SecurityFocus Newsletter #328

Peter Laborge <[email protected]> Tue, 13 Dec 2005 17:01:02 -0700
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #328
----------------------------------------

This Issue is Sponsored By: SpiDynamics

ALERT:  "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!"- White Paper
The newest web app vulnerability. Blind SQL Injection!
Even if your web application does not return error messages, it may still be open to a Blind SQL Injection Attack.
Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and
manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a 
complete guide to protection! 

https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701300000003Har

------------------------------------------------------------------
I.    FRONT AND CENTER
       1. Trusting software
       2. Users inundated with pop-ups
II.   BUGTRAQ SUMMARY
       1. Sobexsrv Dosyslog Remote Format String Vulnerability
       2. InfinetSoftware MyTemplateSite Search.ASP Cross-Site Scripting Vulnerability
       3. Absolute Shopping Package Solutions Shopping Cart Multiple Cross-Site Scripting Vulnerabilities
       4. Solupress News Search.ASP Cross-Site Scripting Vulnerability
       5. SiteBeater MP3 Catalog Search.ASP Cross-Site Scripting Vulnerability
       6. SiteBeater News Archive.ASP Cross-Site Scripting Vulnerability
       7. PHP-Fusion Messages.PHP SQL Injection Vulnerability
       8. Alisveristr E-commerce Login Multiple SQL Injection Vulnerabilities
       9. PHPYellowTM Multiple SQL Injection Vulnerabilities
       10. Widget Press Widget Property Property.PHP SQL Injection Vulnerability
       11. Web4Future KeyWord Frequency Counter Cross-Site Scripting Vulnerability
       12. MediaWiki User Language Remote Code Execution Vulnerability
       13. Nodezilla Evl_Data Directory Unauthorized Access Vulnerability
       14. Easy Search System Search.cgi Cross-Site Scripting Vulnerability
       15. FileLister Definesearch.JSP Cross-SIte Scripting Vulnerability
       16. Web4Future eCommerce Enterprise Edition Multiple SQL Injection Vulnerabilities
       17. Mr CGI Guy Multiple Software Search.CGI Cross-Site Scripting Vulnerability
       18. SAMEDIA Landshop Multiple SQL Injection Vulnerabilities
       19. Quicksilver Forums SQL Injection Vulnerability
       20. MultiTech MultiVOIP INVITE Remote Buffer Overflow Vulnerability
       21. 1-Script 1-Search 1search.CGI Cross-Site Scripting Vulnerability
       22. Hobosworld HobSR Multiple SQL Injection Vulnerabilities
       23. Relative Real Estate Systems SQL Injection Vulnerability
       24. Web4Future eDating Professional Multiple SQL Injection Vulnerabilities
       25. Web4Future Portal Solutions Comentarii.PHP SQL Injection Vulnerability
       26. Web4Future Affiliate Manager PRO Functions.PHP SQL Injection Vulnerability
       27. Web4Future Portal Solutions Arhiva.PHP Directory Traversal Vulnerability
       28. Blog System Multiple SQL Injection Vulnerabilities
       29. Edgewall Software Trac Search Module SQL Injection Vulnerability
       30. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
       31. PluggedOut Nexus Search Script Input Validation Vulnerabilities
       32. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
       33. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
       34. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
       35. Sun Java System Application Server Reverse SSL Proxy Plug-in Man In The Middle Vulnerability
       36. Linux Kernel IPv6 FlowLable Denial Of Service Vulnerability
       37. Horde IMP Email Attachments HTML Injection Vulnerability
       38. DuWare DuPortalPro Password.ASP Cross-Site Scripting Vulnerability
       39. Sun Communications Services Delegated Administrator Default Password Disclosure Vulnerability
       40. IISWorks ASPKnowledgeBase KB.ASP Cross-Site Scripting Vulnerability
       41. PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
       42. PHPForumPro Multiple SQL Injection Vulnerabilities
       43. NetauctionHelp Multiple Cross-Site Scripting Vulnerabilities
       44. XcClassified CPSearch.ASP Cross-Site Scripting Vulnerability
       45. XcPhotoAlbum  PASearch.ASP Cross-Site Scripting Vulnerability
       46. RWAuction Pro Search.ASP Cross-Site Scripting Vulnerability
       47. A-FAQ Multiple SQL Injection Vulnerabilities
       48. DoceboLMS Connector.PHP Directory Traversal Vulnerability
       49. FFmpeg LibAVCodec Heap Buffer Overflow Vulnerability
       50. DoceboLMS Arbitrary File Upload Vulnerability
       51. PluggedOut Blog Index.PHP Multiple SQL Injection Vulnerabilities
       52. Cars Portal Index.PHP Multiple SQL Injection Vulnerabilities
       53. e107 Website System Voting Manipulation Vulnerability
       54. Multiple Vendor BIOS Password Persistence Weakness
       55. Ipswitch Collaboration Suite and IMail Server SMTPD Remote Format String Vulnerability
       56. Ipswitch Collaboration Suite and IMail Server IMAPD LIST Command Denial Of Service Vulnerability
       57. Sony SunnComm MediaMax Insecure Directory Permissions Vulnerability
       58. Appfluent Technology Database IDS APPFLUENT_HOME Variable Buffer Overflow Vulnerability
       59. cURL / libcURL URL Parser Buffer Overflow Vulnerability
       60. Check Point VPN-1 SecureClient Policy Bypass Vulnerability
       61. IBM AIX UMOUNTALL Unspecified Absolute Path Security Vulnerability
       62. HP-UX Unspecified IPSec Unauthorized Remote Access Vulnerability
       63. SugarCRM Sugar Suite Remote and Local File Include Vulnerabilities
       64. PHPMyAdmin Import_Blacklist Variable Overwrite Vulnerability
       65. Apache MPM Worker.C Denial Of Service Vulnerability
       66. ThWboard Multiple Input Validation Vulnerabilities
       67. SimpleBBS Remote Arbitrary Command Execution Vulnerability
       68. Apache James Spooler Memory Leak Denial Of Service Vulnerability
       69. DRZES HMS Login.PHP Cross-Site Scripting Vulnerability
       70. ASPMForum Multiple SQL Injection Vulnerabilities
       71. Dell TrueMobile 2300 Remote Credential Reset Vulnerability
       72. Courier Mail Server Unauthorized Access Vulnerability
       73. Sun Solaris Sun Update Connection Web Proxy Password Disclosure Vulnerability
       74. Mozilla Firefox Large History File Buffer Overflow Vulnerability
       75. CFMagic Multiple Products Input Validation Vulnerabilities
       76. Soti Pocket Controller-Professional Remote Command Execution Vulnerability
       77. Website Baker SQL Injection Vulnerability
       78. CF_Nuke Index.CFM Local File Include Vulnerability
       79. CF_Nuke Index.CFM Cross-Site Scripting Vulnerabilities
       80. ACME Perl-Cal Cal_make.PL Cross-Site Scripting Vulnerability
       81. Microsoft Excel Unspecified Memory Corruption Vulnerability
       82. Microsoft December Advance Notification Unspecified Security Vulnerabilities 
       83. Computer Associates CleverPath Portal Login Page Cross-Site Scripting Vulnerability
       84. PGP Desktop Wipe Free Space Assistant Improper Disk Wipe Vulnerability
       85. QNX RTOS Unspecified Local DHCP.Client Vulnerability
       86. Lyris ListManager Command Execution Vulnerability
       87. Lyris ListManager Multiple SQL Injection Vulnerabilities
       88. Lyris Listmanager TCLHTTPd Service Multiple Information Disclosure Vulnerabilities
       89. Lyris ListManager Hidden Variable Information Disclosure Vulnerability
       90. Contenido CMS Unspecified Remote Command Execution Vulnerability
       91. MilliScripts Register.PHP Cross-Site Scripting Vulnerability
       92. MyBB Multiple Unspecified Vulnerabilities
       93. Ethereal OSPF Protocol Dissection Stack Buffer Overflow Vulnerability
       94. Motorola SB5100E Cable Modem LanD Packet Denial Of Service Vulnerability
       95. Flatnuke Index.PHP Directory Traversal Vulnerability
       96. APANI Networks EpiForce Agent Denial Of Service Vulnerability
III.  SECURITYFOCUS NEWS
       1. eBay pulls vulnerability auction
       2. Consumers improving security, but gaps remain
       3. Federal flaw database commits to grading system
       4. Mac OS X security under scrutiny
       5. Skype under scrutiny for bugs
       6. Say hello to the Skype Trojan
       7. Shared music abuse bug hits iTunes
       8. US cybersecurity all at sea
IV.   SECURITY JOBS LIST SUMMARY
       1. [SJ-JOB] VP of Regional Sales, Southern California
       2. [SJ-JOB] Security Engineer, Charlottesville
       3. [SJ-JOB] Sr. Security Analyst, Nashville
       4. [SJ-JOB] Security System Administrator, Laurel
       5. [SJ-JOB] Developer, Superior
       6. [SJ-JOB] Sr. Security Analyst, London - UK Wide
       7. [SJ-JOB] Disaster Recovery Coordinator, London
       8. [SJ-JOB] Security Architect, Reading / London
       9. [SJ-JOB] Security System Administrator, Basel
       10. [SJ-JOB] Security Consultant, Dubai
       11. [SJ-JOB] Security Consultant, Riyadh
       12. [SJ-JOB] Sr. Security Engineer, San Mateo
       13. [SJ-JOB] Jr. Security Analyst, Seoul
       14. [SJ-JOB] Developer, San Mateo
       15. [SJ-JOB] Customer Support, Superior
       16. [SJ-JOB] Customer Support, Superior
       17. [SJ-JOB] Quality Assurance, Calgary
       18. [SJ-JOB] Quality Assurance, Superior
       19. [SJ-JOB] Quality Assurance, Santa Clara
       20. [SJ-JOB] Manager, Information Security, New York
       21. [SJ-JOB] Channel / Business Development, Riyadh
       22. [SJ-JOB] Security Architect, Berkshire / Hampshire
       23. [SJ-JOB] Security Engineer, Ann Arbor
       24. [SJ-JOB] Manager, Information Security, Dubai
       25. [SJ-JOB] Security Engineer, Paris / Evry
       26. [SJ-JOB] Security Researcher, Atlanta
       27. [SJ-JOB] Information Assurance Analyst, Columbia
       28. [SJ-JOB] Sr. Security Engineer, Washington
       29. [SJ-JOB] Information Assurance Engineer, Washington
       30. [SJ-JOB] Information Assurance Engineer, Washington
       31. [SJ-JOB] Developer, Pasadena
       32. [SJ-JOB] Disaster Recovery Coordinator, Arlington
       33. [SJ-JOB] Sales Representative, Chicago
       34. [SJ-JOB] Security Architect, Arlington
       35. [SJ-JOB] Certification & Accreditation Engineer, Washington
       36. [SJ-JOB] Security Engineer, Washington DC
       37. [SJ-JOB] Sr. Security Analyst, Cupertino
       38. [SJ-JOB] Security Engineer, Washington DC
       39. [SJ-JOB] Sales Engineer, Cupertino
       40. [SJ-JOB] Security Researcher, Cupertino
       41. [SJ-JOB] Security System Administrator, Austin
       42. [SJ-JOB] Security Engineer, Washington DC
       43. [SJ-JOB] Security System Administrator, Austin
       44. [SJ-JOB] Director, Information Security, Sunnyvale
       45. [SJ-JOB] Sr. Security Engineer, Mountain View
       46. [SJ-JOB] Security System Administrator, London
       47. [SJ-JOB] Security Consultant, DC
       48. [SJ-JOB] Application Security Engineer, Tel Aviv
       49. [SJ-JOB] Information Assurance Engineer, Washington
       50. [SJ-JOB] Security Product Manager, San Diego
       51. [SJ-JOB] Certification & Accreditation Engineer, Washington
       52. [SJ-JOB] Security Auditor, Washington
       53. [SJ-JOB] Disaster Recovery Coordinator, Washington
       54. [SJ-JOB] Security Engineer, Rockville
       55. [SJ-JOB] Director, Information Security, Kirkland
V.    INCIDENTS LIST SUMMARY
       1. New (maybe old?) PhpBB worm about?
       2. hacked server, DDoS bin installed
VI.   VULN-DEV RESEARCH LIST SUMMARY
       1. Reviews on Microsoft Communications Protocol Program (MCPP)
       2. (stupid one) physical security of remotes?
       3. ESI Manipulation?
       4. -Exploiting Freelist[0] On Windows XP Service Pack 2-
       5. Critical Myspace.com Vulnerabilites
VII.  MICROSOFT FOCUS LIST SUMMARY
       1. IIS Script source access  permission and NTFS DACLs
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Trusting software
By Jason Miller
rust is in everything we do, from the important to the mundane. Whether it's open-source or closed-source, how do we evaluate what software, companies and projects are safe to trust?
http://www.securityfocus.com/columnists/373

2. Users inundated with pop-ups
By Scott Granneman
There are many examples where users are now being inundated with pop-up messages asking them to respond to things they don't know about or don't understand, and it leads to weaker security overall.
http://www.securityfocus.com/columnists/374


II.  BUGTRAQ SUMMARY
--------------------
1. Sobexsrv Dosyslog Remote Format String Vulnerability
BugTraq ID: 15692
Remote: Yes
Date Published: 2005-12-03
Relevant URL: http://www.securityfocus.com/bid/15692
Summary:
sobexsrv is prone to a remote format string vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation can facilitate a crash or arbitrary code execution in the context of affected server application.

2. InfinetSoftware MyTemplateSite Search.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 15693
Remote: Yes
Date Published: 2005-12-03
Relevant URL: http://www.securityfocus.com/bid/15693
Summary:
MyTemplateSite is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

3. Absolute Shopping Package Solutions Shopping Cart Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 15694
Remote: Yes
Date Published: 2005-12-03
Relevant URL: http://www.securityfocus.com/bid/15694
Summary:
ASPS Shopping Cart is prone to multiple cross-site scripting vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

4. Solupress News Search.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 15695
Remote: Yes
Date Published: 2005-12-03
Relevant URL: http://www.securityfocus.com/bid/15695
Summary:
Solupress News is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

5. SiteBeater MP3 Catalog Search.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 15696
Remote: Yes
Date Published: 2005-12-03
Relevant URL: http://www.securityfocus.com/bid/15696
Summary:
MP3 Catalog is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

6. SiteBeater News Archive.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 15697
Remote: Yes
Date Published: 2005-12-03
Relevant URL: http://www.securityfocus.com/bid/15697
Summary:
SiteBeater News is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

7. PHP-Fusion Messages.PHP SQL Injection Vulnerability
BugTraq ID: 15698
Remote: Yes
Date Published: 2005-12-03
Relevant URL: http://www.securityfocus.com/bid/15698
Summary:
PHP-Fusion is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

8. Alisveristr E-commerce Login Multiple SQL Injection Vulnerabilities
BugTraq ID: 15699
Remote: Yes
Date Published: 2005-12-03
Relevant URL: http://www.securityfocus.com/bid/15699
Summary:
Alisveristr E-commerce is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

9. PHPYellowTM Multiple SQL Injection Vulnerabilities
BugTraq ID: 15700
Remote: Yes
Date Published: 2005-12-03
Relevant URL: http://www.securityfocus.com/bid/15700
Summary:
phpYellowTM is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

10. Widget Press Widget Property Property.PHP SQL Injection Vulnerability
BugTraq ID: 15701
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15701
Summary:
Widget Press Widget Property is prone to an SQL injection vulnerability. 

This issue is due to a failure in the application to properly sanitize user-supplied input to the 'property.php' script before using it in an SQL query. 

This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.

Widget Property 1.1.19 is reportedly vulnerable.  Other versions may be affected as well.

11. Web4Future KeyWord Frequency Counter Cross-Site Scripting Vulnerability
BugTraq ID: 15702
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15702
Summary:
Web4Future KeyWord Frequency Counter is prone to a cross-site scripting vulnerability.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


12. MediaWiki User Language Remote Code Execution Vulnerability
BugTraq ID: 15703
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15703
Summary:
MediaWiki is prone to a remote code execution vulnerability. This is due to a lack of proper sanitization of user-supplied input.

An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the Web server process.

Successful exploitation could facilitate unauthorized access; other attacks are also possible.


13. Nodezilla Evl_Data Directory Unauthorized Access Vulnerability
BugTraq ID: 15704
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15704
Summary:
Nodezilla is prone to an unauthorized access vulnerability.  This issue is due to a failure in the application to restrict access to sensitive files.

An attacker can exploit this issue to gain access to sensitive and privileged information.  Information obtained may aid the malicious user in further attacks against the vulnerable application and possibly the underlying system.

14. Easy Search System Search.cgi Cross-Site Scripting Vulnerability
BugTraq ID: 15705
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15705
Summary:
Easy Search System is prone to a cross-site scripting vulnerability.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


15. FileLister Definesearch.JSP Cross-SIte Scripting Vulnerability
BugTraq ID: 15706
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15706
Summary:
FileLister is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


16. Web4Future eCommerce Enterprise Edition Multiple SQL Injection Vulnerabilities
BugTraq ID: 15707
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15707
Summary:
eCommerce Enterprise Edition is prone to multiple SQL injection vulnerabilities.

These vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks. 

eCommerce Enterprise Edition 2.1 and prior and eCommerce Home Edition are vulnerable to these issues.

17. Mr CGI Guy Multiple Software Search.CGI Cross-Site Scripting Vulnerability
BugTraq ID: 15708
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15708
Summary:
Multiple Mr CGI Guy software are prone to a cross-site scripting vulnerability.  This issue is due to a failure in the applications to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


18. SAMEDIA Landshop Multiple SQL Injection Vulnerabilities
BugTraq ID: 15709
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15709
Summary:
Landshop is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

19. Quicksilver Forums SQL Injection Vulnerability
BugTraq ID: 15710
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15710
Summary:
Quicksilver Forums is prone to an SQL injection vulnerability. 

This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. 

This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.

Quicksilver Forums versions prior to 1.1.5 are vulnerable to this issue.

20. MultiTech MultiVOIP INVITE Remote Buffer Overflow Vulnerability
BugTraq ID: 15711
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15711
Summary:
MultiTech MultiVOIP devices are prone to a remotely exploitable buffer overflow vulnerability.  Successful exploitation could result in a denial of service or potential arbitrary code execution.

This vulnerability may also be present in third-party devices that implement the MultiTech VOIP Gateway and protocol stack.


21. 1-Script 1-Search 1search.CGI Cross-Site Scripting Vulnerability
BugTraq ID: 15712
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15712
Summary:
1-Search is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Versions 1.80 and prior are affected; other versions may also be vulnerable.


22. Hobosworld HobSR Multiple SQL Injection Vulnerabilities
BugTraq ID: 15713
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15713
Summary:
Hobosworld HobSR is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

23. Relative Real Estate Systems SQL Injection Vulnerability
BugTraq ID: 15714
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15714
Summary:
Relative Real Estate Systems is prone to an SQL injection vulnerability. 

This issue is due to a failure in the application to properly sanitize user-supplied input to the 'index.php' script before using it in an SQL query. 

This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.

24. Web4Future eDating Professional Multiple SQL Injection Vulnerabilities
BugTraq ID: 15715
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15715
Summary:
eDating Professional is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

Versions 5 and prior are vulnerable; other versions may also be affected.

25. Web4Future Portal Solutions Comentarii.PHP SQL Injection Vulnerability
BugTraq ID: 15716
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15716
Summary:
Portal Solutions is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


26. Web4Future Affiliate Manager PRO Functions.PHP SQL Injection Vulnerability
BugTraq ID: 15717
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15717
Summary:
Affiliate Manager PRO is prone to an SQL injection vulnerability.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


27. Web4Future Portal Solutions Arhiva.PHP Directory Traversal Vulnerability
BugTraq ID: 15718
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15718
Summary:
Portal Solutions is prone to a directory traversal vulnerability. This is due to a lack of proper sanitization of user-supplied input.

This issue may be leveraged to read arbitrary files on an affected computer with the privileges of the Web server.  An attacker can employ directory traversal sequences to disclose arbitrary files.


28. Blog System Multiple SQL Injection Vulnerabilities
BugTraq ID: 15719
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15719
Summary:
Blog System is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

29. Edgewall Software Trac Search Module SQL Injection Vulnerability
BugTraq ID: 15720
Remote: Yes
Date Published: 2005-12-05
Relevant URL: http://www.securityfocus.com/bid/15720
Summary:
Trac is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

30. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:
xpdf is reported prone to a remote buffer overflow vulnerability. This issue exists because the applications fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer. 

It is reported that this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file.

This issue is reported to affect xpdf 3.01, however, it is likely that earlier versions are prone to this vulnerability as well.  Applications using embedded xpdf code may be vulnerable to this issue as well.

kpdf reportedly incorporates vulnerable xpdf code.  Version 0.5 of kpdf is prone to this issue, however, other versions may also be affected.


31. PluggedOut Nexus Search Script Input Validation Vulnerabilities
BugTraq ID: 15724
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15724
Summary:
PluggedOut Nexus is prone to multiple input validation vulnerabilities.  These issues could permit HTML injection and SQL injection attacks.

In the case of the HTML injection vulnerabilities, these issues could let a remote attacker execute hostile HTML and script code in the browser session of a user of the affected site.  This could permit attackers to steal cookie-based authentication credentials.  Other attacks are also possible.

The SQL injection vulnerabilities could permit an attacker to influence the structure and logic of SQL queries made by the application.  This could be exploited to compromise the application or gain unauthorized database access.

32. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15725
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15725
Summary:
xpdf is reported prone to a remote buffer overflow vulnerability. This issue exists because the applications fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer. 

It is reported that this issue presents itself in the 'StreamPredictor::StreamPredictor' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, however, it is likely that earlier versions are prone to this vulnerability as well.  Applications using embedded xpdf code may be vulnerable to this issue as well.

pdftohtml also includes vulnerable versions of xpdf.  Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.

kpdf reportedly incorporates vulnerable xpdf code.  Version 0.5 of kpdf is prone to this issue, however, other versions may also be affected.



33. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15726
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15726
Summary:
xpdf is reported prone to a remote buffer overflow vulnerability. This issue exists because the applications fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer. 

It is reported that this issue presents itself in the 'DCTStream::readProgressiveSOF' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, however, it is likely that earlier versions are prone to this vulnerability as well.  Applications using embedded xpdf code may be vulnerable to this issue as well.

pdftohtml also includes vulnerable versions of xpdf.  Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.

kpdf reportedly incorporates vulnerable xpdf code.  Version 0.5 of kpdf is prone to this issue, however, other versions may also be affected.



34. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15727
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15727
Summary:
xpdf is reported prone to a remote buffer overflow vulnerability. This issue exists because the applications fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer. 

It is reported that this issue presents itself in the 'CTStream::readBaselineSOF' function residing in the 'xpdf/Stream.cc' file.

This issue is reported to affect xpdf 3.01, however, it is likely that earlier versions are prone to this vulnerability as well.  Applications using embedded xpdf code may be vulnerable to this issue as well.

pdftohtml also includes vulnerable versions of xpdf.  Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.

kpdf reportedly incorporates vulnerable xpdf code.  Version 0.5 of kpdf is prone to this issue, however, other versions may also be affected.


35. Sun Java System Application Server Reverse SSL Proxy Plug-in Man In The Middle Vulnerability
BugTraq ID: 15728
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15728
Summary:
Sun Java System Application Server is prone to a man in the middle vulnerability.

This issue arises when the reverse SSL proxy plug-in is used with a supported Web server.

An attacker may exploit this issue to gain access to sensitive contents of encrypted network traffic between a client and a server.

36. Linux Kernel IPv6 FlowLable Denial Of Service Vulnerability
BugTraq ID: 15729
Remote: No
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15729
Summary:
Linux Kernel is prone to a local denial of service vulnerability.

Local attackers can exploit this to corrupt kernel memory or free non-allocated memory.  Successful exploitation will result in a crash of the kernel, effectively denying service to legitimate users.

37. Horde IMP Email Attachments HTML Injection Vulnerability
BugTraq ID: 15730
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15730
Summary:
Horde IMP is prone to an HTML injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

Reports indicate this issue is only present when viewing IMP content with the Microsoft Internet Explorer Web browser.

38. DuWare DuPortalPro Password.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 15731
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15731
Summary:
DuPortalPro is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


39. Sun Communications Services Delegated Administrator Default Password Disclosure Vulnerability
BugTraq ID: 15733
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15733
Summary:
Sun Java System Communications Services 6 Delegated Administrator 2005Q1 is prone to a vulnerability that can disclose the Top-Level Administrator (TLA) default password.

An attacker can exploit this issue to retrieve the password and gain TLA access.

40. IISWorks ASPKnowledgeBase KB.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 15734
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15734
Summary:
ASPKnowledgeBase is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Versions 2.x and prior are vulnerable; other versions may also be affected.


41. PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 15735
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15735
Summary:
phpMyAdmin is prone to multiple cross-site scripting vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

42. PHPForumPro Multiple SQL Injection Vulnerabilities
BugTraq ID: 15736
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15736
Summary:
phpForumPro is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

43. NetauctionHelp Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 15737
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15737
Summary:
NetAuctionHelp is prone to multiple cross-site scripting vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Versions 3.x and prior are vulnerable; other versions may also be affected.


44. XcClassified CPSearch.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 15738
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15738
Summary:
XcClassified is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Versions 3.x and prior are vulnerable; other versions may also be affected.


45. XcPhotoAlbum  PASearch.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 15739
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15739
Summary:
XcPhotoAlbum is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Versions 1.x and prior are vulnerable; other versions may also be affected.


46. RWAuction Pro Search.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 15740
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15740
Summary:
rwAuction Pro is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Versions 4.0 is vulnerable; prior versions may also be affected.


47. A-FAQ Multiple SQL Injection Vulnerabilities
BugTraq ID: 15741
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15741
Summary:
A-FAQ is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

Versions 1.0 and earlier are vulnerable; other versions may also be affected.


48. DoceboLMS Connector.PHP Directory Traversal Vulnerability
BugTraq ID: 15742
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15742
Summary:
DoceboLMS is prone to a directory traversal vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the Web server process.  Information obtained may aid in further attacks; other attacks are also possible.

49. FFmpeg LibAVCodec Heap Buffer Overflow Vulnerability
BugTraq ID: 15743
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15743
Summary:
FFmpeg's libavcodec is susceptible to a heap buffer overflow vulnerability. This issue is due to a failure of the library to properly bounds check user-supplied data prior to utilizing it in memory allocation and copy operations.

Attackers may exploit this vulnerability to execute arbitrary code in the context of applications that utilize an affected version of the libavcodec library.

An attacker can exploit this issue by enticing a user to open a malformed PNG file with an application that utilizes a vulnerable version of libavcodec. If the application is configured as the default handler for PNG files, this could present a viable Web or email attack vector as when the PNG is clicked from an appropriate client application, the application utilizing the vulnerable library will automatically be invoked.

50. DoceboLMS Arbitrary File Upload Vulnerability
BugTraq ID: 15744
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15744
Summary:
DoceboLMS is prone to an arbitrary file upload vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to upload arbitrary files including PHP code, and execute it in the context of the Web server process.  This may facilitate a compromise of the underlying system; other attacks are also possible.

51. PluggedOut Blog Index.PHP Multiple SQL Injection Vulnerabilities
BugTraq ID: 15746
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15746
Summary:
PluggedOut Blog is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


52. Cars Portal Index.PHP Multiple SQL Injection Vulnerabilities
BugTraq ID: 15747
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15747
Summary:
Cars Portal is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

Versions 1.1 and earlier are vulnerable; other versions may also be affected.


53. e107 Website System Voting Manipulation Vulnerability
BugTraq ID: 15748
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15748
Summary:
e107 is prone to a vulnerability that could permit an attacker to vote multiple times.

An attacker can exploit this issue to vote positively or negatively for content multiple times.  This will skew the expected poll results.

54. Multiple Vendor BIOS Password Persistence Weakness
BugTraq ID: 15751
Remote: No
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15751
Summary:
Multiple BIOS (Basic Input-Output System) vendors fail to clear the keyboard buffer after reading the BIOS password during the system startup process.

This issue is reported to affect Insyde BIOS V190, and AWARD BIOS Modular 4.50pg. Other versions and platforms are also likely affected.

Depending on the operating system running on affected computers, the memory region may or may not be available for user-level access. With Linux operating systems, superuser access is required. With Microsoft Windows operating systems, non-privileged users may access the keyboard buffer region.

Attackers that obtain the BIOS password may then utilize it for further attacks.

55. Ipswitch Collaboration Suite and IMail Server SMTPD Remote Format String Vulnerability
BugTraq ID: 15752
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15752
Summary:
Ipswitch Collaboration Suite and IMail Server are susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in a format-specifier argument to a formatted printing function.

This issue allows remote attackers to execute arbitrary machine code in the context of the affected application.

56. Ipswitch Collaboration Suite and IMail Server IMAPD LIST Command Denial Of Service Vulnerability
BugTraq ID: 15753
Remote: Yes
Date Published: 2005-12-06
Relevant URL: http://www.securityfocus.com/bid/15753
Summary:
Ipswitch Collaboration Suite and IMail Server are prone to a remote denial of service vulnerability.  

Successful exploitation will cause the affected server to crash, effectively denying service to legitimate users.

57. Sony SunnComm MediaMax Insecure Directory Permissions Vulnerability
BugTraq ID: 15754
Remote: No
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15754
Summary:
SunnComm MediaMax is prone to an insecure directory permissions vulnerability.

The vulnerability presents itself because the 'SunnComm Shared' directory allows 'Full Control' permissions to 'Everyone'. 

This insecure access control list associated with the directory can permit unprivileged attackers to read, modify and delete contents in the directory.  Local privilege escalation is also possible.

SunnComm MediaMax 5.0.21.0 is known to be vulnerable to this issue, however, other versions may be affected as well.

58. Appfluent Technology Database IDS APPFLUENT_HOME Variable Buffer Overflow Vulnerability
BugTraq ID: 15755
Remote: No
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15755
Summary:
Appfluent Technology Database IDS is prone to a local buffer overflow vulnerability.

This issue presents itself when the affected application handles a malformed value passed through the APPFLUENT_HOME environment variable.

A successful attack can allow an attacker to execute arbitrary code on the affected computer.  A complete compromise may be possible as well.

Appfluent Technology Database IDS 2.0 is reported to be vulnerable.  Other versions may be affected as well.

59. cURL / libcURL URL Parser Buffer Overflow Vulnerability
BugTraq ID: 15756
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15756
Summary:
cURL and libcURL are prone to a buffer overflow vulnerability.  This issue is due to a failure in the library to perform proper bounds checks on user supplied data before using it in a finite sized buffer.

The issues occur when the URL parser function handles an excessively long URL string.

An attacker can exploit this issue to crash the affected library, effectively denying service.  Arbitrary code execution may also be possible, this may facilitate a compromise of the underlying system.

60. Check Point VPN-1 SecureClient Policy Bypass Vulnerability
BugTraq ID: 15757
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15757
Summary:
VPN-1 SecureClient is reported prone to a policy bypass vulnerability. This issue is due to a failure of the application to securely implement remote administrator-provided policies on affected computers.

This issue allows remote VPN users to bypass the administratively-defined security policies. Specific issues arising from this vulnerability depend on the intended policies defined by administrators. Some examples of the consequences are: unauthorized computers may connect, scripts may not execute, or insecure network configurations may be possible.

61. IBM AIX UMOUNTALL Unspecified Absolute Path Security Vulnerability
BugTraq ID: 15758
Remote: No
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15758
Summary:
IBM AIX umountall is prone to an unspecified absolute path security vulnerability.

This issue is due to an unspecified security error with regards to absolute paths.

Very little information is available on this vulnerability. This BID will be updated as further information becomes available.


62. HP-UX Unspecified IPSec Unauthorized Remote Access Vulnerability
BugTraq ID: 15759
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15759
Summary:
HP-UX is prone to an unspecified unauthorized remote access vulnerability when IPSec is running.

The vendor has not provided any more information about the nature of the vulnerability.  This BID will be updated if more information becomes available.


63. SugarCRM Sugar Suite Remote and Local File Include Vulnerabilities
BugTraq ID: 15760
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15760
Summary:
SugarCRM Sugar Suite is affected by remote and local file include vulnerabilities.

An attacker can supply the path to a remote script through a URI parameter, or use directory traversal sequences and a local script on the server to execute script code.  This may facilitate unauthorized access. 

Sugar Suite 4.0 beta and prior versions are vulnerable to these issues.

64. PHPMyAdmin Import_Blacklist Variable Overwrite Vulnerability
BugTraq ID: 15761
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15761
Summary:
phpMyAdmin is prone to a vulnerability that permits an attacker to overwrite global variables.

An attacker can exploit this issue to overwrite the global variables with arbitrary input.  Through control of the global variables, the attacker may be able to include arbitrary remote and local files depending on the current PHP version.  Various other attacks are also possible.

65. Apache MPM Worker.C Denial Of Service Vulnerability
BugTraq ID: 15762
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15762
Summary:
Apache is prone to a memory leak, causing a denial of service vulnerability.

Apache is prone to a memory leak, causing a denial of service vulnerability.
An attacker may consume excessive memory resources, resulting in a denial of service condition affecting legitimate users.

Apache 2.x versions are vulnerable; other versions may also be affected.


66. ThWboard Multiple Input Validation Vulnerabilities
BugTraq ID: 15763
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15763
Summary:
ThWboard is prone to multiple input validation vulnerabilities. 

The application is vulnerable to HTML injection, cross-site scripting, and SQL injection; these issues are due to a lack of proper sanitization of user-supplied input.

A remote attacker may inject SQL, HTML and script code resulting in theft of cookie-based authentication credentials, arbitrary script code execution, and the passing of malicious input to the underlying database application. 

Version 3 beta 2.8 is vulnerable; other versions may be affected.


67. SimpleBBS Remote Arbitrary Command Execution Vulnerability
BugTraq ID: 15764
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15764
Summary:
SimpleBBS is prone to an arbitrary command execution vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to execute arbitrary PHP commands in the context of the Web server process.  This may facilitate a compromise of the underlying system; other attacks are also possible.

68. Apache James Spooler Memory Leak Denial Of Service Vulnerability
BugTraq ID: 15765
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15765
Summary:
James is prone to a memory leak denial of service vulnerability.

This issue occurs during an error condition in the spooler.

An attacker can exploit this issue by creating multiple error conditions and eventually consume system resources.

Successful exploitation will ultimately crash the application denying service to legitimate users.

69. DRZES HMS Login.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 15766
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15766
Summary:
DRZES HMS is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


70. ASPMForum Multiple SQL Injection Vulnerabilities
BugTraq ID: 15767
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15767
Summary:
ASPMForum is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


71. Dell TrueMobile 2300 Remote Credential Reset Vulnerability
BugTraq ID: 15770
Remote: Yes
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15770
Summary:
It is possible for remote attackers to gain control of a target TrueMobile 2300 running firmware versions 3.0.0.8 and 5.1.1.6.  Other versions are likely affected.  The vulnerability appears to be in an administrative component accessed through the web-based control interface.  Unauthenticated attackers can force the device to reset the administrative credentials without authorization.  Once credentials have been reset an attacker can log in and perform malicious actions, potentially compromising the entire LAN behind the device.

72. Courier Mail Server Unauthorized Access Vulnerability
BugTraq ID: 15771
Remote: Yes
Date Published: 2005-12-08
Relevant URL: http://www.securityfocus.com/bid/15771
Summary:
Courier Mail Server is prone to an unauthorized access vulnerability.  This issue occurs because accounts that have been deactivated may still be able to log onto the server.


73. Sun Solaris Sun Update Connection Web Proxy Password Disclosure Vulnerability
BugTraq ID: 15772
Remote: No
Date Published: 2005-12-07
Relevant URL: http://www.securityfocus.com/bid/15772
Summary:
Sun Solaris Sun Update Connection is prone to a vulnerability that may allow local attackers to obtain the proxy server password.

This vulnerability only presents itself when Sun Update Connection is configured to use a Web proxy with password authentication enabled.

A successful attack may result in information disclosure, which may lead to other attacks as well.

Solaris 10 is prone to this vulnerability.

74. Mozilla Firefox Large History File Buffer Overflow Vulnerability
BugTraq ID: 15773
Remote: Yes
Date Published: 2005-12-08
Relevant URL: http://www.securityfocus.com/bid/15773
Summary:
Mozilla Firefox is reportedly prone to a remote denial of service vulnerability.

This issue presents itself when the browser handles a large entry in the 'history.dat' file.  An attacker may trigger this issue by enticing a user to visit a malicious Web site and supplying excessive data to be stored in the affected file.

This may cause a denial of service condition.

**UPDATE: Proof of concept exploit code has been published.  The author of the code attributes the crash to a buffer overflow condition.  The alleged flaw cannot be reproduced by Symantec.

75. CFMagic Multiple Products Input Validation Vulnerabilities
BugTraq ID: 15774
Remote: Yes
Date Published: 2005-12-08
Relevant URL: http://www.securityfocus.com/bid/15774
Summary:
CFMagic Products are prone to multiple input validation vulnerabilities. These are due to a lack of proper sanitization of user-supplied input.

These vulnerabilities allow an attacker to inject malicious SQL code into database queries, and conduct cross-site scripting attacks. 

Magic Book Professional version 2.0 and prior, Magic List Professional version 2.5 and prior, and Magic Forum Personal versions 2.5 and prior are vulnerable.

Other versions of these applications may also be affected.


76. Soti Pocket Controller-Professional Remote Command Execution Vulnerability
BugTraq ID: 15775
Remote: Yes
Date Published: 2005-12-08
Relevant URL: http://www.securityfocus.com/bid/15775
Summary:
Soti Pocket Controller-Professional is prone to a remote command execution vulnerability.  Successful exploitation could allow an attacker to cause a hard reset of the device, resulting in a loss of data and installed applications.

Pocket Controller-Professional v5 is vulnerable, however, other versions may also be affected.


77. Website Baker SQL Injection Vulnerability
BugTraq ID: 15776
Remote: Yes
Date Published: 2005-12-08
Relevant URL: http://www.securityfocus.com/bid/15776
Summary:
Website Baker is prone to an SQL injection vulnerability.

This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.  A successful attack can allow an attacker to bypass administrator login and gain administrative access to a site.

Successful exploitation could also result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation. 

Website Baker 2.6.0 and prior versions are vulnerable to this issue.

78. CF_Nuke Index.CFM Local File Include Vulnerability
BugTraq ID: 15777
Remote: Yes
Date Published: 2005-12-08
Relevant URL: http://www.securityfocus.com/bid/15777
Summary:
CF_Nuke is prone to a local file include vulnerability. This is due to a lack of sanitization of user-supplied input.

This may facilitate the unauthorized viewing of files and unauthorized execution of local ColdFusion code.

It should be noted that successful exploitation requires that "Sandbox Security" is not enabled for the directory.

CF_Nuke 4.6 and prior versions are reported to be vulnerable; other versions may also be affected.


79. CF_Nuke Index.CFM Cross-Site Scripting Vulnerabilities
BugTraq ID: 15778
Remote: Yes
Date Published: 2005-12-08
Relevant URL: http://www.securityfocus.com/bid/15778
Summary:
CF_Nuke is prone to multiple cross-site scripting vulnerabilities. These are due to a lack of proper sanitization of user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  

These may facilitate the theft of cookie-based authentication credentials as well as other attacks.


80. ACME Perl-Cal Cal_make.PL Cross-Site Scripting Vulnerability
BugTraq ID: 15779
Remote: Yes
Date Published: 2005-12-08
Relevant URL: http://www.securityfocus.com/bid/15779
Summary:
Perl-Cal is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.



81. Microsoft Excel Unspecified Memory Corruption Vulnerability
BugTraq ID: 15780
Remote: Yes
Date Published: 2005-12-08
Relevant URL: http://www.securityfocus.com/bid/15780
Summary:
An unspecified vulnerability has been reported to exist in Microsoft Excel.  The vulnerability was announced on eBay.  The discoverer was offering to sell the vulnerability details until the auction was terminated by eBay.  According to the auction description, it is possible to have a large value passed to "msvcrt.memmove()" through data fields in an Excel .xls file.  The discoverer has claimed that code execution is possible.

This entry will be updated as more details become available.

**UPDATE (Dec 9, 2005): Microsoft has confirmed that this vulnerability exists.  See eWeek link in reference section.  The original listing on eBay has been pulled.

82. Microsoft December Advance Notification Unspecified Security Vulnerabilities 
BugTraq ID: 15782
Remote: Unknown
Date Published: 2005-12-08
Relevant URL: http://www.securityfocus.com/bid/15782
Summary:
Microsoft has released advanced notification for two security bulletins that will be released on December 13, 2005.

83. Computer Associates CleverPath Portal Login Page Cross-Site Scripting Vulnerability
BugTraq ID: 15783
Remote: Yes
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15783
Summary:
Computer Associates CleverPath Portal is prone to a cross-site scripting vulnerability in the login page.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


84. PGP Desktop Wipe Free Space Assistant Improper Disk Wipe Vulnerability
BugTraq ID: 15784
Remote: No
Date Published: 2005-12-08
Relevant URL: http://www.securityfocus.com/bid/15784
Summary:
PGP Desktop Wipe Free Space Assistant is prone to a vulnerability that causes the application to improperly wipe a hard disk. 

This can allow an attacker to obtain data that is stored on the file slack space.

Information gathered through the exploitation of this vulnerability may lead to further attacks.

PGP Desktop Professional 9.0.3 Build 2932 and PGP Desktop Home 8.x versions are reportedly vulnerable to this issue.  Other versions may be affected as well.

85. QNX RTOS Unspecified Local DHCP.Client Vulnerability
BugTraq ID: 15785
Remote: No
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15785
Summary:
QNX RTOS is susceptible to an unspecified local dhcp.client vulnerability that allows unprivileged users to modify network configuration.

This vulnerability allows local attackers to modify network configuration, potentially causing a denial of service condition. Other attacks may also be possible.

This BID will be updated as further information is released.

This issue reportedly affects QNX version 4.25. Other versions may also be affected.

86. Lyris ListManager Command Execution Vulnerability
BugTraq ID: 15786
Remote: Yes
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15786
Summary:
Lyris ListManager is prone to a CRLF injection vulnerability.

Attackers may exploit this weakness to execute list manager administrative commands, and manipulate the structure of outgoing messages. For example, it may be possible for attackers to set the recipient to an arbitrary value.

Versions 5.0 through 8.8a are vulnerable; other versions may also be affected.


87. Lyris ListManager Multiple SQL Injection Vulnerabilities
BugTraq ID: 15787
Remote: Yes
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15787
Summary:
Lyris ListManager is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


88. Lyris Listmanager TCLHTTPd Service Multiple Information Disclosure Vulnerabilities
BugTraq ID: 15788
Remote: Yes
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15788
Summary:
The Lyris ListManager TCLHTTPd Service is prone to multiple vulnerabilities.

An attacker may obtain unathorized access to sensitive information, and view  arbitrary TML source code on the affected computer.

Versions 5.0 through 8.8a are affected; other versions may also be vulnerable.


89. Lyris ListManager Hidden Variable Information Disclosure Vulnerability
BugTraq ID: 15789
Remote: Yes
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15789
Summary:
Lyris ListManager is prone to an information disclosure vulnerability.

This vulnerability may be used to disclose the software version and software installation path, which may be helpful in further attacks.

Versions 5.0 through 8.8a are vulnerable; other versions may also be affected.


90. Contenido CMS Unspecified Remote Command Execution Vulnerability
BugTraq ID: 15790
Remote: Yes
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15790
Summary:
Contenido CMS is prone to an unspecified remote command execution vulnerability. This is due to a lack of proper sanitization of user-supplied input.

An attacker can exploit this vulnerability to execute arbitrary commands in the context of the Web server process.  This may facilitate a compromise of the underlying system; other attacks are also possible.

It should be notes that the "allow_url_fopen" and "register_globals" PHP variables must be enabled to exploit this vulnerability.


91. MilliScripts Register.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 15792
Remote: Yes
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15792
Summary:
MilliScripts is prone to a cross-site scripting vulnerability. This is due to a lack of proper input validation.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


92. MyBB Multiple Unspecified Vulnerabilities
BugTraq ID: 15793
Remote: Yes
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15793
Summary:
MyBB is prone to multiple unspecified vulnerabilities.

The first set of issues arise from insufficient sanitization of user-supplied data through unspecified variables.  These issues can allow an attacker to carry out SQL injection attacks.  

The second set of vulnerabilities can be exploited by anonymous guest users of MyBB and result in a full compromise of an affected site.

This BID will be updated when more information becomes available.

93. Ethereal OSPF Protocol Dissection Stack Buffer Overflow Vulnerability
BugTraq ID: 15794
Remote: Yes
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15794
Summary:
A remote buffer overflow vulnerability affects Ethereal. This issue is due to a failure of the application to securely copy network-derived data into sensitive process buffers. The specific issue exists in the OSPF dissector.

An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.

94. Motorola SB5100E Cable Modem LanD Packet Denial Of Service Vulnerability
BugTraq ID: 15795
Remote: Yes
Date Published: 2005-12-09
Relevant URL: http://www.securityfocus.com/bid/15795
Summary:
Motorola SB5100E Cable Modems are prone to a denial of service vulnerability.

These devices are susceptible to a remote denial of service vulnerability when handling TCP 'LanD' packets.

This issue allows attackers to block network traffic to arbitrarily targeted network services. A physical restart of the device will return it to normal operations.

95. Flatnuke Index.PHP Directory Traversal Vulnerability
BugTraq ID: 15796
Remote: Yes
Date Published: 2005-12-10
Relevant URL: http://www.securityfocus.com/bid/15796
Summary:
Flatnuke is prone to a directory traversal vulnerability. This is due to a lack of proper sanitization of user-supplied input.

A remote attacker may employ directory traversal strings '../' to read sensitive files containing MD5 password hashes, and create malicious cookie data which may be used to log in as an administrative user. An attacker may then create and execute malicious code, which may be executed within the context of the administrative user's account. This code may be executed within the context of the affected Web server process.

Flatnuke 2.5.6 is affected; earlier versions may also be affected.


96. APANI Networks EpiForce Agent Denial Of Service Vulnerability
BugTraq ID: 15797
Remote: Yes
Date Published: 2005-12-10
Relevant URL: http://www.securityfocus.com/bid/15797
Summary:
EpiForce Agent is prone to a denial of service vulnerability.

Unspecified PROTOS protocol tests will crash the IKE Negotiation Module of the Epiforce Agent application. This will cause the Epiforce application to crash, effectively denying service to legitimate users, until the service is automatically restarted.

No further details regarding this vulnerability are known. This BID will be updated when details become available.


III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. eBay pulls vulnerability auction
By: Robert Lemos
The online auction giant shuts down the bidding for a vulnerability in Microsoft's Excel spreadsheet program, saying that the sale of flaw research violates the site's policy against encouraging illegal activity.
http://www.securityfocus.com/news/11363

2. Consumers improving security, but gaps remain
By: Robert Lemos
A study of Internet users finds that fewer home PCs had been compromised by spyware or a virus infection than the year before, but the large majority still lack spyware protection, up-to-date antivirus or a properly configured firewall.
http://www.securityfocus.com/news/11361

3. Federal flaw database commits to grading system
By: Robert Lemos
The National Vulnerability Database adopts the Common Vulnerability Scoring System and assigns severity rankings to more than 13,000 published flaws.
http://www.securityfocus.com/news/11360

4. Mac OS X security under scrutiny
By: Robert Lemos
Flaw finders and hackers have taken a shine to Apple's polished operating system, but some say that recent security problems are more than just skin deep.
http://www.securityfocus.com/news/11359

5. Skype under scrutiny for bugs
By: John Leyden
The recent emergence of two sets of serious security vulnerabilities in Skype, the popular VoIP communications software app, couldn't have come at a worse time for the firm.
http://www.securityfocus.com/news/11354

6. Say hello to the Skype Trojan
By: John Leyden
Virus writers are targeting Skype users with a new Trojan that poses as the latest version of the popular VoIP software.
http://www.securityfocus.com/news/11348

7. Shared music abuse bug hits iTunes
By: John Leyden
Security researchers have discovered a vulnerability in Apple's popular iTunes application which might be exploited to interfere with shared music downloads.
http://www.securityfocus.com/news/11347

8. US cybersecurity all at sea
By: John Leyden
US cybersecurity risks are being poorly managed by the Department of Homeland Security, according to a former US presidential information security advisor.
http://www.securityfocus.com/news/11345

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] VP of Regional Sales, Southern California
http://www.securityfocus.com/archive/77/419388

2. [SJ-JOB] Security Engineer, Charlottesville
http://www.securityfocus.com/archive/77/419394

3. [SJ-JOB] Sr. Security Analyst, Nashville
http://www.securityfocus.com/archive/77/419397

4. [SJ-JOB] Security System Administrator, Laurel
http://www.securityfocus.com/archive/77/419392

5. [SJ-JOB] Developer, Superior
http://www.securityfocus.com/archive/77/419358

6. [SJ-JOB] Sr. Security Analyst, London - UK Wide
http://www.securityfocus.com/archive/77/419359

7. [SJ-JOB] Disaster Recovery Coordinator, London
http://www.securityfocus.com/archive/77/419362

8. [SJ-JOB] Security Architect, Reading / London
http://www.securityfocus.com/archive/77/419364

9. [SJ-JOB] Security System Administrator, Basel
http://www.securityfocus.com/archive/77/419357

10. [SJ-JOB] Security Consultant, Dubai
http://www.securityfocus.com/archive/77/419257

11. [SJ-JOB] Security Consultant, Riyadh
http://www.securityfocus.com/archive/77/419260

12. [SJ-JOB] Sr. Security Engineer, San Mateo
http://www.securityfocus.com/archive/77/419258

13. [SJ-JOB] Jr. Security Analyst, Seoul
http://www.securityfocus.com/archive/77/419259

14. [SJ-JOB] Developer, San Mateo
http://www.securityfocus.com/archive/77/419256

15. [SJ-JOB] Customer Support, Superior
http://www.securityfocus.com/archive/77/419281

16. [SJ-JOB] Customer Support, Superior
http://www.securityfocus.com/archive/77/419252

17. [SJ-JOB] Quality Assurance, Calgary
http://www.securityfocus.com/archive/77/419269

18. [SJ-JOB] Quality Assurance, Superior
http://www.securityfocus.com/archive/77/419262

19. [SJ-JOB] Quality Assurance, Santa Clara
http://www.securityfocus.com/archive/77/419289

20. [SJ-JOB] Manager, Information Security, New York
http://www.securityfocus.com/archive/77/419285

21. [SJ-JOB] Channel / Business Development, Riyadh
http://www.securityfocus.com/archive/77/419283

22. [SJ-JOB] Security Architect, Berkshire / Hampshire
http://www.securityfocus.com/archive/77/419275

23. [SJ-JOB] Security Engineer, Ann Arbor
http://www.securityfocus.com/archive/77/419276

24. [SJ-JOB] Manager, Information Security, Dubai
http://www.securityfocus.com/archive/77/419273

25. [SJ-JOB] Security Engineer, Paris / Evry
http://www.securityfocus.com/archive/77/419274

26. [SJ-JOB] Security Researcher, Atlanta
http://www.securityfocus.com/archive/77/419271

27. [SJ-JOB] Information Assurance Analyst, Columbia
http://www.securityfocus.com/archive/77/419227

28. [SJ-JOB] Sr. Security Engineer, Washington
http://www.securityfocus.com/archive/77/419228

29. [SJ-JOB] Information Assurance Engineer, Washington
http://www.securityfocus.com/archive/77/419225

30. [SJ-JOB] Information Assurance Engineer, Washington
http://www.securityfocus.com/archive/77/419226

31. [SJ-JOB] Developer, Pasadena
http://www.securityfocus.com/archive/77/419182

32. [SJ-JOB] Disaster Recovery Coordinator, Arlington
http://www.securityfocus.com/archive/77/419183

33. [SJ-JOB] Sales Representative, Chicago
http://www.securityfocus.com/archive/77/419180

34. [SJ-JOB] Security Architect, Arlington
http://www.securityfocus.com/archive/77/419181

35. [SJ-JOB] Certification & Accreditation Engineer, Washington
http://www.securityfocus.com/archive/77/419176

36. [SJ-JOB] Security Engineer, Washington DC
http://www.securityfocus.com/archive/77/419179

37. [SJ-JOB] Sr. Security Analyst, Cupertino
http://www.securityfocus.com/archive/77/419174

38. [SJ-JOB] Security Engineer, Washington DC
http://www.securityfocus.com/archive/77/419175

39. [SJ-JOB] Sales Engineer, Cupertino
http://www.securityfocus.com/archive/77/419178

40. [SJ-JOB] Security Researcher, Cupertino
http://www.securityfocus.com/archive/77/419173

41. [SJ-JOB] Security System Administrator, Austin
http://www.securityfocus.com/archive/77/418970

42. [SJ-JOB] Security Engineer, Washington DC
http://www.securityfocus.com/archive/77/418996

43. [SJ-JOB] Security System Administrator, Austin
http://www.securityfocus.com/archive/77/419029

44. [SJ-JOB] Director, Information Security, Sunnyvale
http://www.securityfocus.com/archive/77/419030

45. [SJ-JOB] Sr. Security Engineer, Mountain View
http://www.securityfocus.com/archive/77/419028

46. [SJ-JOB] Security System Administrator, London
http://www.securityfocus.com/archive/77/419024

47. [SJ-JOB] Security Consultant, DC
http://www.securityfocus.com/archive/77/419023

48. [SJ-JOB] Application Security Engineer, Tel Aviv
http://www.securityfocus.com/archive/77/419022

49. [SJ-JOB] Information Assurance Engineer, Washington
http://www.securityfocus.com/archive/77/419018

50. [SJ-JOB] Security Product Manager, San Diego
http://www.securityfocus.com/archive/77/419020

51. [SJ-JOB] Certification & Accreditation Engineer, Washington
http://www.securityfocus.com/archive/77/418956

52. [SJ-JOB] Security Auditor, Washington
http://www.securityfocus.com/archive/77/418957

53. [SJ-JOB] Disaster Recovery Coordinator, Washington
http://www.securityfocus.com/archive/77/418958

54. [SJ-JOB] Security Engineer, Rockville
http://www.securityfocus.com/archive/77/418955

55. [SJ-JOB] Director, Information Security, Kirkland
http://www.securityfocus.com/archive/77/418959

V.   INCIDENTS LIST SUMMARY
---------------------------
1. New (maybe old?) PhpBB worm about?
http://www.securityfocus.com/archive/75/419189

2. hacked server, DDoS bin installed
http://www.securityfocus.com/archive/75/418816

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Reviews on Microsoft Communications Protocol Program (MCPP)
http://www.securityfocus.com/archive/82/419372

2. (stupid one) physical security of remotes?
http://www.securityfocus.com/archive/82/419373

3. ESI Manipulation?
http://www.securityfocus.com/archive/82/419112

4. -Exploiting Freelist[0] On Windows XP Service Pack 2-
http://www.securityfocus.com/archive/82/418925

5. Critical Myspace.com Vulnerabilites
http://www.securityfocus.com/archive/82/418915

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. IIS Script source access  permission and NTFS DACLs
http://www.securityfocus.com/archive/88/419335

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: SpiDynamics

ALERT:  "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!"- White Paper
The newest web app vulnerability. Blind SQL Injection!
Even if your web application does not return error messages, it may still be open to a Blind SQL Injection Attack.
Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and
manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a 
complete guide to protection! 

https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701300000003Har