Section: .. / 0707-advisories /
| /// File Name: |
sa26111.txt |
Description:
|
Secunia Security Advisory - A vulnerability with unknown impact has been reported in uFMOD.
| | Homepage: | http://secunia.com/advisories/26111/ | | File Size: | 2004 | | Last Modified: | Jul 21 04:11:22 2007 |
| MD5 Checksum: | 1363b2bd8e827f5307e64db0263b9358 |
|
| /// File Name: |
PR07-20.txt |
Description:
|
A path disclosure issue exists in Webbler CMS version 3.1.3.
| | Author: | Adrian Pastor | | File Size: | 1955 | | Last Modified: | Jul 25 05:51:25 2007 |
| MD5 Checksum: | 26b734c5ceb88073b75a5c716a2295ba |
|
| /// File Name: |
NGS-ad.txt |
Description:
|
NGSSoftware has discovered a low risk vulnerability in Active Directory which can allow an unauthenticated user to cause a denial of service condition on any affected system.
| | Author: | Peter Winter-Smith | | Homepage: | http://www.ngssoftware.com/ | | File Size: | 1891 | | Last Modified: | Jul 12 03:13:07 2007 |
| MD5 Checksum: | eca80fa6cf0664aee3fd00b9720dc2cb |
|
| /// File Name: |
vauninstall-06_45.txt |
Description:
|
The Visionsoft Audit VSAOD server allows unauthenticated remote uninstalls.
| | Author: | Tim Brown | | Homepage: | http://www.portcullis-security.com/ | | File Size: | 1853 | | Last Modified: | Jul 11 10:22:51 2007 |
| MD5 Checksum: | b7946225f4438b008477609fbb64f020 |
|
| /// File Name: |
oracle-multi.txt |
Description:
|
Multiple security vulnerabilities have been corrected in the Oracle Business Suite 11i and R12 as part of July 2007 Oracle Critical Patch Update (CPU). These include SQL injection and cross site scripting vulnerabilities.
| | Author: | Stephen Kost, Jack Kanter | | Homepage: | http://www.integrigy.com/ | | File Size: | 1820 | | Related CVE(s): | CVE-2007-3865, CVE-2007-3866, CVE-2007-3867 | | Last Modified: | Jul 25 05:29:49 2007 |
| MD5 Checksum: | cfd22abaee53757319f1db989c571c46 |
|
| /// File Name: |
psinjection-06_056.txt |
Description:
|
The P-Synch Windows domain password reset web applications style parameter allows JavaScript injection.
| | Author: | Tim Brown | | Homepage: | http://www.portcullis-security.com/ | | File Size: | 1812 | | Last Modified: | Jul 11 10:24:35 2007 |
| MD5 Checksum: | 3e7ebc2ba727e8a635d76f0e70bd1136 |
|
| /// File Name: |
wsftp75290-dos.txt |
Description:
|
IPSwitch WS_FTP Logging server version 7.5.29.0 suffers from a remote denial of service vulnerability.
| | Author: | Justin Seitz | | File Size: | 1804 | | Last Modified: | Jul 13 03:05:04 2007 |
| MD5 Checksum: | cbbaf70f189bb4b9afcda66966358fa9 |
|
| /// File Name: |
DRUPAL-SA-2007-017.txt |
Description:
|
Drupal security advisory - Several parts in Drupal core are not protected against cross site request forgeries due to improper use of the Forms API, or by taking action solely on GET requests. Malicious users are able to delete comments and content revisions and disable menu items by enticing a privileged users to visit certain URLs while the victim is logged-in to the targeted site. Drupal versions 5.x below 5.2 are affected.
| | Author: | Heine Deelstra | | Homepage: | http://drupal.org/security | | File Size: | 1786 | | Last Modified: | Jul 31 08:06:12 2007 |
| MD5 Checksum: | b734838a39dd108a42a7f302a14031cf |
|
| /// File Name: |
ledgersmb-bypass.txt |
Description:
|
LedgerSMB versions 1.2.0 through 1.2.6 suffer from an authentication bypass.
| | Author: | Chris Travers | | File Size: | 1775 | | Last Modified: | Jul 19 05:09:41 2007 |
| MD5 Checksum: | da593cf217e1cd7ff7d1ecd11e8c035a |
|
| /// File Name: |
easql-06-057.txt |
Description:
|
eVisit Analyst is susceptible to SQL injection vulnerabilities.
| | Author: | Tim Brown | | Homepage: | http://www.portcullis-security.com/ | | File Size: | 1704 | | Last Modified: | Jul 11 10:25:41 2007 |
| MD5 Checksum: | f38be95649827042f62cfc989acffee7 |
|
| /// File Name: |
phlogger-sql.txt |
Description:
|
Power Phlogger version 2.2.5 suffers from a SQL injection vulnerability.
| | Author: | Attila Gerendi | | File Size: | 1665 | | Last Modified: | Jul 7 04:37:32 2007 |
| MD5 Checksum: | 954077bec66ecb88271007d156d74209 |
|
| /// File Name: |
ie-entrap.txt |
Description:
|
It appears that Microsoft Internet Explorer suffers from a browser entrapment vulnerability in document.open() calls.
| | Author: | Michal Zalewski | | Homepage: | http://lcamtuf.coredump.cx/ | | File Size: | 1638 | | Last Modified: | Jul 17 09:22:12 2007 |
| MD5 Checksum: | a8e4a0a8e6bbda99cf4f77e69923c24c |
|
| /// File Name: |
wyciwyg.txt |
Description:
|
A vulnerability exists in how Mozilla Firefox handles internal wyciwyg:// pseudo-URIs.
| | Author: | Michal Zalewski | | Homepage: | http://lcamtuf.coredump.cx/ | | File Size: | 1435 | | Last Modified: | Jul 10 05:04:59 2007 |
| MD5 Checksum: | abfc62b40701ed2d0de2a1efeaf77641 |
|
| /// File Name: |
encase-broken.txt |
Description:
|
Encase version 5.0 suffers from a vulnerability in the file parsing engine.
| | Homepage: | http://www.breakpointsecurity.net/ | | File Size: | 1343 | | Last Modified: | Jul 28 04:22:49 2007 |
| MD5 Checksum: | 46a92cd482e5b7b137ab999631da874b |
|
| /// File Name: |
opera-redirect.txt |
Description:
|
Opera / Konqueror suffers from an arbitrary redirection vulnerability. It appears that Opera 9.21 and Konqueror 3.5.7 are susceptible.
| | Author: | Robert Swiecki | | Homepage: | http://alt.swiecki.net/ | | File Size: | 1196 | | Last Modified: | Jul 17 09:24:53 2007 |
| MD5 Checksum: | df62c3606813ff0419901df0c1610fe1 |
|
| /// File Name: |
homestay-xss.txt |
Description:
|
There is a cross site scripting vulnerability in HomestayFinder's Dictionary.aspx script which is responsible for mirroring the content of Wikipedia.
| | Author: | Susam Pal | | Homepage: | http://susam.in/ | | File Size: | 1046 | | Last Modified: | Jul 11 11:04:30 2007 |
| MD5 Checksum: | 40f59e1bd0d95cad11c1deace7149165 |
|
| /// File Name: |
meta-clamav.txt |
Description:
|
ClamAV versions below 0.91 crash while processing corrupted RAR files causing a null pointer dereference.
| | Homepage: | http://www.metaeye.org/ | | File Size: | 1032 | | Last Modified: | Jul 12 03:52:54 2007 |
| MD5 Checksum: | babbeec796bbc4352f24f68c1ddd8bf6 |
|
| /// File Name: |
CVE-2007-3383.txt |
Description:
|
Tomcat versions 4.0.0 to 4.0.6 and 4.1.0 to 4.1.36 suffer from a cross site scripting vulnerability.
| | Author: | Tomasz Kuczynski | | Homepage: | http://tomcat.apache.org/ | | File Size: | 972 | | Last Modified: | Jul 23 06:28:14 2007 |
| MD5 Checksum: | 6437db7a26ce9d7dc98afa56756dee11 |
|
| /// File Name: |
blizzard-sanity.txt |
Description:
|
Blizzard.com fails to properly sanitize user supplied input allow for information disclosure attacks.
| | Author: | kefka | | File Size: | 942 | | Last Modified: | Jul 3 02:56:57 2007 |
| MD5 Checksum: | f33730885fccc5c55f09d2847a78a347 |
|
|
|
|
|