Section: .. / 0606-advisories /
| /// File Name: |
glsa-200606-29.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-29 - Tikiwiki fails to properly sanitize user input before processing it, including in SQL statements. Versions less than 1.9.4 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 2597 | | Last Modified: | Jul 2 09:22:16 2006 |
| MD5 Checksum: | 950ff506d1204d1b7e7e871c41d677b9 |
|
| /// File Name: |
glsa-200606-30.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-30 - The iax_net_read function in the iaxclient library fails to properly handle IAX2 packets with truncated full frames or mini-frames. These frames are detected in a length check but processed anyway, leading to buffer overflows. Versions less than 0.8.5_p1 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 2662 | | Last Modified: | Jul 2 10:35:36 2006 |
| MD5 Checksum: | 0b29c20b7b202f3b37f4a87c7fe4b7ae |
|
| /// File Name: |
hobbit42.txt |
Description:
|
All versions under the 4.2 release of Hobbit prior to 2006-Jun-30 suffer from a flaw where the logfetch utility can be used to read any file on the filesystem.
| | Author: | Henrik Stoerner | | File Size: | 1338 | | Last Modified: | Jul 2 11:30:38 2006 |
| MD5 Checksum: | 00c7b00d096a6972d0ad00603d75d045 |
|
| /// File Name: |
housecarers.txt |
Description:
|
Housecarers.com is susceptible to cross site scripting attacks.
| | Author: | luny | | File Size: | 1201 | | Last Modified: | Jun 26 08:08:18 2006 |
| MD5 Checksum: | 4d45724d9795896351c6de080ab3d228 |
|
| /// File Name: |
ImageVue-16.2 |
Description:
|
ImageVue Gallery 16.2 suffers from a file upload vulnerability.
| | Author: | silitix | | File Size: | 2091 | | Last Modified: | Jun 14 06:15:37 2006 |
| MD5 Checksum: | 9cb3dfa5bb83ac0bc40730d5b1915b69 |
|
| /// File Name: |
KAPDA-47.txt |
Description:
|
[KAPDA::#47] - myNewsletter 1.1.2 SQL_Injection
| | Homepage: | http://www.KAPDA.ir | | File Size: | 1800 | | Last Modified: | Jun 11 05:17:14 2006 |
| MD5 Checksum: | 9081b758fc5c004f6a1c61c3c7f26cb7 |
|
| /// File Name: |
KAPDA-48.txt |
Description:
|
[KAPDA::48] CopperminePhotoGallery 1.4.8.stable suffer from a SQL injection vulnerability.
| | Homepage: | http://www.KAPDA.ir | | File Size: | 1521 | | Last Modified: | Jun 14 06:20:57 2006 |
| MD5 Checksum: | 3638147ae0c4f4e01f980b4320ad0831 |
|
| /// File Name: |
kapda-snitz.txt |
Description:
|
Snitz Forum versions 3.4.05 and below suffer from a SQL injection vulnerability.
| | Author: | FarhadKey | | Homepage: | http://www.kapda.ir/ | | File Size: | 2001 | | Last Modified: | Jun 12 10:31:49 2006 |
| MD5 Checksum: | ee43192e6f008525ada0f909f38a6d83 |
|
| /// File Name: |
KmitaFAQv1.0.txt |
Description:
|
Kmita FAQ v1.0 suffers from XSS and SQL injection.
| | Author: | luny | | File Size: | 347 | | Last Modified: | Jun 11 05:09:38 2006 |
| MD5 Checksum: | 83956cd801a1af4423240c4cb45241dd |
|
| /// File Name: |
ks-10.txt |
Description:
|
05:16:46 2006 Kurdish Security Advisory #10: MF Piadas 1.0 Remote File Include Vulnerability and cross site scripting.
| | Homepage: | http://kurdishsecurity.blogspot.com | | File Size: | 1352 | | Last Modified: | Jun 29 |
| MD5 Checksum: | d565d6ed6d221f75b637c274c1227115 |
|
| /// File Name: |
LD-CAeTrust.txt |
Description:
|
A format string vulnerability was discovered within etrust Antivirus 8.0. The vulnerability is due to improper processing of format strings within the scan job description field. An attacker could create a scan job containing special crafted format strings that could potential lead to execution of arbitrary code, rights escalation and at a minimum denial of service.
| | Author: | Deral Heiland | | Homepage: | http://www.LayeredDefense.com | | File Size: | 2421 | | Last Modified: | Jun 29 05:58:34 2006 |
| MD5 Checksum: | f885ce8cc2ec636a62a4c907cc19aed2 |
|
| /// File Name: |
libwmf0284.txt |
Description:
|
libwmf version 0.2.8.4 has been found susceptible to an integer overflow in memory allocation that leads to a heap overflow.
| | Author: | sean | | File Size: | 6940 | | Last Modified: | Jul 2 10:16:24 2006 |
| MD5 Checksum: | 544d8a84acef4d5a6afade28d5179290 |
|
| /// File Name: |
mailmarshal61.txt |
Description:
|
The MailMarshal 6.1 SMTP Server does not unpack and analyze the content of ACE archives, making it possible to circumvent any active content filter by default.
| | Author: | O Aziz | | File Size: | 3088 | | Last Modified: | Jun 12 08:43:06 2006 |
| MD5 Checksum: | 27cc4eb2cc36fc5bfd70058aa6d83842 |
|
| /// File Name: |
major_rls11.txt |
Description:
|
OpenCMS versions 6.2.1 and below suffer from a cross site scripting flaw.
| | Author: | David "Aesthetico" Vieira-Kurz | | Homepage: | http://www.majorsecurity.de | | File Size: | 1418 | | Last Modified: | Jun 12 10:30:27 2006 |
| MD5 Checksum: | 430b8b488c8b0d0c580e52b23e9e50b0 |
|
| /// File Name: |
major_rls12.txt |
Description:
|
ZMS versions 2.9 and below suffer from a cross site scripting flaw.
| | Author: | David "Aesthetico" Vieira-Kurz | | Homepage: | http://www.majorsecurity.de | | File Size: | 1473 | | Last Modified: | Jun 12 10:41:02 2006 |
| MD5 Checksum: | e5c743dd33ce85d454a3b5cc31479b9d |
|
| /// File Name: |
major_rls13.txt |
Description:
|
Cabacos Web CMS versions 3.8.498 and below suffer from a cross site scripting flaw.
| | Author: | David "Aesthetico" Vieira-Kurz | | Homepage: | http://www.majorsecurity.de | | File Size: | 1464 | | Last Modified: | Jun 12 10:42:23 2006 |
| MD5 Checksum: | f98a88522472e5526a90f64175e838f5 |
|
| /// File Name: |
major_rls14.txt |
Description:
|
CFXe-CMS versions 2.0 and below suffer from a cross site scripting flaw.
| | Author: | David "Aesthetico" Vieira-Kurz | | Homepage: | http://www.majorsecurity.de | | File Size: | 1480 | | Last Modified: | Jun 12 10:43:10 2006 |
| MD5 Checksum: | 58ca9cbfc5310b25f6de4e3c5fb6fac0 |
|
| /// File Name: |
major_rls18.txt |
Description:
|
Ralf Image Gallery versions 0.7.4 and below suffer from multiple cross site scripting, remote file inclusion, and directory traversal vulnerabilities.
| | Author: | David "Aesthetico" Vieira-Kurz | | Homepage: | http://www.majorsecurity.de | | File Size: | 3750 | | Last Modified: | Jun 27 06:30:38 2006 |
| MD5 Checksum: | 255d8563d0cc16073bc91bee46fe6e7a |
|
| /// File Name: |
MajorSecurity-8.txt |
Description:
|
05:13:58 2006 [MajorSecurity #8]DreamAccount 3.1 and prior - Remote File Include Vulnerability
| | Homepage: | http://www.majorsecurity.de | | File Size: | 1601 | | Last Modified: | Jun 11 |
| MD5 Checksum: | e773babff3644cd02eebe7bab7cd4125 |
|
| /// File Name: |
MajorSecurity-9.txt |
Description:
|
05:14:50 2006 [MajorSecurity #9] HostAdmin 3.1 and prior - Remote File Include Vulnerability
| | Homepage: | http://www.majorsecurity.de | | File Size: | 1899 | | Last Modified: | Jun 11 |
| MD5 Checksum: | 82342c56ff8adae8eeb95ca5e143e0a2 |
|
| /// File Name: |
ManualMakerv1.0.txt |
Description:
|
PHP ManualMaker v1.0 suffers from XSS.
| | Author: | luny | | File Size: | 382 | | Last Modified: | Jun 3 06:26:24 2006 |
| MD5 Checksum: | a054006c5df068da3511d991428bf94c |
|
| /// File Name: |
MDKSA-2006-093.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-093: A format string vulnerability in Dia allows user-complicit attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3236 | | Last Modified: | Jun 1 02:57:16 2006 |
| MD5 Checksum: | cdb8f4dd28f96dd58a03f7fd3fcc7dec |
|
| /// File Name: |
MDKSA-2006-094.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-094: Evolution, as shipped in Mandriva Linux 2006.0, can crash displaying certain carefully crafted images, if the "Load images if sender is in address book" option in enabled in Edit | Preferences | Mail Preferences | HTML.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 2771 | | Last Modified: | Jun 3 06:13:05 2006 |
| MD5 Checksum: | 123a7c8b6e3f537281ea0687a09577f8 |
|
|
|
|
|