Section: .. / 0605-advisories /
| /// File Name: |
PHPcafe.net.txt |
Description:
|
PHPcafe.net Tutorial Manager v1.0 Beta 2 suffers from SQL injection.
| | Author: | black-cod3 | | File Size: | 390 | | Last Modified: | May 29 03:59:03 2006 |
| MD5 Checksum: | cc262afa61fa1e3742e2f271f8ee816e |
|
| /// File Name: |
htmlsguestgear.txt |
Description:
|
html Guest Gear suffers from html injection and XSS.
| | Author: | pieisgdvgd | | File Size: | 422 | | Last Modified: | May 29 03:57:15 2006 |
| MD5 Checksum: | c5b0be96e2a2fce4e0a4ad609826ff16 |
|
| /// File Name: |
ZH2006-20.txt |
Description:
|
CosmicShoppingCart suffers from multiple SQL injection and XSS vulnerabilities.
| | Homepage: | http://www.zone-h.org/ | | File Size: | 1391 | | Last Modified: | May 29 03:55:08 2006 |
| MD5 Checksum: | 20bbfcb7c013213249edf864af2357a3 |
|
| /// File Name: |
curlphp-4.4.2-5.1.4.txt |
Description:
|
It is possible to bypass safe mode in PHP 4.4.2 and 5.1.4 by using the cURL library.
| | Author: | cxib | | Homepage: | http://securityreason.com | | File Size: | 3638 | | Last Modified: | May 29 03:54:04 2006 |
| MD5 Checksum: | 76489a9d1067503afe0e9437851568f9 |
|
| /// File Name: |
Wavecon-Open-Xchange.txt |
Description:
|
Wavecon Advisory: Open-Xchange versions less than or equal to 0.8.2 defaultuser with /bin/bash and default password.
| | Homepage: | http://www.wavecon.de | | File Size: | 2544 | | Last Modified: | May 29 03:52:26 2006 |
| MD5 Checksum: | 0ccf1216f89f1cdacc1c0b8a2bc0a409 |
|
| /// File Name: |
PlumeCMS.txt |
Description:
|
Plume CMS suffers from a remote file inclusion vulnerability.
| | Author: | beford | | File Size: | 335 | | Last Modified: | May 29 03:51:08 2006 |
| MD5 Checksum: | 9861bbe9624a2a3f262b97cd1296c902 |
|
| /// File Name: |
Insel.txt |
Description:
|
Omegasoft's Insel suffers from XSS and possible SQL injection vulnerabilities.
| | Author: | MC Iglo | | File Size: | 306 | | Last Modified: | May 29 03:50:16 2006 |
| MD5 Checksum: | 57861e87eb0e9c3bb4911f810161c252 |
|
| /// File Name: |
rPSA-2006-0084-1.txt |
Description:
|
rPath Security Advisory: 2006-0084-1 Previous versions of fetchmail, when talking to a hostile (possibly compromised) mail server, are vulnerable to possible denial of service or user compromise.
| | Homepage: | http://rpath.com | | File Size: | 1044 | | Last Modified: | May 29 03:47:42 2006 |
| MD5 Checksum: | 7da148d0dd58c3d807e8a6e160239dc6 |
|
| /// File Name: |
rPSA-2006-0083-1.txt |
Description:
|
rPath Security Advisory: 2006-0083-1: Previous versions of the enscript package have weaknesses that may enable vulnerabilities in other applications; in particular, some print filters may call enscript while allowing the user to provide arbitrary filenames or options.
| | Homepage: | http://rpath.com | | File Size: | 1007 | | Last Modified: | May 29 03:46:50 2006 |
| MD5 Checksum: | 3d5c741ca9883e95d4b8140850a7092e |
|
| /// File Name: |
OpenPKG-SA-2006.009.txt |
Description:
|
OpenPKG Security Advisory OpenPKG-SA-2006.009 - According to a vendor bug report [0], a buffer overflow in "libbfd" of GNU Binutils [1], as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.
| | Homepage: | http://www.openpkg.org/ | | File Size: | 2318 | | Last Modified: | May 29 03:45:00 2006 |
| MD5 Checksum: | ae0fce71f46ca5a40763c27099bfa556 |
|
| /// File Name: |
MDKSA-2006-092.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-092: An unspecified vulnerability in mpg123 0.59r allows user-complicit attackers to trigger a segmentation fault and possibly have other impacts via a certain MP3 file, as demonstrated by mpg1DoS3.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 2981 | | Last Modified: | May 29 03:42:45 2006 |
| MD5 Checksum: | 93afd17973170b4ba0ce2b2c2ed67dff |
|
| /// File Name: |
dsa-1079-1.txt |
Description:
|
Debian Security Advisory 1079-1: Several vulnerabilities have been discovered in MySQL, a popular SQL database.
| | Homepage: | http://www.debian.org/security | | File Size: | 12424 | | Last Modified: | May 29 03:39:25 2006 |
| MD5 Checksum: | 2028ffaa54dce17d11ecbe0e99c077fc |
|
| /// File Name: |
dsa-1078-1.txt |
Description:
|
Debian Security Advisory 1078-1: Andrey Kiselev discovered a problem in the TIFF library that may allow an attacker with a specially crafted TIFF image with Yr/Yg/Yb values that exceed the YCR/YCG/YCB values to crash the library and hence the surrounding application.
| | Homepage: | http://www.debian.org/security | | File Size: | 12327 | | Last Modified: | May 29 03:39:11 2006 |
| MD5 Checksum: | e2d9b4e403405f51b510838c4e72a065 |
|
| /// File Name: |
dsa-1077-1.txt |
Description:
|
Debian Security Advisory 1077-1: Michael Zalewski discovered that lynx, the popular text-mode WWW Browser, is not able to grok invalid HTML including a TEXTAREA tag with a large COLS value and a large tag name in an element that is not terminated, and loops forever trying to render the broken HTML. The same code is present in lynx-ssl.
| | Homepage: | http://www.debian.org/security | | File Size: | 4968 | | Last Modified: | May 29 03:39:03 2006 |
| MD5 Checksum: | 66ed9dd2153f9819ad5f7bed2ba41c86 |
|
| /// File Name: |
dsa-1076-1.txt |
Description:
|
Debian Security Advisory 1076-1: Michal Zalewski discovered that lynx, the popular text-mode WWW Browser, is not able to grok invalid HTML including a TEXTAREA tag with a large COLS value and a large tag name in an element that is not terminated, and loops forever trying to render the broken HTML.
| | Homepage: | http://www.debian.org/security | | File Size: | 7536 | | Last Modified: | May 29 03:38:56 2006 |
| MD5 Checksum: | 9d288b10d87bea5d4f5d0c143548dd88 |
|
| /// File Name: |
dsa-1075-1.txt |
Description:
|
Debian Security Advisory 1075-1: Hendrik Weimer discovered that awstats can execute arbitrary commands under the user id the web-server runs when users are allowed to supply arbitrary configuration files. Even though, this bug was referenced in DSA 1058 accidently, it was not fixed yet.
| | Homepage: | http://www.debian.org/security | | File Size: | 3189 | | Last Modified: | May 29 03:38:48 2006 |
| MD5 Checksum: | ac4a8ef7ad9eb83121f837629984afa1 |
|
| /// File Name: |
PrettyGuestbookv1.txt |
Description:
|
Pretty Guestbook v1 suffers from XSS in view.php
| | Author: | luny | | File Size: | 502 | | Last Modified: | May 29 03:37:49 2006 |
| MD5 Checksum: | e8348862048f94f4e06f67345494ed7b |
|
| /// File Name: |
BuHa-13.txt |
Description:
|
BuHa Security-Advisory #13 - Memory Corruption Vulnerability in Internet Explorer: #7d519030
| | Homepage: | http://buha.info/board/ | | File Size: | 7462 | | Last Modified: | May 29 03:36:29 2006 |
| MD5 Checksum: | ca5cdd39bfd6713472e9611d50abef1d |
|
| /// File Name: |
BuHa-12.txt |
Description:
|
BuHa Security-Advisory #12 - Denial of Service bug in Internet Explorer: #7d6d2db
| | Homepage: | http://buha.info/board/ | | File Size: | 4726 | | Last Modified: | May 29 03:35:34 2006 |
| MD5 Checksum: | 503fb1340d56ce3ab67b5c62f50aea61 |
|
| /// File Name: |
V-Webmail1.6.4.txt |
Description:
|
V-Webmail 1.6.4 suffers from a remote file inclusion vulnerability.
| | Author: | beford | | File Size: | 749 | | Last Modified: | May 29 03:30:14 2006 |
| MD5 Checksum: | 511de337406152fd8cec7c59aaf08c7b |
|
| /// File Name: |
DoceboLMS2.05.txt |
Description:
|
Docebo LMS 2.05 suffers from a remote file inclusion vulnerability.
| | Author: | beford | | File Size: | 471 | | Last Modified: | May 29 03:27:38 2006 |
| MD5 Checksum: | 3e9fb7293168e2c691805d5de44eab40 |
|
| /// File Name: |
Tikiwiki1.9.x.txt |
Description:
|
Tikiwiki 1.9.x suffers from multiple XSS vulnerabilities.
| | Author: | blwood | | Homepage: | http://www.blwood.net | | File Size: | 3835 | | Last Modified: | May 29 03:26:16 2006 |
| MD5 Checksum: | 05b538b4011412c50e821c90b7db95a9 |
|
| /// File Name: |
VacationRetal.txt |
Description:
|
Vacation Rental Script v1.0 suffers from XSS
| | Homepage: | http://www.youfucktard.com | | File Size: | 690 | | Last Modified: | May 29 03:23:51 2006 |
| MD5 Checksum: | 2f99ca27a97c99127afdcc41dd967e48 |
|
| /// File Name: |
Socketmail-2.2.6.txt |
Description:
|
Socketmail versions less than or equal to 2.2.6 suffer from a remote file inclusion vulnerability.
| | Author: | Aesthetico | | Homepage: | http://www.majorsecurity.de | | File Size: | 1303 | | Last Modified: | May 29 03:22:51 2006 |
| MD5 Checksum: | 03c2f9fe77314cf91a86a1e10e6d065d |
|
|
|
|
|