Section: .. / 0701-advisories /
| /// File Name: |
wbv265-sql.txt |
Description:
|
Website Baker version 2.6.5 suffers from a SQL injection flaw.
| | Author: | Rolf Huisman | | File Size: | 1563 | | Last Modified: | Jan 26 20:56:30 2007 |
| MD5 Checksum: | 7a7836c4083198eb731d162709a1deb0 |
|
| /// File Name: |
winntcomp.txt |
Description:
|
A critical security vulnerability has been found in the Windows NT Message compiler. Arbitrary code execution might be possible.
| | Author: | sapheal | | File Size: | 941 | | Last Modified: | Jan 3 21:53:42 2007 |
| MD5 Checksum: | c0cbe312d8f92d18cef79225e95240e7 |
|
| /// File Name: |
winzipactivex.txt |
Description:
|
WinZip version 10.0 Build 6667 suffers from an arbitrary code execution vulnerability via an input validation flaw.
| | Author: | Xiao Hui | | Homepage: | http://www.nipc.org.cn | | File Size: | 2681 | | Last Modified: | Jan 1 21:59:22 2007 |
| MD5 Checksum: | 5d1079d5b66fe32cb3706d7d99bce7cb |
|
| /// File Name: |
wp206-disclose.txt |
Description:
|
WordPress versions 2.1Alpha and 2.0.6 and below suffer from information disclosure flaws.
| | Author: | Xy7 | | File Size: | 1138 | | Last Modified: | Jan 13 19:46:03 2007 |
| MD5 Checksum: | cc236f8888abfb5c3e73eee74af3c454 |
|
| /// File Name: |
ws2007-format.txt |
Description:
|
WS_FTP 2007 Professional SCP suffers from a format string vulnerability.
| | Author: | Michal Bucko | | File Size: | 830 | | Last Modified: | Jan 29 11:20:37 2007 |
| MD5 Checksum: | 4410ba18e5e669f9f0d181a489baf499 |
|
| /// File Name: |
yim-xss.txt |
Description:
|
Yahoo! Messenger versions 8.1.0.29 and below suffer from a javascript injection flaw.
| | Author: | Hai Nam Luke | | File Size: | 1469 | | Last Modified: | Jan 26 23:30:12 2007 |
| MD5 Checksum: | 27d35218f889720d1bc6ff53479c97f6 |
|
| /// File Name: |
ZDI-07-001.txt |
Description:
|
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Eudora WorldMail. Authentication is not required to exploit this vulnerability. Affected is the Eudora WorldMail 3.1.x Mail Management Server.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2531 | | Related CVE(s): | CVE-2006-6336 | | Last Modified: | Jan 13 15:36:56 2007 |
| MD5 Checksum: | d528cdc64a44cf939af3cd4ac6fb28a7 |
|
| /// File Name: |
ZDI-07-002.txt |
Description:
|
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates BrightStor ARCserve Backup. User interaction is not required to exploit this vulnerability. The specific flaw exists in the handling of RPC requests to the Tape Engine service which listens by default on TCP port 6502. Affected include BrightStor ARCserve Backup r11.5, BrightStor ARCserve Backup r11.1, BrightStor ARCserve Backup r11, BrightStor Enterprise Backup r10.5, and BrightStor ARCserve Backup v9.01.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2837 | | Related CVE(s): | CVE-2007-0168 | | Last Modified: | Jan 13 19:14:27 2007 |
| MD5 Checksum: | 14a1278e12723d0ac985d47f748fbc77 |
|
| /// File Name: |
ZDI-07-003.txt |
Description:
|
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates BrightStor ARCserve Backup. User interaction is not required to exploit this vulnerability. The specific flaws exists in the Message Engine RPC service which listens by default on TCP ports 6503 and 6504. Affected include BrightStor ARCserve Backup r11.5, BrightStor ARCserve Backup r11.1, BrightStor ARCserve Backup r11, BrightStor Enterprise Backup r10.5, and BrightStor ARCserve Backup v9.01.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2921 | | Related CVE(s): | CVE-2007-0169 | | Last Modified: | Jan 13 19:15:41 2007 |
| MD5 Checksum: | 97132b2d3b4e89621dff17ca66794441 |
|
| /// File Name: |
ZDI-07-004.txt |
Description:
|
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates BrightStor ARCserve Backup. User interaction is not required to exploit this vulnerability. The specific flaw exists in the Tape Engine RPC service which listens by default on TCP port 6503. Affected include BrightStor ARCserve Backup r11.5, BrightStor ARCserve Backup r11.1, BrightStor ARCserve Backup r11, BrightStor Enterprise Backup r10.5, and BrightStor ARCserve Backup v9.01.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2837 | | Related CVE(s): | CVE-2007-0169 | | Last Modified: | Jan 13 19:16:26 2007 |
| MD5 Checksum: | 751ec3a215916654c25086a3af2b1ae1 |
|
| /// File Name: |
ZDI-07-005.txt |
Description:
|
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Sun Microsystems Java Virtual Machine (JVM). User interaction is required to exploit this vulnerability in that the target must visit a malicious website.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2916 | | Related CVE(s): | CVE-2007-0243 | | Last Modified: | Jan 19 20:16:45 2007 |
| MD5 Checksum: | 4be61731d61a0eeec39c080a33cbaeb7 |
|
| /// File Name: |
ZDI-07-006.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of Citrix Presentation Server, Metaframe Presentation Server or MetaFrame XP. Authentication is not required to exploit this vulnerability.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2926 | | Related CVE(s): | CVE-2007-0444 | | Last Modified: | Jan 26 21:34:15 2007 |
| MD5 Checksum: | e9efacaacf35961b818bbb09ab39a5c1 |
|
|
|
|
|