Section: .. / 0707-advisories /
| /// File Name: |
sa26018.txt |
Description:
|
Secunia Security Advisory - Gary O'leary-Steele has reported a vulnerability in MailMarshal, which can be exploited by malicious people to disclose potentially sensitive information.
| | Homepage: | http://secunia.com/advisories/26018/ | | File Size: | 2692 | | Last Modified: | Jul 18 05:40:34 2007 |
| MD5 Checksum: | 76e82d337f5e151c894810ff6854b4be |
|
| /// File Name: |
sa26008.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Infinite Responder, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/26008/ | | File Size: | 2369 | | Last Modified: | Jul 18 05:40:34 2007 |
| MD5 Checksum: | ca6286b60981e255f6a8dfec20707232 |
|
| /// File Name: |
sa25953.txt |
Description:
|
Secunia Security Advisory - Daniel C. Litzenberger has reported a weakness in DAR, which can potentially be exploited by malicious people to disclose certain information.
| | Homepage: | http://secunia.com/advisories/25953/ | | File Size: | 2254 | | Last Modified: | Jul 18 05:40:34 2007 |
| MD5 Checksum: | ac60bd3088ae9b94941e80dbbad6e38c |
|
| /// File Name: |
07.16.07-2.txt |
Description:
|
iDefense Security Advisory 07.16.07 - Remote exploitation of an authorization bypass vulnerability in Trend Micro Inc.'s OfficeScan for Windows could allow attackers to login to the management console and alter application settings. The OfficeScan installation includes a web management console that allows administrators to configure the application and the Antivirus clients it manages. The web interface login is handled by cgiChkMasterPwd.exe which is passed a hash and an encrypted version of the password generated by an ActiveX control on the login page. If cgiChkMasterPwd.exe is sent an empty encryption string and empty hash it proceeds to issue the client a valid session id which can then be used to access the web management console. iDefense has confirmed the existence of this vulnerability in OfficeScan for Windows 7.3 with all current patches applied. Previous versions may also be affected.
| | Author: | David Maciejak | | Homepage: | http://www.idefense.com/ | | File Size: | 3811 | | Related CVE(s): | CVE-2007-3455 | | Last Modified: | Jul 17 09:50:19 2007 |
| MD5 Checksum: | 9feb23e6fea2157756924c3bbe576752 |
|
| /// File Name: |
07.16.07-1.txt |
Description:
|
iDefense Security Advisory 07.16.07 - Remote exploitation of a stack-based buffer overflow vulnerability in Trend Micro Inc.'s OfficeScan for Windows could allow attackers to execute arbitrary code with the privileges of the IIS Web User. The OfficeScan installation includes a series of CGI executables that are used for configuration through the Web interface. A shared library, CGIOCommon.dll, is used by many of these binaries to access environment variables passed to them from the parent IIS process. If a malicious Web request is made for a vulnerable binary, including an overly long session cookie, a stack-based Unicode buffer overflow will occur. iDefense has confirmed this vulnerability in OfficeScan 7.3 with all current patches applied. Testing has shown that this attack can be conducted by requesting multiple CGI binaries that make use of the shared library. Other versions are suspected to be vulnerable.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3954 | | Related CVE(s): | CVE-2007-3454 | | Last Modified: | Jul 17 09:48:27 2007 |
| MD5 Checksum: | 690a05b37c2cbeba9b270c6c3cc72693 |
|
| /// File Name: |
exlibris-xss.txt |
Description:
|
Multiple versions of the ExLibris Aleph and Metalib products are vulnerable to simple cross site scripting vulnerabilities.
| | Author: | Matthew Cook | | Homepage: | http://escarpment.net/ | | File Size: | 2075 | | Last Modified: | Jul 17 09:34:34 2007 |
| MD5 Checksum: | 0c219ccffc36d17ffe623b2a33f23ccc |
|
| /// File Name: |
SSRT071435.txt |
Description:
|
HP Security Bulletin - A potential security vulnerability has been identified with HP Serviceguard for Linux. The vulnerability could be exploited to allow local unauthorized access or to increase privilege.
| | Homepage: | http://www.hp.com/ | | File Size: | 6502 | | Last Modified: | Jul 17 09:33:04 2007 |
| MD5 Checksum: | d92949bba66c79c4205e176e791036a1 |
|
| /// File Name: |
opera-redirect.txt |
Description:
|
Opera / Konqueror suffers from an arbitrary redirection vulnerability. It appears that Opera 9.21 and Konqueror 3.5.7 are susceptible.
| | Author: | Robert Swiecki | | Homepage: | http://alt.swiecki.net/ | | File Size: | 1196 | | Last Modified: | Jul 17 09:24:53 2007 |
| MD5 Checksum: | df62c3606813ff0419901df0c1610fe1 |
|
| /// File Name: |
ie-entrap.txt |
Description:
|
It appears that Microsoft Internet Explorer suffers from a browser entrapment vulnerability in document.open() calls.
| | Author: | Michal Zalewski | | Homepage: | http://lcamtuf.coredump.cx/ | | File Size: | 1638 | | Last Modified: | Jul 17 09:22:12 2007 |
| MD5 Checksum: | a8e4a0a8e6bbda99cf4f77e69923c24c |
|
| /// File Name: |
sitescape-xss.txt |
Description:
|
SiteScape Forum versions below 7.3 suffer form a cross site scripting vulnerability.
| | Author: | Marc Ruef | | Homepage: | http://www.scip.ch/ | | File Size: | 4040 | | Last Modified: | Jul 17 08:26:40 2007 |
| MD5 Checksum: | 8f91255d47204d82c9642d4331c95b49 |
|
| /// File Name: |
sa26091.txt |
Description:
|
Secunia Security Advisory - Robert Swiecki has reported a vulnerability in Konqueror, which can be exploited by malicious people to conduct spoofing attacks.
| | Homepage: | http://secunia.com/advisories/26091/ | | File Size: | 2150 | | Last Modified: | Jul 17 03:59:39 2007 |
| MD5 Checksum: | 6f3fe4806f9698f556763ed18ec37a72 |
|
| /// File Name: |
sa26090.txt |
Description:
|
Secunia Security Advisory - Christopher Schwardt has reported multiple vulnerabilities in WebCit, which can be exploited by malicious users to conduct script insertion attacks and by malicious people to conduct cross-site request forgery and cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/26090/ | | File Size: | 3039 | | Last Modified: | Jul 17 03:59:39 2007 |
| MD5 Checksum: | 768176fd31994df7509ab89b62fe367e |
|
| /// File Name: |
sa26085.txt |
Description:
|
Secunia Security Advisory - shinnai has discovered a vulnerability in PHP, which can be exploited by malicious, local users to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/26085/ | | File Size: | 2319 | | Last Modified: | Jul 17 03:59:39 2007 |
| MD5 Checksum: | 0995ecd579f460330286b505751aaf79 |
|
| /// File Name: |
sa26078.txt |
Description:
|
Secunia Security Advisory - h4si & pUm have discovered a vulnerability in paFileDB, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/26078/ | | File Size: | 2422 | | Last Modified: | Jul 17 03:59:39 2007 |
| MD5 Checksum: | ea904b14fb750d9e8ca6fbf82ef36f22 |
|
| /// File Name: |
sa26074.txt |
Description:
|
Secunia Security Advisory - Robert Swiecki has discovered a vulnerability in Opera, which can be exploited by malicious people to conduct spoofing attacks.
| | Homepage: | http://secunia.com/advisories/26074/ | | File Size: | 2324 | | Last Modified: | Jul 17 03:59:39 2007 |
| MD5 Checksum: | 9fca11a26a6ab083b9a426d485067e72 |
|
| /// File Name: |
sa26070.txt |
Description:
|
Secunia Security Advisory - GeFORC3 has reported a vulnerability in MzK Blog, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/26070/ | | File Size: | 2229 | | Last Modified: | Jul 17 03:59:39 2007 |
| MD5 Checksum: | 912ddc8980cce3753e10c660480ca990 |
|
| /// File Name: |
sa26069.txt |
Description:
|
Secunia Security Advisory - Michal Zalewski has discovered a vulnerability in Internet Explorer, which can be exploited by a malicious website to spoof the address bar.
| | Homepage: | http://secunia.com/advisories/26069/ | | File Size: | 2438 | | Last Modified: | Jul 17 03:59:39 2007 |
| MD5 Checksum: | 13f23a619ea26690729fc5075080ae03 |
|
| /// File Name: |
sa26068.txt |
Description:
|
Secunia Security Advisory - t0pP8uZz and xprog have discovered a vulnerability in Realtor 747, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/26068/ | | File Size: | 2294 | | Last Modified: | Jul 17 03:59:39 2007 |
| MD5 Checksum: | dbff5f5b0d7d23b79b270c8fe7ae955a |
|
| /// File Name: |
sa26051.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in HP ServiceGuard for Linux, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/26051/ | | File Size: | 2542 | | Last Modified: | Jul 17 03:59:39 2007 |
| MD5 Checksum: | ad0e308bd170a1d2d0e1d60f6c445b8e |
|
| /// File Name: |
sa26012.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for libnet-dns-perl. This fixes two vulnerabilities, which can be exploited to poison the DNS cache or to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/26012/ | | File Size: | 4666 | | Last Modified: | Jul 17 03:59:39 2007 |
| MD5 Checksum: | 233bde8a7a1ba29c157bc5452077d230 |
|
| /// File Name: |
sa26005.txt |
Description:
|
Secunia Security Advisory - Daniel Weber has reported a vulnerability in eSoft InstaGate, which can be exploited by malicious people to conduct cross-site request forgery attacks.
| | Homepage: | http://secunia.com/advisories/26005/ | | File Size: | 2468 | | Last Modified: | Jul 17 03:59:39 2007 |
| MD5 Checksum: | 2ca5455f165d7eeed10cfcbcc83b8faf |
|
| /// File Name: |
sa25979.txt |
Description:
|
Secunia Security Advisory - Alex Hernandez has reported some vulnerabilities in Proventia GX5108 and GX5008, which potentially can be exploited by malicious people to conduct cross-site scripting attacks and compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/25979/ | | File Size: | 3052 | | Last Modified: | Jul 17 03:59:39 2007 |
| MD5 Checksum: | b339b564df0fd3dd2a7d1efa6fbc9573 |
|
| /// File Name: |
sa25739.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been discovered in CinePlayer, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/25739/ | | File Size: | 2179 | | Last Modified: | Jul 17 03:59:39 2007 |
| MD5 Checksum: | 02acd1ff7cd199b141ed42267dd054d0 |
|
| /// File Name: |
sa25718.txt |
Description:
|
Secunia Security Advisory - Parvez Anwar has discovered two vulnerabilities in InterActual Player, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/25718/ | | File Size: | 2634 | | Last Modified: | Jul 17 03:59:39 2007 |
| MD5 Checksum: | 4234a11805a0f3cc4d0e4bdf2a75d11c |
|
|
|
|
|