SecurityFocus Newsletter #333

Peter Laborge <[email protected]> Tue, 17 Jan 2006 13:27:44 -0700
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #333
----------------------------------------

This Issue is Sponsored By: SpiDynamics

ALERT: Learn to Think Like a Hacker- Simulate a Hacker Breaking into Your Web Apps
The speed with which Web Applications are developed make them prime targets for attackers, often these applications were developed so quickly that they are not coded properly or subjected to any security testing. Hackers know this and use it as their weapon. Download this *FREE* test guide from SPI Dynamics to check for Web application vulnerabilities.

https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=701300000003P6V

------------------------------------------------------------------
I.    FRONT AND CENTER
      1. Wiretapping, FISA, and the NSA
      2. Sebek 3: tracking the attackers, part one
II.   BUGTRAQ SUMMARY
       1. NetSarang XLPD Remote Denial of Service Vulnerability
       2. Navboard Multiple BBCode Tag Script Injection Vulnerabilities
       3. AppServ Open Project Remote File Include Vulnerability
       4. Microsoft Windows Graphics Rendering Engine Multiple Memory Corruption Vulnerabilities
       5. PD9 Software MegaBBS Private Message Information Disclosure Vulnerability
       6. 427BB Showthread.PHP SQL Injection Vulnerability
       7. BSD SecureLevel Time Setting Security Restriction Bypass Vulnerability
       8. Bogofilter Multiple Remote Buffer Overflow Vulnerabilities
       9. Foxrum Multiple BBCode Tag Script Injection Vulnerabilities
       10. NetBSD KernFS LSEEK Local Kernel Memory Disclosure Vulnerability
       11. PHP PEAR Go-Pear.PHP Arbitrary Remote Code Execution Vulnerability
       12. SysCP WebFTP Module Local File Include Vulnerability
       13. Venom Board Post.PHP3 Multiple SQL Injection Vulnerabilities
       14. Dave Carrigan Auth_LDAP Remote Format String Vulnerability
       15. 427BB Authentication Bypass Vulnerability
       16. Qualcomm Eudora Internet Mail Server Multiple Denial of Service Vulnerabilities
       17. PHPChamber Search_result.PHP Cross-Site Scripting Vulnerability
       18. Microsoft Excel Unspecified Code Execution Vulnerability
       19. Magic News Plus Administrator Password Change Vulnerability
       20. Andromeda Andromeda.PHP Cross-Site Scripting Vulnerability
       21. Sudo Python Environment Variable Handling Security Bypass Vulnerability
       22. Joomla Vcard Access Information Disclosure Vulnerability
       23. PHPNuke EV Search Module SQL Injection Vulnerability
       24. ADOdb Server.PHP SQL Injection Vulnerability
       25. Stefan Frings SMS Server Tools Local Format String Vulnerability
       26. Xoops Pool Module IMG Tag HTML Injection Vulnerability
       27. Petris Local Buffer Overflow Vulnerability
       28. Clam Anti-Virus ClamAV UPX Compressed File Heap Buffer Overflow Vulnerability
       29. PHPNuke Multiple Modules IMG Tag HTML Injection Vulnerability
       30. Sun Solaris UUSTAT Local Buffer Overflow Vulnerability
       31. Microsoft Windows Embedded Web Font Buffer Overflow Vulnerability
       32. Hummingbird Enterprise Collaboration Multiple Vulnerabilities
       33. WebWiz Forums Search_form.ASP Cross-Site Scripting Vulnerability
       34. Microsoft Outlook / Microsoft Exchange TNEF Decoding Remote Code Execution Vulnerability
       35. Trac HTML WikiProcessor Wiki Content HTML Injection Vulnerability
       36. Orjinweb Index.PHP Remote File Include Vulnerability
       37. Cisco IP Phone 7940 Remote Denial of Service Vulnerability
       38. PostgreSQL Postmaster Denial Of Service Vulnerability
       39. Apple QuickTime Multiple Code Execution Vulnerabilities
       40. XMame Multiple Local Command Line Argument Buffer Overflow Vulnerabilities
       41. Blackberry Enterprise Server Attachment Service PNG Attachment Denial Of Service Vulnerability
       42. Cray UNICOS Multiple Local Command Line Argument Buffer Overflow Vulnerabilities
       43. CaLogic Calendars Add Event Multiple HTML Injection Vulnerabilities
       44. FreeBSD EE Insecure Temporary File Creation Vulnerability
       45. MyPhPim Addresses.PHP3 Arbitrary File Upload Vulnerability
       46. FreeBSD IPFW IP Fragment Remote Denial Of Service Vulnerability
       47. MyPhPim Multiple Input Validation Vulnerabilities
       48. Cisco CS-MARS Default Administrative Password Vulnerability
       49. Apple QuickTime PictureViewer JPEG/PICT File Buffer Overflow Vulnerability
       50. eStara Softphone SIP SDP Data Packet Remote Buffer Overflow Vulnerability
       51. Interspire TrackPoint NX Index.PHP Cross-Site Scripting Vulnerability
       52. BEA WebLogic Server and WebLogic Express MBean Remote Information Disclosure Vulnerability
       53. Fog Creek Software FogBugz Default.ASP Cross-Site Scripting Vulnerability
       54. Cisco Aironet Wireless Access Point ARP Memory Exhaustion Denial Of Service Vulnerability
       55. PHP Toolkit for PayPal IPN_success.PHP Logfile Injection Vulnerability
       56. PHP MySQLI Error Logging Remote Format String Vulnerability
       57. PHP 5 User-Supplied Session ID Input Validation Vulnerability
       58. Sun Solaris Find In Proc Filesystem Local Denial Of Service Vulnerability
       59. Sun Solaris Operating System Unspecified Privilege Escalation Vulnerability
       60. Microsoft Visual Studio UserControl Remote Code Execution Vulnerability
       61. SuSE Open Enterprise Server Novell Remote Manager HTTP Request Header Heap Overflow Vulnerability
       62. Wordcircle Multiple Input Validation Vulnerabilities
       63. TankLogger General Functions Script SQL Injection Vulnerabilities
       64. Light Weight Calendar Index.PHP Remote Command Execution Vulnerability
       65. MyBB Usercp.PHP SQL Injection Vulnerability
       66. DDSN Interactive CM3CMS Admin Panel Index.ASP SQL Injection Vulnerability
       67. DCP Portal Multiple Input Validation Vulnerabilities
       68.  AlstraSoft Template Seller Pro Fullview.PHP Cross-Site Scripting Vulnerability
       69. Web Host Automation Ltd. Helm ForgotPassword.ASP Cross-Site Scripting Vulnerability
       70. 123 Flash Chat Server Arbitrary Remote File Creation Vulnerability
       71. Toshiba Bluetooth Stack Object Push Service File Upload Directory Traversal Vulnerability
       72. EZDatabaseRemote PHP Script Code Execution Vulnerability
       73. Helmsman HomeFtp Remote Denial Of Service Vulnerability
III.  SECURITYFOCUS NEWS
       1. Researcher: Sony BMG "rootkit" still widespread
       2. Zero-day WMF flaw underscores patch problems
       3. Security flaws on the rise, questions remain
       4. Data security moves front and center in 2005
       5. Skype under scrutiny for bugs
       6. Say hello to the Skype Trojan
       7. Shared music abuse bug hits iTunes
       8. US cybersecurity all at sea
IV.   SECURITY JOBS LIST SUMMARY
       1. [SJ-JOB] Security Engineer, Chicago
       2. [SJ-JOB] Sales Representative, Vienna
       3. [SJ-JOB] Security Engineer, Atlanta
       4. [SJ-JOB] Sales Representative, North Brunswick
       5. [SJ-JOB] Security System Administrator, Santa Barbara
       6. [SJ-JOB] Jr. Security Analyst, Charlotte
       7. [SJ-JOB] Sr. Security Engineer, North Brunswick
       8. [SJ-JOB] Auditor, North Brunswick
       9. [SJ-JOB] Sales Engineer, Cupertino
       10. [SJ-JOB] Security System Administrator, Louisville
       11. [SJ-JOB] Security Researcher, Cupertino
       12. [SJ-JOB] Technical Writer, Cupertino
       13. [SJ-JOB] Security System Administrator, Rockaway
       14. [SJ-JOB] Manager, Information Security, New York
       15. [SJ-JOB] Security Director, Arlington
       16. [SJ-JOB] Security Director, Arlington
       17. [SJ-JOB] Manager, Information Security, New York
       18. [SJ-JOB] Security Consultant, Denver
       19. [SJ-JOB] Sales Engineer, Phoenix
       20. [SJ-JOB] Auditor, New York
       21. [SJ-JOB] Security Engineer, Richmond
       22. [SJ-JOB] Security System Administrator, Tampa
       23. [SJ-JOB] Security System Administrator, Tampa
       24. [SJ-JOB] Director, Information Security, Wilmington
       25. [SJ-JOB] Security Engineer, Washington
       26. [SJ-JOB] Security Consultant, Bangalore , Mumbai
       27. [SJ-JOB] Security Consultant, Canberra & Brisbane
       28. [SJ-JOB] Security Product Manager, Longmont
       29. [SJ-JOB] Account Manager, San Jose
       30. [SJ-JOB] CHECK Team Leader, North Hampshire
       31. [SJ-JOB] Security Director, Charlotte
       32. [SJ-JOB] Sales Engineer, Slough
       33. [SJ-JOB] Manager, Information Security, South Boston
       34. [SJ-JOB] Sales Engineer, Atlanta
       35. [SJ-JOB] Security Engineer, Washington DC Metro
       36. [SJ-JOB] Sales Engineer, Scottsdale, AZ, Denver, CO or Huntingdon    Beach, CA
       37. [SJ-JOB] Security Engineer, Huntsville
       38. [SJ-JOB] Security Consultant, Annapolis Junction
       39. [SJ-JOB] Application Security Engineer, Anywhere in the USA
       40. [SJ-JOB] Security Engineer, Eastern Iowa
       41. [SJ-JOB] Sales Representative, New York
       42. [SJ-JOB] Developer, Foster City
       43. [SJ-JOB] Developer, Foster City
       44. [SJ-JOB] Developer, Foster City
       45. [SJ-JOB] Sales Engineer, Atlanta
       46. [SJ-JOB] Sales Engineer, Charlotte
       47. [SJ-JOB] Sales Engineer, Alexandria
       48. [SJ-JOB] Quality Assurance, Superior, Colorado
       49. [SJ-JOB] Developer, Superior, Colorado
       50. [SJ-JOB] Sales Engineer, New York
       51. [SJ-JOB] Sr. Security Analyst, London and South
       52. [SJ-JOB] Sales Engineer, New York
       53. [SJ-JOB] Account Manager, New York
       54. [SJ-JOB] Jr. Security Analyst, Bristol
       55. [SJ-JOB] Sr. Security Analyst, London and South
       56. [SJ-JOB] Sales Engineer, Oxfordshire
       57. [SJ-JOB] Security Director, New York City
       58. [SJ-JOB] Manager, Information Security, Lanham
       59. [SJ-JOB] Sales Engineer, Metro DC
       60. [SJ-JOB] Sales Engineer, London
       61. [SJ-JOB] Sales Engineer, New York Area
V.    INCIDENTS LIST SUMMARY
       1. Dead thread: Why was there no WMF Internet Attack...
VI.   VULN-DEV RESEARCH LIST SUMMARY
       1. Advanced Buffer Overflow Methods lecture + PPT - Tel Aviv University
       2. shellcoding on gentoo
       3. EUSecWest papers and CanSecWest CFP
VII.  MICROSOFT FOCUS LIST SUMMARY
       1. Windows wireless flaw...
       2. SecurityFocus Microsoft Newsletter #273
       3. How to disable interactive logon for service accounts on W2K and W2K3
       4. Different side of the problem (was)  New article on SecurityFocus
       5. patching servers...
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
       1. Sendmail/Blacklists rejecting authenticated users
       2. Hide internal address (Postfix)
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Wiretapping, FISA, and the NSA
By Mark Rasch
U.S. wiretapping laws, FISA and Presidential powers given to the NSA to intercept communications make for interesting times when coupled with technology. What are the issues surrounding privacy, search, seizure and surveillance?
http://www.securityfocus.com/columnists/379

2. Sebek 3: tracking the attackers, part one
By Raul Siles, GSE
The first of this two-part series will discuss what Sebek is and what makes it so interesting, first by looking at the new capabilities of version 3 and how it integrates with GenIII Honeynet infrastructures.
http://www.securityfocus.com/infocus/1855


II.  BUGTRAQ SUMMARY
--------------------
1. NetSarang XLPD Remote Denial of Service Vulnerability
BugTraq ID: 16164
Remote: Yes
Date Published: 2006-01-07
Relevant URL: http://www.securityfocus.com/bid/16164
Summary:
Xlpd is prone to a remote denial of service vulnerability. This issue is due to a failure in the application to handle exceptional conditions.

A remote attacker can exploit this issue to crash the affected application effectively denying service to legitimate users.

This issue is reported to affect Xlpd version 2.1; other versions may also be vulnerable.

2. Navboard Multiple BBCode Tag Script Injection Vulnerabilities
BugTraq ID: 16165
Remote: Yes
Date Published: 2006-01-07
Relevant URL: http://www.securityfocus.com/bid/16165
Summary:
Navboard is prone to multiple script injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input prior to including it in dynamically generated content.

Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials.  Other attacks are also possible.

These issues are reported to affect versions V16 and V17beta2; other versions may also be vulnerable.


3. AppServ Open Project Remote File Include Vulnerability
BugTraq ID: 16166
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16166
Summary:
AppServ Open Project is prone to a remote file include vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.

This issue affects version 2.4.5; other versions may also be vulnerable.

4. Microsoft Windows Graphics Rendering Engine Multiple Memory Corruption Vulnerabilities
BugTraq ID: 16167
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16167
Summary:
Microsoft Windows WMF graphics rendering engine is affected by multiple memory corruption vulnerabilities.  These issues affect the 'ExtCreateRegion' and 'ExtEscape' functions.

These problems present themselves when a user views a malicious WMF formatted file containing specially crafted data.

Reports indicate that these issues lead to a denial of service condition. Earlier conjectures that the issues may result in the execution of arbitrary code appear at this point to be incorrect. Attackers could force a crash or restart of the viewing application.

5. PD9 Software MegaBBS Private Message Information Disclosure Vulnerability
BugTraq ID: 16168
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16168
Summary:
MegaBBS is prone to an information disclosure vulnerability. This issue is due to a failure in the application to properly verify user-supplied data.

An attacker can exploit this issue to view private messages of other users. Information obtained may aid in further attacks.

6. 427BB Showthread.PHP SQL Injection Vulnerability
BugTraq ID: 16169
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16169
Summary:
427BB is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

This issue affects versions 2.2 and 2.2.1; other versions may also be vulnerable.

7. BSD SecureLevel Time Setting Security Restriction Bypass Vulnerability
BugTraq ID: 16170
Remote: No
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16170
Summary:
BSD securelevels are susceptible to a security restriction bypass vulnerability that allows local attackers to set the system clock to any arbitrary value.

This vulnerability allows local attackers to set the system clock to any arbitrary value they desire, even those in the past, circumventing the securelevel restriction. Various further attacks against time-sensitive systems are then possible.

8. Bogofilter Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 16171
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16171
Summary:
Multiple remote buffer overflow vulnerabilities affect Bogofilter. These issues are due to a failure of the application to properly handle invalid input sequences and validate the length of user-supplied strings prior to copying them into static process buffers.

An attacker may exploit these issue to cause a denial of service condition. It may also be possible to execute arbitrary code with the privileges of the vulnerable application. This may facilitate unauthorized access or privilege escalation.

It should be noted that successful exploitation requires that Bogofilter is used with an unicode database.


9. Foxrum Multiple BBCode Tag Script Injection Vulnerabilities
BugTraq ID: 16172
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16172
Summary:
foxrum is prone to multiple script injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input prior to including it in dynamically generated content.

Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials.  Other attacks are also possible.

These issues are reported to affect version 4.0.4f; other versions may also be vulnerable.

10. NetBSD KernFS LSEEK Local Kernel Memory Disclosure Vulnerability
BugTraq ID: 16173
Remote: No
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16173
Summary:
The kernfs file system in NetBSD is prone to a kernel memory disclosure vulnerability. This issue arises due to insufficient sanitization of user-supplied arguments passed to the 'lseek()' system call.

Information disclosed through this attack may be used to launch other attacks against a computer and potentially aid in a complete compromise.

11. PHP PEAR Go-Pear.PHP Arbitrary Remote Code Execution Vulnerability
BugTraq ID: 16174
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16174
Summary:
go-pear.php is prone to a vulnerability that could permit the execution of arbitrary code.

Successful exploitation will facilitate a remote compromise of the affected computer.

This issue is reported to affect version 0.2.2; other versions may also be vulnerable.

12. SysCP WebFTP Module Local File Include Vulnerability
BugTraq ID: 16175
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16175
Summary:
SysCP WebFTP module is prone to a local file include vulnerability.

This may facilitate the unauthorized viewing of files and unauthorized execution of local scripts.

WebFTP 1.2.6 is reportedly vulnerable to this issue.  Other versions may be affected as well.

13. Venom Board Post.PHP3 Multiple SQL Injection Vulnerabilities
BugTraq ID: 16176
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16176
Summary:
Venom Board is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


14. Dave Carrigan Auth_LDAP Remote Format String Vulnerability
BugTraq ID: 16177
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16177
Summary:
Dave Carrigan's auth_ldap is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input prior to utilizing it in the format-specifier of a formatted printing function.

These issues likely only arise if auth_ldap has been enabled and is used for user authentication. 

This issue allows remote attackers to execute arbitrary machine code in the context of Apache Web servers that utilize the affected module. This may facilitate the compromise of affected computers.

15. 427BB Authentication Bypass Vulnerability
BugTraq ID: 16178
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16178
Summary:
427BB is prone to an authentication bypass vulnerability. This issue is due to a failure in the application to properly validate user-supplied data.

An attacker can exploit this issue to bypass the authentication mechanism and gain access to the affected application as an administrative user. This may facilitate a compromise of the underlying system; other attacks are also possible.

This issue affects version 2.2 and 2.2.1; other versions may also be vulnerable.

16. Qualcomm Eudora Internet Mail Server Multiple Denial of Service Vulnerabilities
BugTraq ID: 16179
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16179
Summary:
Qualcomm Eudora Internet Mail Server is prone to multiple denial of service vulnerabilities.

Malformed NTLM authentication requests, corrupted incoming Mail X or a malformed temporary mail file may trigger crashes.

It is conjectured that the first issue is remote in nature, however, the other two issues may present a local threat.  This is not confirmed.

EIMS 3.2.8 and prior versions are affected.

17. PHPChamber Search_result.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 16180
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16180
Summary:
phpChamber is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


18. Microsoft Excel Unspecified Code Execution Vulnerability
BugTraq ID: 16181
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16181
Summary:
Microsoft Excel is susceptible to an unspecified code execution vulnerability. The issue presents itself when Microsoft Excel attempts to process malformed or corrupted XLS files.

Attackers may exploit this issue to execute arbitrary machine code in the context of the affected application.

This BID will be updated as further information is disclosed. This issue is not believed to be related to the ones described in BID 15926 (Microsoft Excel Unspecified Memory Corruption Vulnerabilities).

19. Magic News Plus Administrator Password Change Vulnerability
BugTraq ID: 16182
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16182
Summary:
Magic News Plus is prone to a vulnerability regarding the administrator password. This issue is due to a failure in the application to properly verify user-supplied input.

An attacker can exploit this issue to change the administrator password and gain access to the affected application as the administrator. This may facilitate a compromise of the underlying system; other attacks are also possible.

This issue is reported to affect version 1.0.3; earlier versions may also be vulnerable.

20. Andromeda Andromeda.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 16183
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16183
Summary:
Andromeda is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

21. Sudo Python Environment Variable Handling Security Bypass Vulnerability
BugTraq ID: 16184
Remote: No
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16184
Summary:
Sudo is prone to a security bypass vulnerability that could lead to arbitrary code execution. This issue is due to an error in the application when handling environment variables.

A local attacker with the ability to run Python scripts can exploit this vulnerability to gain access to an interactive Python prompt. Attackers may then execute arbitrary code with elevated privileges, facilitating the complete compromise of affected computers.

An attacker must have the ability to run Python scripts through Sudo to exploit this vulnerability.

This issue is similar to BID 15394 ( Sudo Perl Environment Variable Handling Security Bypass Vulnerability).

22. Joomla Vcard Access Information Disclosure Vulnerability
BugTraq ID: 16185
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16185
Summary:
Joomla is prone to an information disclosure vulnerability. This issue is due to a failure in the application to properly secure sensitive and privileged information.

An attacker can exploit this issue to retrieve Vcard data. Such data consists of email addresses and other personal information. The information obtained may aid an attacker in harvesting email addresses for use in spam and malicious code attacks; other attacks are also possible.

23. PHPNuke EV Search Module SQL Injection Vulnerability
BugTraq ID: 16186
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16186
Summary:
PHPNuke EV is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

PHPNuke EV version 7.7 is vulnerable; earlier versions may also be affected.


24. ADOdb Server.PHP SQL Injection Vulnerability
BugTraq ID: 16187
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16187
Summary:
ADOdb is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

Exploitation of this issue requires the root password for MySQL to be empty and the affected script is located inside the Web root.

25. Stefan Frings SMS Server Tools Local Format String Vulnerability
BugTraq ID: 16188
Remote: No
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16188
Summary:
A local format string vulnerability affects Stefan Frings SMS Server Tools.

The problem presents itself when the affected application attempts to log messages using a formatted print function. User-supplied input is improperly sanitized prior to its inclusion in the format specifier argument of a formatted print function.

An attacker may leverage this issue to execute arbitrary code with superuser privileges, ultimately facilitating privilege escalation.

Version 1.14.8 of SMS Server Tools is vulnerable to this issue; other versions may also be affected.

26. Xoops Pool Module IMG Tag HTML Injection Vulnerability
BugTraq ID: 16189
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16189
Summary:
The XOOPS Pool Module is prone to an HTML injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.

27. Petris Local Buffer Overflow Vulnerability
BugTraq ID: 16190
Remote: No
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16190
Summary:
petris is vulnerable to a locally exploitable buffer overflow vulnerability.  It has been reported that a local attacker may exploit this condition to execute attacker-supplied code with group games privileges. 

Due to a lack of information, further details cannot be provided at the moment.  This BID will be updated when more information becomes available.

28. Clam Anti-Virus ClamAV UPX Compressed File Heap Buffer Overflow Vulnerability
BugTraq ID: 16191
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16191
Summary:
ClamAV is prone to a heap buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check user-supplied data prior to copying it to an insufficiently sized memory buffer.

This issue occurs when the application attempts to handle compressed UPX files.

Exploitation of this issue could allow attacker-supplied machine code to be executed in the context of the affected application. The issue would occur when the malformed file is scanned manually or automatically in deployments such as email gateways.

29. PHPNuke Multiple Modules IMG Tag HTML Injection Vulnerability
BugTraq ID: 16192
Remote: Yes
Date Published: 2006-01-09
Relevant URL: http://www.securityfocus.com/bid/16192
Summary:
The PHPNuke Pool and News Modules are prone to an HTML injection vulnerability.  This issue is due to a failure in the application modules to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.


30. Sun Solaris UUSTAT Local Buffer Overflow Vulnerability
BugTraq ID: 16193
Remote: No
Date Published: 2006-01-10
Relevant URL: http://www.securityfocus.com/bid/16193
Summary:
Sun Solaris uustat utility is prone to a local buffer overflow vulnerability. 

An attacker can exploit this issue to execute arbitrary code and gain 'uucp' user privileges which correspond to user ID 5 by default.

31. Microsoft Windows Embedded Web Font Buffer Overflow Vulnerability
BugTraq ID: 16194
Remote: Yes
Date Published: 2006-01-10
Relevant URL: http://www.securityfocus.com/bid/16194
Summary:
Microsoft Windows is susceptible to a remotely exploitable buffer overflow vulnerability. This issue is due to a failure of the software to properly bounds check user-supplied input prior to copying it to an insufficiently sized memory buffer.

This issue allows remote attackers to execute arbitrary machine code in the context of the vulnerable software on the targeted user's computer.

32. Hummingbird Enterprise Collaboration Multiple Vulnerabilities
BugTraq ID: 16195
Remote: Yes
Date Published: 2006-01-10
Relevant URL: http://www.securityfocus.com/bid/16195
Summary:
Hummingbird Enterprise Collaboration is prone to multiple vulnerabilities. 

The following specific issues were identified:

The application reportedly allows remote attackers to upload arbitrary HTML files and script code to the application.

Another vulnerability allows attackers to trick users into downloading potentially malicious files.

An attacker may also disclose sensitive information about the server by sending specially crafted HTTP GET requests.

Hummingbird Enterprise Collaboration 5.2.1 and prior versions are vulnerable to these issues.

33. WebWiz Forums Search_form.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 16196
Remote: Yes
Date Published: 2006-01-10
Relevant URL: http://www.securityfocus.com/bid/16196
Summary:
WebWiz Forums is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.


34. Microsoft Outlook / Microsoft Exchange TNEF Decoding Remote Code Execution Vulnerability
BugTraq ID: 16197
Remote: Yes
Date Published: 2006-01-10
Relevant URL: http://www.securityfocus.com/bid/16197
Summary:
Microsoft Exchange Server and Outlook email clients are prone to a remote code execution vulnerability.  

This vulnerability presents itself when the applications decode a message containing a specially crafted TNEF MIME attachment.  Successful exploitation may result in arbitrary code execution facilitating a remote compromise.

An attack against Microsoft Exchange Server could lead to a SYSTEM level remote compromise, while attacks against Outlook would result in arbitrary code execution in the context of the current user.


35. Trac HTML WikiProcessor Wiki Content HTML Injection Vulnerability
BugTraq ID: 16198
Remote: Yes
Date Published: 2006-01-10
Relevant URL: http://www.securityfocus.com/bid/16198
Summary:
Trac is prone to an HTML injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.


36. Orjinweb Index.PHP Remote File Include Vulnerability
BugTraq ID: 16199
Remote: Yes
Date Published: 2006-01-10
Relevant URL: http://www.securityfocus.com/bid/16199
Summary:
Orjinweb is prone to a remote file include vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.


37. Cisco IP Phone 7940 Remote Denial of Service Vulnerability
BugTraq ID: 16200
Remote: Yes
Date Published: 2006-01-10
Relevant URL: http://www.securityfocus.com/bid/16200
Summary:
Cisco IP Phone 7940 is prone to a remote denial of service vulnerability.

Successful exploitation causes the phone to restart.

Cisco is tracking this issue as Cisco bug ID CSCef33398.

38. PostgreSQL Postmaster Denial Of Service Vulnerability
BugTraq ID: 16201
Remote: Yes
Date Published: 2006-01-10
Relevant URL: http://www.securityfocus.com/bid/16201
Summary:
PostgreSQL is prone to a denial of service vulnerability. This issue is due to a failure in the application to properly handle exceptional conditions.

A remote attacker can exploit this issue to crash the postmaster service, thus denying future connections until the service is manually restarted.

This issue only affects PostgreSQL for Microsoft Windows.

39. Apple QuickTime Multiple Code Execution Vulnerabilities
BugTraq ID: 16202
Remote: Yes
Date Published: 2006-01-10
Relevant URL: http://www.securityfocus.com/bid/16202
Summary:
Apple QuickTime is prone to multiple remote code execution vulnerabilities. 

These issues arise when the application handles specially crafted QTIF, TGA, TIFF, and GIF image formats.

Successful exploitation of these issues may allow remote attacker to trigger a denial of service condition or gain unauthorized access.

QuickTime versions prior to 7.0.4 are vulnerable.

40. XMame Multiple Local Command Line Argument Buffer Overflow Vulnerabilities
BugTraq ID: 16203
Remote: No
Date Published: 2006-01-10
Relevant URL: http://www.securityfocus.com/bid/16203
Summary:
XMame is prone to locally exploitable buffer overflow vulnerabilities. These issues are due to insufficient bounds checking of command line parameters.

Successful exploitation on some systems could result in execution of malicious instructions with elevated privileges, as XMame may be installed with setuid-superuser privileges.

XMame version 0.102 is vulnerable to these issues; other versions may also be affected.

This issue may be related to BID 7773 (XMame Lang Local Buffer Overflow Vulnerability).

41. Blackberry Enterprise Server Attachment Service PNG Attachment Denial Of Service Vulnerability
BugTraq ID: 16204
Remote: Yes
Date Published: 2006-01-10
Relevant URL: http://www.securityfocus.com/bid/16204
Summary:
Research In Motion Blackberry Enterprise Server is prone to denial of service attacks.  This issue affects the Attachment Service and may be triggered by a malformed PNG attachment.

The issue is caused by a heap-based buffer overflow. This issue allows remote attackers to execute arbitrary machine code in the context of the affected Attachment Service. Failed exploitation attempts will likely cause a denial of service in the affected application.

42. Cray UNICOS Multiple Local Command Line Argument Buffer Overflow Vulnerabilities
BugTraq ID: 16205
Remote: No
Date Published: 2006-01-10
Relevant URL: http://www.securityfocus.com/bid/16205
Summary:
Cray UNICOS is prone to locally exploitable buffer overflow vulnerabilities. These issues are due to insufficient bounds checking of command line parameters in various utilities with setuid-superuser privileges.

Successful exploitation could result in execution of malicious machine code with superuser privileges, facilitating the complete compromise of affected computers.

These issues are reported in version 9.0.2.2 of UNICOS; other versions may also be affected.

43. CaLogic Calendars Add Event Multiple HTML Injection Vulnerabilities
BugTraq ID: 16206
Remote: Yes
Date Published: 2006-01-11
Relevant URL: http://www.securityfocus.com/bid/16206
Summary:
CaLogic Calendars is prone to multiple HTML injection vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.

Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.


44. FreeBSD EE Insecure Temporary File Creation Vulnerability
BugTraq ID: 16207
Remote: No
Date Published: 2006-01-11
Relevant URL: http://www.securityfocus.com/bid/16207
Summary:
ee creates temporary files in an insecure manner.

Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.


45. MyPhPim Addresses.PHP3 Arbitrary File Upload Vulnerability
BugTraq ID: 16208
Remote: Yes
Date Published: 2006-01-11
Relevant URL: http://www.securityfocus.com/bid/16208
Summary:
MyPhPim is prone to an arbitrary file upload vulnerability.

An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the Web server process.  This may facilitate unauthorized access or privilege escalation; other attacks are also possible.


46. FreeBSD IPFW IP Fragment Remote Denial Of Service Vulnerability
BugTraq ID: 16209
Remote: Yes
Date Published: 2006-01-11
Relevant URL: http://www.securityfocus.com/bid/16209
Summary:
FreeBSD's IPFW is susceptible to a remote denial of service vulnerability. This issue is due to a flaw in affected kernels that results in an uninitialized kernel memory access when handling ICMP IP fragments.

This issue allows remote attackers to crash affected kernels, denying further network service to legitimate users.

47. MyPhPim Multiple Input Validation Vulnerabilities
BugTraq ID: 16210
Remote: Yes
Date Published: 2006-01-11
Relevant URL: http://www.securityfocus.com/bid/16210
Summary:
MyPhPim is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.


48. Cisco CS-MARS Default Administrative Password Vulnerability
BugTraq ID: 16211
Remote: No
Date Published: 2006-01-11
Relevant URL: http://www.securityfocus.com/bid/16211
Summary:
Cisco Security Monitoring, Analysis and Response System (CS-MARS) sets a default administrative password during installation.  This password is static across all installations of the software.

Users with authenticated access to the CS-MARS command line interface may use this default password to gain unauthorized administrative access in affected installations.

It is possible for those running software release 4.1.3 and later to change a portion of the default administrative password, effectively addressing the vulnerability.  However, earlier versions do not provide this option.

49. Apple QuickTime PictureViewer JPEG/PICT File Buffer Overflow Vulnerability
BugTraq ID: 16212
Remote: Yes
Date Published: 2006-01-11
Relevant URL: http://www.securityfocus.com/bid/16212
Summary:
Apple QuickTime is prone to a buffer overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before copying it to finite sized process buffers.

An attacker may be able to exploit this issue to execute arbitrary machine code in the context of the affected application; this has not been confirmed. Unsuccessful exploitation attempts will most likely result in a crash of the application.

This issue affects QuickTime versions 6.5.2 and 7.0.3; other versions may also be vulnerable. Version 7.0.4 may also be vulnerable, this has not been confirmed.

This issue may have previously been discussed in BID 16202 (Apple QuickTime Multiple Code Execution Vulnerabilities).

50. eStara Softphone SIP SDP Data Packet Remote Buffer Overflow Vulnerability
BugTraq ID: 16213
Remote: Yes
Date Published: 2006-01-11
Relevant URL: http://www.securityfocus.com/bid/16213
Summary:
A remote buffer overflow vulnerability affects eStara Softphone. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.

An attacker may exploit this issue to execute arbitrary code with the privileges of the vulnerable application. This may facilitate unauthorized access or privilege escalation.

eStara Softphone versions 3.0.1.14, and 3.0.1.46 are vulnerable to this issue; other versions may also be affected.

51. Interspire TrackPoint NX Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 16214
Remote: Yes
Date Published: 2006-01-12
Relevant URL: http://www.securityfocus.com/bid/16214
Summary:
TrackPoint NX is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

TrackPoint NX versions less than 0.1 are reported to be vulnerable.


52. BEA WebLogic Server and WebLogic Express MBean Remote Information Disclosure Vulnerability
BugTraq ID: 16215
Remote: Yes
Date Published: 2006-01-12
Relevant URL: http://www.securityfocus.com/bid/16215
Summary:
BEA WebLogic Server and WebLogic Express are susceptible to a remote information disclosure vulnerability. This issue is due to the affected server application improperly disclosing potentially sensitive configuration information to anonymous users.

This issue allows remote attackers to gain access to potentially sensitive information that may aid them in further attacks.

53. Fog Creek Software FogBugz Default.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 16216
Remote: Yes
Date Published: 2006-01-12
Relevant URL: http://www.securityfocus.com/bid/16216
Summary:
FogBugz is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

FogBugz versions 4.029 and prior are vulnerable.


54. Cisco Aironet Wireless Access Point ARP Memory Exhaustion Denial Of Service Vulnerability
BugTraq ID: 16217
Remote: Yes
Date Published: 2006-01-12
Relevant URL: http://www.securityfocus.com/bid/16217
Summary:
Various Cisco Aironet wireless access point devices are prone to a denial of service vulnerability. This issue is due to memory exhaustion caused by improper handling of an excessive number of ARP requests.

This issue allows attackers that can successfully associate with a vulnerable access point to exhaust the memory of the affected device. This results in the device failing to pass legitimate traffic until it has been rebooted.

55. PHP Toolkit for PayPal IPN_success.PHP Logfile Injection Vulnerability
BugTraq ID: 16218
Remote: Yes
Date Published: 2006-01-12
Relevant URL: http://www.securityfocus.com/bid/16218
Summary:
A vulnerability exists in PHP Toolkit for PayPal which may allow a remote attacker to append entries to the PayPal transaction log file.

An attacker may be able to use this vulnerability to falsely obtain goods and services from a vendor running the affected application, if the vendor can be duped into believing that the goods ordered by the attacker have been paid for.


56. PHP MySQLI Error Logging Remote Format String Vulnerability
BugTraq ID: 16219
Remote: Yes
Date Published: 2006-01-12
Relevant URL: http://www.securityfocus.com/bid/16219
Summary:
PHP is susceptible to a remote format string vulnerability in the 'mysqli' extension. This issue is due to a failure of the application to properly sanitize user-supplied input prior to using it in the format-specifier argument to a formatted printing function.

This issue allows attackers to execute arbitrary machine code in the context of the Web server hosting the PHP interpreter.

This issue affects PHP 5.1.0, and 5.1.1.

57. PHP 5 User-Supplied Session ID Input Validation Vulnerability
BugTraq ID: 16220
Remote: Yes
Date Published: 2006-01-12
Relevant URL: http://www.securityfocus.com/bid/16220
Summary:
PHP 5 is prone to an input validation vulnerability. This is due to a lack of proper sanitization of user-supplied input of PHP session ID's, transmitted by way of HTTP headers.

An attacker may use this vulnerability to perform HTTP response splitting,  often resulting in content spoofing and cross-site scripting attacks.

PHP 5 version 5.1.1 and prior are affected.


58. Sun Solaris Find In Proc Filesystem Local Denial Of Service Vulnerability
BugTraq ID: 16222
Remote: No
Date Published: 2006-01-12
Relevant URL: http://www.securityfocus.com/bid/16222
Summary:
Sun Solaris is prone to a local denial of service vulnerability.

A local unprivileged attacker can cause a system panic by executing recursive operations in the '/proc' filesystem. This will crash the computer, denying further service to legitimate users.

59. Sun Solaris Operating System Unspecified Privilege Escalation Vulnerability
BugTraq ID: 16224
Remote: No
Date Published: 2006-01-12
Relevant URL: http://www.securityfocus.com/bid/16224
Summary:
Sun Solaris on x86 platforms is prone to an unspecified privilege escalation vulnerability. 

This vulnerability is due to an unspecified security issue which may allow a local unprivileged user to gain elevated privileges or panic the kernel.
This issue affects the Solaris 9 and 10 operating system.


60. Microsoft Visual Studio UserControl Remote Code Execution Vulnerability
BugTraq ID: 16225
Remote: Yes
Date Published: 2006-01-12
Relevant URL: http://www.securityfocus.com/bid/16225
Summary:
Microsoft Visual Studio is prone to a vulnerability that could allow remote arbitrary code execution. This is due to a design flaw that executes code contained in a project file without first notifying users.

This issue allows attackers to execute arbitrary code in the context of the user viewing a malicious project file. As viewing a project file is usually considered to be a safe operation, users may have a false sense of security by attempting to inspect unknown code prior to compiling or executing it.

This vulnerability may be remotely exploited due to project files originating from untrusted sources.

Visual Studio 2005 is reportedly vulnerable to this issue; other versions may also be affected.

61. SuSE Open Enterprise Server Novell Remote Manager HTTP Request Header Heap Overflow Vulnerability
BugTraq ID: 16226
Remote: Yes
Date Published: 2006-01-13
Relevant URL: http://www.securityfocus.com/bid/16226
Summary:
Novell Remote Manager (novell-nrm) is prone to a remotely exploitable heap overflow vulnerability.  This issue may be triggered by a malicious HTTP request header.

Successful exploitation will allow for arbitrary code execution in the context of the application.

Novell Remote Manager ships with the SuSE Open Enterprise Server only.

62. Wordcircle Multiple Input Validation Vulnerabilities
BugTraq ID: 16227
Remote: Yes
Date Published: 2006-01-12
Relevant URL: http://www.securityfocus.com/bid/16227
Summary:
Wordcircle is prone to multiple input validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.  Multiple SQL injection and HTML injection vulnerabilities affect the application.

Successful exploitation of these vulnerabilities could result in a compromise of the application, disclosure or modification of data, the theft of cookie-based authentication credentials. They may also permit an attacker to exploit vulnerabilities in the underlying database implementation as well as other attacks.

63. TankLogger General Functions Script SQL Injection Vulnerabilities
BugTraq ID: 16228
Remote: Yes
Date Published: 2006-01-12
Relevant URL: http://www.securityfocus.com/bid/16228
Summary:
TankLogger is prone to multiple SQL injection vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

64. Light Weight Calendar Index.PHP Remote Command Execution Vulnerability
BugTraq ID: 16229
Remote: Yes
Date Published: 2006-01-13
Relevant URL: http://www.securityfocus.com/bid/16229
Summary:
Light Weight Calendar is prone to a remote command execution vulnerability. This is due to a lack of proper sanitization of user-supplied input.

An attacker can exploit this issue to execute arbitrary remote PHP commands on an affected computer with the privileges of the Web server process.

Successful exploitation could facilitate unauthorized access; other attacks are also possible.


65. MyBB Usercp.PHP SQL Injection Vulnerability
BugTraq ID: 16230
Remote: Yes
Date Published: 2006-01-13
Relevant URL: http://www.securityfocus.com/bid/16230
Summary:
MyBB is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


66. DDSN Interactive CM3CMS Admin Panel Index.ASP SQL Injection Vulnerability
BugTraq ID: 16231
Remote: Yes
Date Published: 2006-01-13
Relevant URL: http://www.securityfocus.com/bid/16231
Summary:
DDSN cm3 CMS is prone to an SQL injection vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.


67. DCP Portal Multiple Input Validation Vulnerabilities
BugTraq ID: 16232
Remote: Yes
Date Published: 2006-01-13
Relevant URL: http://www.securityfocus.com/bid/16232
Summary:
DCP Portal is prone to multiple input validation vulnerabilities.  These issues are due to a failure in the application to properly sanitize user-supplied input.

For the cross-site scripting vulnerability, an attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  These may facilitate the theft of cookie-based authentication credentials as well as other attacks. 

For the HTML injection vulnerability, ttacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.


68.  AlstraSoft Template Seller Pro Fullview.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 16233
Remote: Yes
Date Published: 2006-01-13
Relevant URL: http://www.securityfocus.com/bid/16233
Summary:
Template Seller Pro is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

The discoverer of this vulnerability did not specify which version of this application is vulnerable.


69. Web Host Automation Ltd. Helm ForgotPassword.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 16234
Remote: Yes
Date Published: 2006-01-13
Relevant URL: http://www.securityfocus.com/bid/16234
Summary:
Helm is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

Version 3.2.8 is reported to be vulnerable; other versions may also be affected.


70. 123 Flash Chat Server Arbitrary Remote File Creation Vulnerability
BugTraq ID: 16235
Remote: Yes
Date Published: 2006-01-13
Relevant URL: http://www.securityfocus.com/bid/16235
Summary:
123 Flash Chat server is susceptible to an arbitrary remote file creation vulnerability. This issue is due to a lack of proper input sanitization of user-supplied data.

This issue allows remote attackers to create or overwrite arbitrary files on the server computer. This occurs with the privileges of the server process.

This issue affects versions 5.0, and 5.1 of 123 Flash Chat server; previous versions may also be affected.

71. Toshiba Bluetooth Stack Object Push Service File Upload Directory Traversal Vulnerability
BugTraq ID: 16236
Remote: Yes
Date Published: 2006-01-13
Relevant URL: http://www.securityfocus.com/bid/16236
Summary:
Toshiba Bluetooth Stack is prone to directory traversal attacks during Bluetooth file uploads.  The issue exists in the Object Push Service.

This vulnerability may allow an attacker to upload malicious files to arbitrary locations on affected computers over Bluetooth.  An attacker can take advantage of the issue to execute arbitrary code by uploading executables to a location on the computer where they will later be executed.

72. EZDatabaseRemote PHP Script Code Execution Vulnerability
BugTraq ID: 16237
Remote: Yes
Date Published: 2006-01-14
Relevant URL: http://www.securityfocus.com/bid/16237
Summary:
ezDatabase  is prone to a remote PHP script code execution vulnerability.

An attacker can exploit this issue to execute arbitrary malicious PHP code and execute it in the context of the Web server process. These may facilitate a compromise of the application and the underlying system; other attacks are also possible.

ezDatabase version 2.0 is vulnerable to these issues; other versions may also be affected.

73. Helmsman HomeFtp Remote Denial Of Service Vulnerability
BugTraq ID: 16238
Remote: Yes
Date Published: 2006-01-14
Relevant URL: http://www.securityfocus.com/bid/16238
Summary:
Helmsman HomeFtp is prone to a remote denial of service vulnerability. Successfully authentication is required to exploit this issue.

A remote attacker may exploit this issue to deny service for legitimate users.


III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Researcher: Sony BMG "rootkit" still widespread
By: Robert Lemos
Even as media giant Sony BMG settles six cases in New York, a security researcher finds hundreds of thousands of networks appear to still contain PCs with the controversial copy protection installed.
http://www.securityfocus.com/news/11369

2. Zero-day WMF flaw underscores patch problems
By: Robert Lemos
The Windows Meta File incident suggests that open-source efforts can result in quicker fixes but pose larger issues of trust, and highlights that companies can no longer depend on patches to protect their systems.
http://www.securityfocus.com/news/11368

3. Security flaws on the rise, questions remain
By: Robert Lemos
After three years of modest or no gains, the number of publicly reported vulnerabilities jumped in 2005, boosted by easy-to-find bugs in Web applications. Yet, questions remain about the value of analyzing current databases, whose data rarely correlates easily.
http://www.securityfocus.com/news/11367

4. Data security moves front and center in 2005
By: Robert Lemos
YEAR IN REVIEW: High-profile data breaches leaked more than 50 million database records in the United States, while phishing, bot networks, and targeted Trojan horses compromised millions of PCs worldwide. 
http://www.securityfocus.com/news/11366

5. Skype under scrutiny for bugs
By: John Leyden
The recent emergence of two sets of serious security vulnerabilities in Skype, the popular VoIP communications software app, couldn't have come at a worse time for the firm.
http://www.securityfocus.com/news/11354

6. Say hello to the Skype Trojan
By: John Leyden
Virus writers are targeting Skype users with a new Trojan that poses as the latest version of the popular VoIP software.
http://www.securityfocus.com/news/11348

7. Shared music abuse bug hits iTunes
By: John Leyden
Security researchers have discovered a vulnerability in Apple's popular iTunes application which might be exploited to interfere with shared music downloads.
http://www.securityfocus.com/news/11347

8. US cybersecurity all at sea
By: John Leyden
US cybersecurity risks are being poorly managed by the Department of Homeland Security, according to a former US presidential information security advisor.
http://www.securityfocus.com/news/11345

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Engineer, Chicago
http://www.securityfocus.com/archive/77/422121

2. [SJ-JOB] Sales Representative, Vienna
http://www.securityfocus.com/archive/77/422118

3. [SJ-JOB] Security Engineer, Atlanta
http://www.securityfocus.com/archive/77/422117

4. [SJ-JOB] Sales Representative, North Brunswick
http://www.securityfocus.com/archive/77/422030

5. [SJ-JOB] Security System Administrator, Santa Barbara
http://www.securityfocus.com/archive/77/422032

6. [SJ-JOB] Jr. Security Analyst, Charlotte
http://www.securityfocus.com/archive/77/422024

7. [SJ-JOB] Sr. Security Engineer, North Brunswick
http://www.securityfocus.com/archive/77/422025

8. [SJ-JOB] Auditor, North Brunswick
http://www.securityfocus.com/archive/77/422026

9. [SJ-JOB] Sales Engineer, Cupertino
http://www.securityfocus.com/archive/77/422014

10. [SJ-JOB] Security System Administrator, Louisville
http://www.securityfocus.com/archive/77/422013

11. [SJ-JOB] Security Researcher, Cupertino
http://www.securityfocus.com/archive/77/422021

12. [SJ-JOB] Technical Writer, Cupertino
http://www.securityfocus.com/archive/77/422022

13. [SJ-JOB] Security System Administrator, Rockaway
http://www.securityfocus.com/archive/77/422016

14. [SJ-JOB] Manager, Information Security, New York
http://www.securityfocus.com/archive/77/422036

15. [SJ-JOB] Security Director, Arlington
http://www.securityfocus.com/archive/77/422038

16. [SJ-JOB] Security Director, Arlington
http://www.securityfocus.com/archive/77/422015

17. [SJ-JOB] Manager, Information Security, New York
http://www.securityfocus.com/archive/77/422035

18. [SJ-JOB] Security Consultant, Denver
http://www.securityfocus.com/archive/77/422000

19. [SJ-JOB] Sales Engineer, Phoenix
http://www.securityfocus.com/archive/77/422001

20. [SJ-JOB] Auditor, New York
http://www.securityfocus.com/archive/77/422012

21. [SJ-JOB] Security Engineer, Richmond
http://www.securityfocus.com/archive/77/421978

22. [SJ-JOB] Security System Administrator, Tampa
http://www.securityfocus.com/archive/77/421980

23. [SJ-JOB] Security System Administrator, Tampa
http://www.securityfocus.com/archive/77/421981

24. [SJ-JOB] Director, Information Security, Wilmington
http://www.securityfocus.com/archive/77/421977

25. [SJ-JOB] Security Engineer, Washington
http://www.securityfocus.com/archive/77/421979

26. [SJ-JOB] Security Consultant, Bangalore , Mumbai
http://www.securityfocus.com/archive/77/421976

27. [SJ-JOB] Security Consultant, Canberra & Brisbane
http://www.securityfocus.com/archive/77/421982

28. [SJ-JOB] Security Product Manager, Longmont
http://www.securityfocus.com/archive/77/421973

29. [SJ-JOB] Account Manager, San Jose
http://www.securityfocus.com/archive/77/421974

30. [SJ-JOB] CHECK Team Leader, North Hampshire
http://www.securityfocus.com/archive/77/421975

31. [SJ-JOB] Security Director, Charlotte
http://www.securityfocus.com/archive/77/421752

32. [SJ-JOB] Sales Engineer, Slough
http://www.securityfocus.com/archive/77/421753

33. [SJ-JOB] Manager, Information Security, South Boston
http://www.securityfocus.com/archive/77/421749

34. [SJ-JOB] Sales Engineer, Atlanta
http://www.securityfocus.com/archive/77/421750

35. [SJ-JOB] Security Engineer, Washington DC Metro
http://www.securityfocus.com/archive/77/421751

36. [SJ-JOB] Sales Engineer, Scottsdale, AZ, Denver, CO or Huntingdon    Beach, CA
http://www.securityfocus.com/archive/77/421756

37. [SJ-JOB] Security Engineer, Huntsville
http://www.securityfocus.com/archive/77/421760

38. [SJ-JOB] Security Consultant, Annapolis Junction
http://www.securityfocus.com/archive/77/421757

39. [SJ-JOB] Application Security Engineer, Anywhere in the USA
http://www.securityfocus.com/archive/77/421761

40. [SJ-JOB] Security Engineer, Eastern Iowa
http://www.securityfocus.com/archive/77/421755

41. [SJ-JOB] Sales Representative, New York
http://www.securityfocus.com/archive/77/421759

42. [SJ-JOB] Developer, Foster City
http://www.securityfocus.com/archive/77/421591

43. [SJ-JOB] Developer, Foster City
http://www.securityfocus.com/archive/77/421586

44. [SJ-JOB] Developer, Foster City
http://www.securityfocus.com/archive/77/421587

45. [SJ-JOB] Sales Engineer, Atlanta
http://www.securityfocus.com/archive/77/421589

46. [SJ-JOB] Sales Engineer, Charlotte
http://www.securityfocus.com/archive/77/421588

47. [SJ-JOB] Sales Engineer, Alexandria
http://www.securityfocus.com/archive/77/421554

48. [SJ-JOB] Quality Assurance, Superior, Colorado
http://www.securityfocus.com/archive/77/421551

49. [SJ-JOB] Developer, Superior, Colorado
http://www.securityfocus.com/archive/77/421552

50. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/421553

51. [SJ-JOB] Sr. Security Analyst, London and South
http://www.securityfocus.com/archive/77/421550

52. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/421449

53. [SJ-JOB] Account Manager, New York
http://www.securityfocus.com/archive/77/421448

54. [SJ-JOB] Jr. Security Analyst, Bristol
http://www.securityfocus.com/archive/77/421446

55. [SJ-JOB] Sr. Security Analyst, London and South
http://www.securityfocus.com/archive/77/421447

56. [SJ-JOB] Sales Engineer, Oxfordshire
http://www.securityfocus.com/archive/77/421445

57. [SJ-JOB] Security Director, New York City
http://www.securityfocus.com/archive/77/421414

58. [SJ-JOB] Manager, Information Security, Lanham
http://www.securityfocus.com/archive/77/421425

59. [SJ-JOB] Sales Engineer, Metro DC
http://www.securityfocus.com/archive/77/421406

60. [SJ-JOB] Sales Engineer, London
http://www.securityfocus.com/archive/77/421409

61. [SJ-JOB] Sales Engineer, New York Area
http://www.securityfocus.com/archive/77/421405

V.   INCIDENTS LIST SUMMARY
---------------------------
1. Dead thread: Why was there no WMF Internet Attack...
http://www.securityfocus.com/archive/75/421581

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Advanced Buffer Overflow Methods lecture + PPT - Tel Aviv University
http://www.securityfocus.com/archive/82/421879

2. shellcoding on gentoo
http://www.securityfocus.com/archive/82/421847

3. EUSecWest papers and CanSecWest CFP
http://www.securityfocus.com/archive/82/421767

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Windows wireless flaw...
http://www.securityfocus.com/archive/88/421962

2. SecurityFocus Microsoft Newsletter #273
http://www.securityfocus.com/archive/88/421687

3. How to disable interactive logon for service accounts on W2K and W2K3
http://www.securityfocus.com/archive/88/421523

4. Different side of the problem (was)  New article on SecurityFocus
http://www.securityfocus.com/archive/88/421522

5. patching servers...
http://www.securityfocus.com/archive/88/421403

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Sendmail/Blacklists rejecting authenticated users
http://www.securityfocus.com/archive/91/421577

2. Hide internal address (Postfix)
http://www.securityfocus.com/archive/91/421374

X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored By: SpiDynamics

ALERT: Learn to Think Like a Hacker- Simulate a Hacker Breaking into Your Web Apps
The speed with which Web Applications are developed make them prime targets for attackers, often these applications were developed so quickly that they are not coded properly or subjected to any security testing. Hackers know this and use it as their weapon. Download this *FREE* test guide from SPI Dynamics to check for Web application vulnerabilities.

https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=701300000003P6V