70f3c450521 |
|
| /// File Name: |
sa19648.txt |
Description:
|
Secunia Security Advisory - R@1D3N has discovered a vulnerability in FarsiNews, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/19648/ | | File Size: | 2029 | | Last Modified: | Apr 19 15:19:57 2006 |
| MD5 Checksum: | 218b9f8f0882bbfcf33749158306abd1 |
|
| /// File Name: |
sa19650.txt |
Description:
|
Secunia Security Advisory - Two vulnerabilities have been reported in Article Publisher Pro, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/19650/ | | File Size: | 2045 | | Last Modified: | Apr 19 15:19:57 2006 |
| MD5 Checksum: | aa003988e62dc3cd7b81ab83ad7bf10f |
|
|
|
|
|