Section: .. / 0702-advisories /
| /// File Name: |
ublog-inject.txt |
Description:
|
Ublog Reload version 1.0.5 suffers from multiple html injection vulnerabilities.
| | Author: | Doz | | Homepage: | http://www.hackerscenter.com/ | | File Size: | 1406 | | Last Modified: | Feb 5 23:58:23 2007 |
| MD5 Checksum: | ea4329422981a57a2c37faeda06c9630 |
|
| /// File Name: |
comodofp.txt |
Description:
|
Comodo Firewall Pro (former Comodo Personal Firewall) implements a component control, which is based on a checksum comparison of process modules. Probably to achieve a better performance, cyclic redundancy check (CRC32) is used as a checksum function in its implementation. However, CRC32 was developed for error detection purposes and can not be used as a reliable cryptographic hashing function because it is possible to generate collisions in real time.
| | Homepage: | http://www.matousec.com/ | | File Size: | 1299 | | Last Modified: | Feb 16 02:50:00 2007 |
| MD5 Checksum: | 09a26a30d9a7113a40ac361ea315efe6 |
|
| /// File Name: |
firefox-bookmark.txt |
Description:
|
There is an interesting vulnerability in how Firefox handles bookmarks. The flaw allows the attacker to steal credentials from commonly used browser start sites.
| | Author: | Michal Zalewski | | Homepage: | http://lcamtuf.coredump.cx/ | | File Size: | 1270 | | Last Modified: | Feb 23 20:45:50 2007 |
| MD5 Checksum: | a0329b99dae1c0984225a5d60d36c5a8 |
|
| /// File Name: |
ipswitch504-exec.txt |
Description:
|
Ipswitch WS_FTP Server version 5.04 suffers from multiple arbitrary code execution vulnerabilities.
| | Author: | sapheal | | File Size: | 1256 | | Last Modified: | Feb 5 23:12:11 2007 |
| MD5 Checksum: | 41c3dc01b6ba7b5d157817bca31c3260 |
|
| /// File Name: |
BTP00000P005CF.txt |
Description:
|
Comodo Firewall Pro (former Comodo Personal Firewall) hooks many functions in SSDT and in at least seven cases it fails to validate arguments that come from the user mode. Affected versions include Comodo Firewall Pro 2.4.16.174 and Comodo Personal Firewall 2.3.6.81.
| | Homepage: | http://www.matousec.com/ | | Related Exploit: | BTP00000P005CF.zip | | File Size: | 1169 | | Last Modified: | Feb 5 23:05:13 2007 |
| MD5 Checksum: | 70dbf1a4a2904f73f4f89fba108d3b43 |
|
| /// File Name: |
qwik-format.txt |
Description:
|
qwik-smtpd suffers from a format string vulnerability.
| | Author: | H0tTurk- | | File Size: | 1168 | | Last Modified: | Feb 22 21:53:23 2007 |
| MD5 Checksum: | 3a1b56e6ea8a4bcf5582517a6d35de6c |
|
| /// File Name: |
iemobile-dos.txt |
Description:
|
A denial of service condition exists in Internet Explorer for Microsoft Windows Mobile 5.0.
| | Author: | Michael Kemp | | Homepage: | http://www.clappymonkey.com | | File Size: | 1082 | | Last Modified: | Feb 13 01:05:26 2007 |
| MD5 Checksum: | 69ebbdf1c60ed96cd83a7f8e486f8287 |
|
| /// File Name: |
jbossvuln.txt |
Description:
|
JBoss suffers from a flaw that allows for unauthenticated access to the backend application that controls related data.
| | Author: | Ben Dexter | | File Size: | 1076 | | Last Modified: | Feb 23 18:00:39 2007 |
| MD5 Checksum: | fabf0bdec3eec553d4c785dd2b18d3d9 |
|
| /// File Name: |
vbulletin364-xss.txt |
Description:
|
vBulletin version 3.6.4 is susceptible to cross site scripting flaws in multiple functions in index.php.
| | Author: | Doz | | Homepage: | http://www.hackerscenter.com/ | | File Size: | 1038 | | Last Modified: | Feb 7 23:50:03 2007 |
| MD5 Checksum: | 42460c9ee20fdccc009e9f0d01752bf0 |
|
| /// File Name: |
ls-setgid.txt |
Description:
|
It appears that /bin/ls has slipped into the linux-ftpd distribution for Debian as setgid 0. This could possibly be used to leverage root group access.
| | Author: | Paul Szabo | | Homepage: | http://www.maths.usyd.edu.au/u/psz/ | | File Size: | 691 | | Last Modified: | Feb 23 19:00:05 2007 |
| MD5 Checksum: | 1c1ac6b027563fb2b5c07a86e4ae4302 |
|
| /// File Name: |
pwg141-xss.txt |
Description:
|
PHPWebGallery version 1.4.1 suffers from multiple cross site scripting flaws.
| | Author: | Simon Bonnard | | File Size: | 509 | | Last Modified: | Feb 27 19:46:27 2007 |
| MD5 Checksum: | a55343f4a4fdbf73b3fb8c0d1d3e425f |
|
| /// File Name: |
mtcms.txt |
Description:
|
MTCMS version 2.2 suffers from upload and cross site scripting vulnerabilities.
| | Author: | laurent gaffi | | File Size: | 443 | | Last Modified: | Feb 27 19:32:29 2007 |
| MD5 Checksum: | bb98b497f1080db42973e68d02402849 |
|
|
|
|
|