SecurityFocus Newsletter #343
Peter Laborge <[email protected]> Wed, 29 Mar 2006 16:38:35 -0700
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #343
----------------------------------------
Test your Network Security Free with QualysGuard
Requiring NO software, QualysGuard will safely and accurately test your network and provide you with the necessary fixes to proactively guard your network. Try QualysGuard Risk Free with No Obligation.
http://www.securityfocus.com/cgi-bin/ib.pl
------------------------------------------------------------------
I. FRONT AND CENTER
1. Security Czar
2. Learning an advanced skillset
II. BUGTRAQ SUMMARY
1. DIA XFIG File Import Multiple Remote Buffer Overflow Vulnerabilities
2. EzASPSite Default.ASP SQL Injection Vulnerability
3. AkoComment akocomment.PHP Multiple SQL Injection Vulnerabilities
4. dotNetBB Forums dotNetBB Cross-Site Scripting Vulnerability
5. Metisware Instructor PersonalTaskEdit.ASP Cross-Site Scripting Vulnerability
6. Nuked-Klan Index.PHP SQL Injection Vulnerability
7. EZHomePagePro Multiple Cross-Site Scripting Vulnerabilities
8. SaphpLesson Print.PHP SQL Injection Vulnerability
9. uniForum Multiple Cross-Site Scripting Vulnerabilities
10. Absolute FAQ Manager Cross-Site Scripting Vulnerability
11. Calendar Express Multiple Cross-Site Scripting Vulnerabilities
12. WEBalbum Remote Command Execution Vulnerability
13. Microsoft Office Routing Slip Processing Remote Buffer Overflow Vulnerability
14. HP-UX Swagentd Remote Denial Of Service Vulnerability
15. ConfTool Index.PHP Cross-Site Scripting Vulnerability
16. PHP-Stats Multiple Input Validation and Information Disclosure Vulnerabilities
17. PHPBookingCalendar Details_View.PHP SQL Injection Vulnerability
18. PHP Ticket Search.PHP SQL Injection Vulnerability
19. DSDownload Multiple SQL-Injection Vulnerabilities
20. DSCounter Index.PHP SQL Injection Vulnerability
21. Pablo Software Solutions Quick 'n Easy FTP Server User Command Denial of Service Vulnerability
22. Microsoft Internet Explorer Script Action Handler Buffer Overflow Vulnerability
23. Zoo Misc.c Buffer Overflow Vulnerability
24. ImageMagick Image Filename Remote Command Execution Vulnerability
25. ImageMagick File Name Handling Remote Format String Vulnerability
26. eXpandable Home Page CMS Multiple Access Validation Vulnerabilities
27. Tetris-BSD Tetris-bsd.scores Local Privilege Escalation Vulnerability
28. RealNetworks Multiple Products Multiple Buffer Overflow Vulnerabilities
29. PhxContacts Login.PHP Cross-Site Scripting Vulnerability
30. Null News Multiple SQL Injection Vulnerabilities
31. PHP Classifieds Search.PHP Cross-Site Scripting Vulnerability
32. Explorer XP Multiple Input Validation Vulnerabilities
33. PHP Html_Entity_Decode() Information Disclosure Vulnerability
34. Sourceworkshop Newsletter Newsletter.PHP SQL Injection Vulnerability
35. cURL / libcURL URL Parser Buffer Overflow Vulnerability
36. PhxContacts Multiple SQL Injection Vulnerabilities
37. vCounter vCounter.PHP SQL Injection Vulnerability
38. PHPNewsManager Multiple SQL Injection Vulnerabilities
39. Sun Solaris Proc Filesystem Pagedata Subsystem Local Denial Of Service Vulnerability
40. Tilde CMS Index.PHP SQL Injection Vulnerability
41. PhpCollab Sendpassword.PHP SQL Injection Vulnerability
42. NetOffice Sendpassword.PHP SQL Injection Vulnerability
43. OneOrZero Helpdesk Index.PHP SQL Injection Vulnerability
44. PHP Script Index Search Parameter Cross-Site Scripting Vulnerability
45. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
46. MPlayer Multiple Integer Overflow Vulnerabilities
47. FreeRadius RLM_SQLCounter SQL Injection Vulnerability
48. FreeRADIUS Multiple RLM_SQLCounter Buffer Overflow Vulnerabilities
49. Horde Help Viewer Remote PHP Code Execution Vulnerability
50. FreeRADIUS Multiple Remote Vulnerabilities
51. D2KBlog Multiple Input Validation Vulnerabilities
52. Microsoft Internet Explorer CreateTextRange Remote Code Execution Vulnerability
53. PHPKIT Cross-Site Scripting Vulnerability
54. Debian GNU/Linux Multiple Packages Insecure RUNPATH Vulnerability
55. VWar Functions_install.PHP Remote File Include Vulnerability
56. AL-Caricatier Multiple Cross-Site Scripting Vulnerabilities
57. Connect Daily Multiple Cross-Site Scripting Vulnerabilities
58. Sun Grid Engine Local Privilege Escalation Vulnerability
59. CONTROLzx HMS Multiple Cross-Site Scripting Vulnerabilities
60. Genius VideoCAM NB Local Privilege Escalation Vulnerability
61. PHPmyfamily Track.PHP Cross-Site Scripting Vulnerability
62. phpCOIN Multiple Cross-Site Scripting Vulnerabilities
63. Tachyondecay VSNS Lemon Final_functions.PHP SQL Injection Vulnerability
64. NetPBM PSToPNM Arbitrary Code Execution Vulnerability
65. HP-UX Passwd Unspecified Local Denial of Service Vulnerability
66. ActiveCampaign SupportTrio Multiple Cross-Site Scripting Vulnerabilities
67. Web Host Automation Ltd. Helm ForgotPassword.ASP Cross-Site Scripting Vulnerability
68. Linux Kernel IP ID Information Disclosure Weakness
69. FusionZONE CouponZONE Multiple Cross-Site Scripting Vulnerabilities
70. FusionZONE CouponZONE Multiple SQL Injection Vulnerabilities
71. RealestateZONE Multiple Cross-Site Scripting Vulnerabilities
72. TWiki Remote Information Disclosure Vulnerability
73. Blazix Java Application/Web Server JSP Source Disclosure Vulnerability
74. ClassifiedZONE Accountlogon.CFM Cross-Site Scripting Vulnerability
75. FreeRADIUS EAP-MSCHAPv2 Authentication Bypass Vulnerability
76. MediaWiki Encoded Page Link HTML Injection Vulnerability
77. TWiki Remote Denial Of Service Vulnerability
78. Flex Code Generation Buffer Overflow Vulnerability
79. TFT Gallery Administrator Password Information Disclosure Vulnerability
80. Noah Grey Greymatter Arbitrary File Upload Vulnerability
81. DSLogin Index.PHP Multiple SQL Injection Vulnerabilities
82. BlankOL Bol.CGI Multiple Cross-Site Scripting Vulnerabilities
83. Web Host Automation Ltd. Helm Multiple Cross-Site Scripting Vulnerabilities
84. Vavoom Multiple Denial of Service Vulnerabilities
85. VERITAS NetBackup Multiple Remote Buffer Overflow Vulnerabilities
86. Xigla Absolute Live Support XE Multiple HTML Injection Vulnerabilities
87. Caloris Planitia Technologies School Management System Cross-Site Scripting Vulnerability
88. Veritas Backup Exec Multiple Remote Denial of Service Vulnerabilities
89. Pixel Motion Multiple SQL Injection Vulnerabilities
90. Meeting Reserve SearchResult.PHP Cross-Site Scripting Vulnerability
91. Online Quiz System Multiple Cross-Site Scripting Vulnerabilities
92. SweetSuite.NET Content Management System Search.ASPX Cross-Site Scripting Vulnerability
93. Microsoft Office XP Array Index Denial of Service Vulnerability
94. G-Book HTML Injection Vulnerability
95. PHPAdsNew and PHPPGAds Multiple Input Validation Vulnerabilities
96. CSDoom 2005 Multiple Buffer Overflow and Format String Vulnerabilities
97. Toast Forums Toast.ASP Multiple Cross-Site Scripting Vulnerabilities
98. Maian Weblog Multiple SQL-Injection Vulnerabilities
99. Microsoft .NET Framework SDK MSIL Tools Buffer Overflow Vulnerabilities
100. LibVC VCard Processing Buffer Overflow Vulnerability
III. SECURITYFOCUS NEWS
1. Patches released for zero-day IE threat
2. Check Point calls off Sourcefire buy
3. Debit-card fraud underscores legal loopholes
4. Virus names likely a lost cause
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Security Consultant, Reading
2. [SJ-JOB] Application Security Architect, London
3. [SJ-JOB] Manager, Information Security, London
4. [SJ-JOB] Security Engineer, Sydney
5. [SJ-JOB] Security Engineer, Zurich
6. [SJ-JOB] Forensics Engineer, Falls Church
7. [SJ-JOB] Information Assurance Engineer, Falls Church
8. [SJ-JOB] Certification & Accreditation Engineer, Arlington (Crystal City)
9. [SJ-JOB] Sales Engineer, North Central USA
10. [SJ-JOB] Security Consultant, london
11. [SJ-JOB] Sr. Security Analyst, Pune
12. [SJ-JOB] Management, Melville
13. [SJ-JOB] Sales Representative, Western USA
14. [SJ-JOB] Sales Representative, North Central USA
15. [SJ-JOB] Security Consultant, All
16. [SJ-JOB] Security System Administrator, Washington D.C.
17. [SJ-JOB] Security Architect, Detroit
18. [SJ-JOB] Sr. Security Engineer, Munich
19. [SJ-JOB] Developer, Columbia
20. [SJ-JOB] Customer Support, Columbia
21. [SJ-JOB] Security Engineer, New York City
22. [SJ-JOB] Security Engineer, Washington D.C.
23. [SJ-JOB] Security Consultant, Atlanta
24. [SJ-JOB] VP, Information Security, Columbus
25. [SJ-JOB] CSO, Moscow
26. [SJ-JOB] Security Consultant, New York
27. [SJ-JOB] Security Architect, New York
28. [SJ-JOB] Security Consultant, San Francisco & LA
29. [SJ-JOB] Security Architect, San Francisco or Los Angeles
30. [SJ-JOB] Customer Service, Schaumburg
31. [SJ-JOB] Information Assurance Analyst, Battle Creek
32. [SJ-JOB] Sr. Security Engineer, NW London
33. [SJ-JOB] Chief Security Strategist, Schaumburg
34. [SJ-JOB] Security Consultant, Raleigh Durham
35. [SJ-JOB] Security Architect, Santa Barbara
36. [SJ-JOB] Manager, Information Security, Milwaukee
37. [SJ-JOB] Security Engineer, Cambridge
38. [SJ-JOB] Manager, Information Security, Newport
39. [SJ-JOB] VP / Dir / Mgr engineering, McLean
40. [SJ-JOB] Sr. Security Analyst, Edison
41. [SJ-JOB] Manager, Information Security, Richmond
42. [SJ-JOB] Manager, Information Security, Boston
43. [SJ-JOB] Sales Representative, Birmingham
44. [SJ-JOB] Account Manager, East Coast
45. [SJ-JOB] Security Consultant, Birmingham
46. [SJ-JOB] Information Assurance Analyst, Vienna
47. [SJ-JOB] Information Assurance Analyst, Vienna
48. [SJ-JOB] Management, Minneapolis
49. [SJ-JOB] Management, New York
50. [SJ-JOB] Manager, Information Security, NYC
V. INCIDENTS LIST SUMMARY
1. Internet SSH scans thread
2. Win2k Machine contacting Root Server???
3. A pretty neat Chase Phish
VI. VULN-DEV RESEARCH LIST SUMMARY
1. Beating memory address randomization (secuirty) features in Unix/Linux
2. PasswordSafe 3.0 weak random number generator allows key recovery attack
3. Data Entropy Tool
4. foundstone free tool (ms05-039)
VII. MICROSOFT FOCUS LIST SUMMARY
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
1. Systrace 1.6: Phoenix Release for Linux
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Security Czar
By Scott Granneman
In this column Scott Granneman takes the role of dictator of the security world and presents his ideas about mandatory reforms that would improve security for millions of people.
http://www.securityfocus.com/columnists/394
2. Learning an advanced skillset
By Don Parker
The purpose of this article is to guide network security analysts towards learning the advanced skillset required to help further their careers. We'll look at two key pillars of knowledge, protocols and programming, and why they're both so important in the security field.
http://www.securityfocus.com/infocus/1861
II. BUGTRAQ SUMMARY
--------------------
1. DIA XFIG File Import Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 17310
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17310
Summary:
Dia is affected by multiple remote buffer-overflow vulnerabilities. These issues are due to the application's failure to properly bounds-check user-supplied input before copying it into insufficiently sized memory buffers.
These issues allow remote attackers to execute arbitrary machine code in the context of the user running the affected application to open attacker-supplied malicious XFig files.
2. EzASPSite Default.ASP SQL Injection Vulnerability
BugTraq ID: 17309
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17309
Summary:
EzASPSite is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
EzASPSite versions 2.0 RC3 and prior are affected by this issue.
3. AkoComment akocomment.PHP Multiple SQL Injection Vulnerabilities
BugTraq ID: 17241
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17241
Summary:
AkoComment is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
4. dotNetBB Forums dotNetBB Cross-Site Scripting Vulnerability
BugTraq ID: 17246
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17246
Summary:
dotNetBB is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
5. Metisware Instructor PersonalTaskEdit.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 17234
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17234
Summary:
Metisware Instructor is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
6. Nuked-Klan Index.PHP SQL Injection Vulnerability
BugTraq ID: 17233
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17233
Summary:
Nuked-Klan is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
7. EZHomePagePro Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17236
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17236
Summary:
EZHomePagePro is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
8. SaphpLesson Print.PHP SQL Injection Vulnerability
BugTraq ID: 17239
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17239
Summary:
SaphpLesson is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
9. uniForum Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17245
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17245
Summary:
uniForum is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
These issues affect uniForum 4.
10. Absolute FAQ Manager Cross-Site Scripting Vulnerability
BugTraq ID: 17242
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17242
Summary:
Absolute FAQ Manager is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
11. Calendar Express Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17240
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17240
Summary:
Calendar Express is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
These issues affect Calendar Express 2.2.
12. WEBalbum Remote Command Execution Vulnerability
BugTraq ID: 17228
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17228
Summary:
WEBalbum is prone to a remote command-execution vulnerability. The issue exists because the application fails to sanitize paths in cookies before using them in includes.
WEBalbum 2.02pl is vulnerable; earlier versions may also be affected.
13. Microsoft Office Routing Slip Processing Remote Buffer Overflow Vulnerability
BugTraq ID: 17000
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17000
Summary:
Microsoft Office is prone to a remote buffer-overflow vulnerability.
This vulnerability occurs when the application handles a specially crafted document. A successful attack can result in a remote compromise in the context of an affected user.
14. HP-UX Swagentd Remote Denial Of Service Vulnerability
BugTraq ID: 17215
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17215
Summary:
A remote denial-of-service vulnerability has been reported in the HP-UX 'swagentd' daemon.
A remote unauthenticated user may cause the swagentd server daemon to become unresponsive.
The precise technical details of this vulnerability are currently unknown. This BID will be updated as further information becomes available.
15. ConfTool Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17231
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17231
Summary:
ConfTool is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
16. PHP-Stats Multiple Input Validation and Information Disclosure Vulnerabilities
BugTraq ID: 16963
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/16963
Summary:
PHP-Stats is prone to multiple vulnerabilities:
- Multiple input-validation vulnerabilities that lead to SQL injections, PHP code injections, local file includes, and authentication bypasses.
- An SQL-injection vulnerability.
- An information-disclosure vulnerability.
These issues allow remote attackers to execute arbitrary PHP script code in the context of the hosting webserver, gain administrative privileges in the web application, and gain access to potentially sensitive information.
The SQL-injection vulnerabilities could permit remote attackers to pass malicious input to database queries, resulting in the modification of query logic or other attacks. Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Other attacks may also be possible.
PHP-Stats version 0.1.9.1 is vulnerable to these issues; other versions may also be affected.
17. PHPBookingCalendar Details_View.PHP SQL Injection Vulnerability
BugTraq ID: 17230
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17230
Summary:
phpBookingCalendar is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
18. PHP Ticket Search.PHP SQL Injection Vulnerability
BugTraq ID: 17229
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17229
Summary:
PHP Ticket is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
19. DSDownload Multiple SQL-Injection Vulnerabilities
BugTraq ID: 17116
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17116
Summary:
DSDownload is prone to multiple SQL-injection vulnerabilities. The application fails to properly sanitize user-supplied input before using it in SQL queries.
This will allow an attacker to inject arbitrary SQL logic into the vulnerable parameters and scripts. As a result, the attacker may be able to access or modify sensitive information, compromise the application, or even compromise the underlying database. Other attacks are possible.
20. DSCounter Index.PHP SQL Injection Vulnerability
BugTraq ID: 17112
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17112
Summary:
DSCounter is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
21. Pablo Software Solutions Quick 'n Easy FTP Server User Command Denial of Service Vulnerability
BugTraq ID: 14451
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/14451
Summary:
Quick 'n Easy FTP Server is prone to a remotely exploitable denial-of-service vulnerability. Attackers may trigger this through an overly long argument for the USER command.
Successful exploitation may exhaust system resources and crash the server.
This issue was originally identified as a buffer-overflow vulnerability. Due to the availability of more details, it is being changed to a denial-of-service vulnerability.
22. Microsoft Internet Explorer Script Action Handler Buffer Overflow Vulnerability
BugTraq ID: 17131
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17131
Summary:
Microsoft Internet Explorer is susceptible to a remote buffer-overflow vulnerability in 'MSHTML.DLL'. The application fails to properly bounds-check user-supplied input data before copying it into an insufficiently sized memory buffer.
Remote attackers may exploit this issue to crash affected web browsers. Remote code execution may also be possible, but this has not been confirmed.
Internet Explorer 6 is vulnerable to this issue; other versions may also be affected.
23. Zoo Misc.c Buffer Overflow Vulnerability
BugTraq ID: 16790
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/16790
Summary:
Zoo is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before using it in a finite-sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the victim user running the affected application.
24. ImageMagick Image Filename Remote Command Execution Vulnerability
BugTraq ID: 16093
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/16093
Summary:
ImageMagick is prone to a remote shell command-execution vulnerability.
Successful exploitation can allow arbitrary commands to be executed in the context of the affected user. Note that attackers could exploit this issue through other applications that use ImageMagick as the default image viewer.
ImageMagick 6.2.4.5 is reportedly vulnerable. Other versions may be affected as well.
25. ImageMagick File Name Handling Remote Format String Vulnerability
BugTraq ID: 12717
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/12717
Summary:
ImageMagick is reported prone to a remote format-string vulnerability.
Reportedly, this issue arises when the application handles malformed filenames. An attacker can exploit this vulnerability by crafting a malicious file with a name that contains format specifiers and sending the file to an unsuspecting user.
Note that there are other attack vectors that may not require user interaction, since the application can be used with custom printing systems and web applications.
A successful attack may crash the application or lead to arbitrary code execution.
All versions of ImageMagick are considered vulnerable at the moment.
26. eXpandable Home Page CMS Multiple Access Validation Vulnerabilities
BugTraq ID: 17209
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17209
Summary:
eXpandable Home Page CMS is prone to multiple access-validation vulnerabilities. These issues are due to a failure in the application to limit access to administrative sections of the application.
A successful exploit may allow an attacker to access potentially sensitive information and to execute arbitrary PHP code in the context of the webserver process.
This issue is reported to affect XHP CMS version 0.5; other versions may also be vulnerable.
27. Tetris-BSD Tetris-bsd.scores Local Privilege Escalation Vulnerability
BugTraq ID: 17308
Remote: No
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17308
Summary:
Tetris-BSD is prone to a local privilege-escalation vulnerability. The issue results from a design error.
A local attacker can leverage this issue to exploit latent vulnerabilities in applications by overwriting shared game data files.
28. RealNetworks Multiple Products Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 17202
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17202
Summary:
Various RealNetworks products are prone to multiple buffer-overflow vulnerabilities.
These issues can result in memory corruption and facilitate arbitrary code execution. A successful attack can allow remote attackers to execute arbitrary code in the context of the application to gain unauthorized access.
29. PhxContacts Login.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17307
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17307
Summary:
PhxContacts is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
PhxContacts versions 0.93.1 and prior are reported vulnerable.
30. Null News Multiple SQL Injection Vulnerabilities
BugTraq ID: 17300
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17300
Summary:
Null News is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Version 2005.07.27 is reported to be vulnerable. Other versions may be affected as well.
31. PHP Classifieds Search.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17305
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17305
Summary:
PHP Classifieds is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
PHP Classifieds version 6.18 and 6.20 are reported to be vulnerable; other versions may also be affected.
32. Explorer XP Multiple Input Validation Vulnerabilities
BugTraq ID: 17303
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17303
Summary:
Explorer XP is prone to cross-site scripting and information-disclosure vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage the cross-site scripting issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
An attacker may leverage the information-disclosure issue to gain access to the contents of arbitrary files with the privileges of the hosting webserver. This may aid the attacker in further attacks.
33. PHP Html_Entity_Decode() Information Disclosure Vulnerability
BugTraq ID: 17296
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17296
Summary:
PHP 'html_entity_decode()' function is prone to an information-disclosure vulnerability. This issue arises when a script using the function accepts data from a remote untrusted source and returns the function's result to an attacker.
Information that the attacker gathers by exploiting this vulnerability may aid in other attacks.
PHP versions prior to 5.1.3-RC1 are vulnerable to this issue.
34. Sourceworkshop Newsletter Newsletter.PHP SQL Injection Vulnerability
BugTraq ID: 17304
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17304
Summary:
Newsletter is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Newsletter version 1.0 is reported to be affected. Other versions may be vulnerable as well.
35. cURL / libcURL URL Parser Buffer Overflow Vulnerability
BugTraq ID: 15756
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/15756
Summary:
cURL and libcURL are prone to a buffer-overflow vulnerability. This issue is due to a failure in the library to perform proper bounds checks on user-supplied data before using it in a finite-sized buffer.
The issues occur when the URL parser function handles an excessively long URL string.
An attacker can exploit this issue to crash the affected library, effectively denying service. Arbitrary code execution may also be possible, which may facilitate a compromise of the underlying system.
36. PhxContacts Multiple SQL Injection Vulnerabilities
BugTraq ID: 17306
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17306
Summary:
PhxContacts is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
PhxContacts 0.93.1 and prior are vulnerable; other versions may also be affected.
37. vCounter vCounter.PHP SQL Injection Vulnerability
BugTraq ID: 17302
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17302
Summary:
vCounter is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
vCounter version 1.0 is reported affected. Other versions may be vulnerable as well.
38. PHPNewsManager Multiple SQL Injection Vulnerabilities
BugTraq ID: 17301
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17301
Summary:
phpNewsManager is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
phpNewsManager 1.48 is vulnerable; other versions may also be affected.
39. Sun Solaris Proc Filesystem Pagedata Subsystem Local Denial Of Service Vulnerability
BugTraq ID: 16966
Remote: No
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/16966
Summary:
Sun Solaris is prone to a local denial-of-service vulnerability. This issue affects the pagedata subsystem of the Process File System.
A local unauthorized user can cause a system crash.
40. Tilde CMS Index.PHP SQL Injection Vulnerability
BugTraq ID: 17299
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17299
Summary:
Tilde CMS is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Tilde CMS 3 is reported affected. Other versions may be vulnerable as well.
41. PhpCollab Sendpassword.PHP SQL Injection Vulnerability
BugTraq ID: 17283
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17283
Summary:
The phpCollab application is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
42. NetOffice Sendpassword.PHP SQL Injection Vulnerability
BugTraq ID: 17286
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17286
Summary:
NetOffice is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
43. OneOrZero Helpdesk Index.PHP SQL Injection Vulnerability
BugTraq ID: 17298
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17298
Summary:
OneOrZero Helpdesk is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
OneOrZero Helpdesk 1.6.3.0 is prone to this issue. Other versions may be affected as well.
44. PHP Script Index Search Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 17297
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17297
Summary:
PHP Script Index is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
All versions of PHP Script Index are considered to be vulnerable.
This issue may be related to BID 14154 (AutoIndex PHP Script Index.PHP Cross-Site Scripting Vulnerability). If subsequent analysis reveals that the two issues are identical, this BID will be retired.
45. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
BugTraq ID: 17192
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17192
Summary:
Sendmail is prone to a remote code-execution vulnerability.
Remote attackers may leverage this issue to execute arbitrary code with the privileges of the application, which typically runs as superuser.
Sendmail versions prior to 8.13.6 are vulnerable to this issue.
46. MPlayer Multiple Integer Overflow Vulnerabilities
BugTraq ID: 17295
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17295
Summary:
MPlayer is susceptible to two integer-overflow vulnerabilities. An attacker may exploit these issues to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may help the attacker gain unauthorized access or escalate privileges.
MPlayer version 1.0.20060329 is affected by these issues; other versions may also be affected.
47. FreeRadius RLM_SQLCounter SQL Injection Vulnerability
BugTraq ID: 17294
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17294
Summary:
FreeRADIUS is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
48. FreeRADIUS Multiple RLM_SQLCounter Buffer Overflow Vulnerabilities
BugTraq ID: 17293
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17293
Summary:
FreeRADIUS is prone to multiple buffer-overflow vulnerabilities. These issues are due to a failure in the application to do proper bounds checking on user-supplied data.
Reportedly, these issues may result in a denial-of-service condition only. Attackers cannot exploit these issues to gain unauthorized remote access.
49. Horde Help Viewer Remote PHP Code Execution Vulnerability
BugTraq ID: 17292
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17292
Summary:
Horde is prone to a remote PHP code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary malicious PHP code and in the context of the webserver process. This may help the attacker compromise the application and the underlying system; other attacks are also possible.
Horde versions 3.0 up to 3.0.9 and 3.1.0 are vulnerable; other versions may also be affected.
50. FreeRADIUS Multiple Remote Vulnerabilities
BugTraq ID: 14775
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/14775
Summary:
FreeRADIUS is susceptible to multiple remote vulnerabilities.
- Memory-handling vulnerabilities. These issues may allow remote attackers to crash affected services or possibly execute arbitrary machine code in the context of the vulnerable application.
- File descriptor leak. Attackers may exploit this to gain access to files that they may not normally have access to.
- The LDAP module contains a flaw whereby attacker-specified data may be passed on to the configured LDAP database without proper input sanitization.
These issues are all reported to affect version 1.0.4 of FreeRADIUS; previous versions are also likely vulnerable to one or more of these issues.
**Update: The vendor has posted a response to these issues. Please see "Response to Suse Audit Report on FreeRADIUS" for further details.
51. D2KBlog Multiple Input Validation Vulnerabilities
BugTraq ID: 17035
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17035
Summary:
D2KBlog is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
The application is prone to HTML-injection and SQL-injection vulnerabilities.
D2KBlog versions 1.0.3 and prior are vulnerable to these issues; other versions may also be affected.
52. Microsoft Internet Explorer CreateTextRange Remote Code Execution Vulnerability
BugTraq ID: 17196
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17196
Summary:
Microsoft Internet Explorer is susceptible to a remote code-execution vulnerability. This issue is due to a flaw that results in an invalid table-pointer dereference.
Remote attackers may exploit this issue to crash affected browsers or to execute arbitrary machine code in the context of affected users.
Microsoft has reported that this issue does not affect the March 20, 2006 release of Internet Explorer 7 Beta 2 Preview.
53. PHPKIT Cross-Site Scripting Vulnerability
BugTraq ID: 17291
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17291
Summary:
PHPKIT is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
PHPKIT 1.6.03 is reported vulnerable; other versions may also be affected.
54. Debian GNU/Linux Multiple Packages Insecure RUNPATH Vulnerability
BugTraq ID: 17288
Remote: No
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17288
Summary:
Multiple packages in Debian GNU/Linux are susceptible to an insecure RUNPATH vulnerability. This issue is due to a flaw in the build system that results in insecure RUNPATHs being included in certain binaries.
This vulnerability may result in arbitrary code being executed in the context of users who run the vulnerable executables. This may facilitate privilege escalation.
55. VWar Functions_install.PHP Remote File Include Vulnerability
BugTraq ID: 17290
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17290
Summary:
VWar is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Versions 1.5.0 and prior are vulnerable; other versions may also be affected.
56. AL-Caricatier Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17289
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17289
Summary:
AL-Caricatier is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
57. Connect Daily Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17287
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17287
Summary:
Connect Daily is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
58. Sun Grid Engine Local Privilege Escalation Vulnerability
BugTraq ID: 16366
Remote: No
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/16366
Summary:
Sun Grid Engine is susceptible to a local privilege-escalation vulnerability.
This issue allows local users to gain superuser privileges, facilitating the complete compromise of affected computers.
Sun Grid Engine versions prior to 6.0u7_1 are vulnerable to this issue.
59. CONTROLzx HMS Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17282
Remote: Yes
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17282
Summary:
CONTROLzx HMS is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
CONTROLzx HMS 3.3.4 is vulnerable. Other versions may be affected as well.
60. Genius VideoCAM NB Local Privilege Escalation Vulnerability
BugTraq ID: 17284
Remote: No
Last Updated: 2006-03-29
Relevant URL: http://www.securityfocus.com/bid/17284
Summary:
Genius VideoCAM NB is susceptible to a local privilege-escalation vulnerability. This issue is due to the application's failure to properly lower the privileges of the running process when required.
The affected driver executes with SYSTEM privileges and fails to drop these elevated privileges when displaying a file-save dialog.
This vulnerability allows local attackers to access and execute arbitrary files with SYSTEM privileges, facilitating the compromise of the local computer.
61. PHPmyfamily Track.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17278
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17278
Summary:
The 'phpmyfamily' application is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
62. phpCOIN Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17279
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17279
Summary:
phpCOIN is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions 1.2.2 and prior are vulnerable; other versions may also be affected.
63. Tachyondecay VSNS Lemon Final_functions.PHP SQL Injection Vulnerability
BugTraq ID: 17281
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17281
Summary:
VSNS Lemon is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
64. NetPBM PSToPNM Arbitrary Code Execution Vulnerability
BugTraq ID: 14379
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/14379
Summary:
The 'pstopnm' command is susceptible to an arbitrary command-execution vulnerability. This issue is due to the program's failure of to ensure that GhostScript is executed in a secure manner.
This issue allows attackers to create malicious PostScript files that allow arbitrary commands to be executed when the affected utility parses the files. This occurs in the context of the user running the affected utility.
This vulnerability was reported in version 10.0 of netpbm. Other versions may also be affected.
65. HP-UX Passwd Unspecified Local Denial of Service Vulnerability
BugTraq ID: 17280
Remote: No
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17280
Summary:
HP-UX passwd(1) is prone to an unspecified local denial-of-service vulnerability.
This issue arises because the software fails to handle exceptional conditions in a proper manner.
Due to a lack of details, further information cannot be provided at the moment. This BID will be updated when more information becomes available.
66. ActiveCampaign SupportTrio Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17276
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17276
Summary:
ActiveCampaign SupportTrio is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
ActiveCampaign SupportTrio 2.50.2 is vulnerable. Other versions may be affected as well.
67. Web Host Automation Ltd. Helm ForgotPassword.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 16234
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/16234
Summary:
Helm is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Version 3.2.8 is reported vulnerable; other versions may also be affected.
68. Linux Kernel IP ID Information Disclosure Weakness
BugTraq ID: 17109
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17109
Summary:
The Linux kernel is susceptible to a remote information-disclosure weakness. This issue is due to an implementation flaw of a zero 'ip_id' information-disclosure countermeasure.
This issue allows remote attackers to use affected computers in stealth network port and trust scans.
The Linux kernel 2.6 series, as well as some kernels in the 2.4 series, are affected by this weakness.
69. FusionZONE CouponZONE Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17272
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17272
Summary:
The couponZONE application is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Version 4.2 of couponZONE is reported to be vulnerable. Other versions may be affected as well.
70. FusionZONE CouponZONE Multiple SQL Injection Vulnerabilities
BugTraq ID: 17274
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17274
Summary:
The couponZONE application is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Version 4.2 of couponZONE reported vulnerable. Other versions may be affected as well.
71. RealestateZONE Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17277
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17277
Summary:
The realestateZONE script is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
72. TWiki Remote Information Disclosure Vulnerability
BugTraq ID: 17268
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17268
Summary:
TWiki is prone to an information-disclosure vulnerability. The application fails to properly sanitize user-supplied input.
Attackers may gain access to arbitrary, restricted content files with the privileges of the hosting webserver. This can aid in further attacks.
73. Blazix Java Application/Web Server JSP Source Disclosure Vulnerability
BugTraq ID: 17270
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17270
Summary:
A problem with Blazix Java Application/Web Server results in the disclosure of the source code of Java Server Pages. This allows attackers to gain unauthorized access to sensitive information, potentially aiding them in further attacks.
This issue affects Blazix Java Application/Web Server 1.2.5 on Windows. Other versions may be vulnerable as well.
74. ClassifiedZONE Accountlogon.CFM Cross-Site Scripting Vulnerability
BugTraq ID: 17273
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17273
Summary:
The classifiedZONE script is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
75. FreeRADIUS EAP-MSCHAPv2 Authentication Bypass Vulnerability
BugTraq ID: 17171
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17171
Summary:
FreeRADIUS is prone to an authentication-bypass vulnerability. The issue exists in the EAP-MSCHAPv2 state machine. Bypassing authentication could also cause the server to crash.
FreeRADIUS versions from 1.0.0 to 1.1.0 are vulnerable.
76. MediaWiki Encoded Page Link HTML Injection Vulnerability
BugTraq ID: 17269
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17269
Summary:
MediaWiki is prone to an HTML-injection vulnerability. This issue is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
77. TWiki Remote Denial Of Service Vulnerability
BugTraq ID: 17267
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17267
Summary:
TWiki is prone to a remote denial-of-service vulnerability. This issue is due to a design error.
An attacker may exploit this vulnerability to deny service to legitimate users.
78. Flex Code Generation Buffer Overflow Vulnerability
BugTraq ID: 16896
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/16896
Summary:
Flex is prone to a buffer-overflow vulnerability. This issue is due to a failure in the application to do proper bounds checking on user-supplied data before using it in finite-sized memory buffers.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. This may facilitate a compromise of the underlying computer.
Flex versions 2.5.31 and prior are vulnerable.
79. TFT Gallery Administrator Password Information Disclosure Vulnerability
BugTraq ID: 17250
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17250
Summary:
TFT Gallery is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to do proper access validation before granting access to sensitive and privileged information.
An attacker can exploit this vulnerability to obtain the application's administrative encrypted password. The attacker may then use this to carry out brute-force attacks to gain administrative access.
Information that the attacker obtains may aid in further attacks against the underlying system; other attacks are also possible.
80. Noah Grey Greymatter Arbitrary File Upload Vulnerability
BugTraq ID: 17271
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17271
Summary:
Greymatter is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
81. DSLogin Index.PHP Multiple SQL Injection Vulnerabilities
BugTraq ID: 17262
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17262
Summary:
DSLogin is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
82. BlankOL Bol.CGI Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17265
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17265
Summary:
BlankOL is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
83. Web Host Automation Ltd. Helm Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17263
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17263
Summary:
Helm is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
A beta version of 3.2.10 is reported to be vulnerable; other versions may also be affected.
84. Vavoom Multiple Denial of Service Vulnerabilities
BugTraq ID: 17261
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17261
Summary:
Vavoom is prone to two denial-of-service vulnerabilities. These issues can cause the application to stop responding or fail.
Vavoom 1.19.1 and earlier are affected.
85. VERITAS NetBackup Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 17264
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17264
Summary:
Various daemons running in VERITAS NetBackup are prone to buffer-overflow vulnerabilities.
Specifically, the vulnerabilities affect the volume manager daemon ('vmd'), the NetBackup Catalog daemon ('bpdbm'), and the NetBackup Sharepoint Services server daemon ('bpspsserver').
A successful attack may allow remote attackers to execute arbitrary code on a vulnerable computer to gain unauthorized access in the context of the application.
These issues affect various versions of NetBackup servers and clients.
86. Xigla Absolute Live Support XE Multiple HTML Injection Vulnerabilities
BugTraq ID: 17258
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17258
Summary:
Absolute Live Support XE is prone to HTML-injection vulnerabilities. These issues are due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user and launch other attacks.
Versions 2.0 and prior are vulnerable; other versions may also be affected.
87. Caloris Planitia Technologies School Management System Cross-Site Scripting Vulnerability
BugTraq ID: 17257
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17257
Summary:
Caloris Planitia Technologies School Management System is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
88. Veritas Backup Exec Multiple Remote Denial of Service Vulnerabilities
BugTraq ID: 17098
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17098
Summary:
Veritas Backup Exec is prone to multiple remote denial-of-service vulnerabilities.
These issues result in memory violations and memory exhaustion and lead to denial-of-service conditions in the affected applications. A restart is required to regain normal functionality in most cases.
Various versions of Backup Exec for Windows, Linux, and NetWare are vulnerable. NetBackup for NetWare Media Server Option releases are also affected.
89. Pixel Motion Multiple SQL Injection Vulnerabilities
BugTraq ID: 17260
Remote: Yes
Last Updated: 2006-03-28
Relevant URL: http://www.securityfocus.com/bid/17260
Summary:
Pixel Motion is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
90. Meeting Reserve SearchResult.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17256
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17256
Summary:
Meeting Reserve is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
91. Online Quiz System Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17255
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17255
Summary:
Online Quiz System is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
92. SweetSuite.NET Content Management System Search.ASPX Cross-Site Scripting Vulnerability
BugTraq ID: 17254
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17254
Summary:
SweetSuite.NET Content Management System is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
93. Microsoft Office XP Array Index Denial of Service Vulnerability
BugTraq ID: 17252
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17252
Summary:
Microsoft Office is prone to a denial-of-service condition when handling malformed array indices. When an Office application such as Excel, Word, or PowerPoint tries to open a file containing a malformed array index, an exception will be thrown, causing the application to fail.
Office XP is vulnerable to this issue; other versions may also be affected.
94. G-Book HTML Injection Vulnerability
BugTraq ID: 17253
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17253
Summary:
G-Book is prone to an HTML-injection vulnerability. This issue is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
95. PHPAdsNew and PHPPGAds Multiple Input Validation Vulnerabilities
BugTraq ID: 17251
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17251
Summary:
phpAdsNew and phpPgAds are prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of a victim user in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, and to launch other attacks.
96. CSDoom 2005 Multiple Buffer Overflow and Format String Vulnerabilities
BugTraq ID: 17248
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17248
Summary:
csDoom 2005 is susceptible to multiple buffer-overflow and format-string vulnerabilities.
The buffer-overflow issues are due to the application's failure to properly bounds-check user-supplied input data before copying it to an insufficiently sized memory buffer. The format-string vulnerabilities are due to the application's failure to properly sanitize user-supplied input before using it in a formatted-printing function.
These issues may allow attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the targeted application. Both clients and servers are affected by these issues.
97. Toast Forums Toast.ASP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17249
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17249
Summary:
Toast Forums is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Version 1.6 and prior are vulnerable; other versions may also be affected.
98. Maian Weblog Multiple SQL-Injection Vulnerabilities
BugTraq ID: 17247
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17247
Summary:
Maian Weblog is prone to multiple SQL-injection vulnerabilities. The application fails to properly sanitize user-supplied input before using it in SQL queries.
This will allow an attacker to inject arbitrary SQL logic into the vulnerable parameters and scripts. As a result, the attacker may be able to access or modify sensitive information, compromise the application, or even compromise the underlying database. Other attacks are possible.
99. Microsoft .NET Framework SDK MSIL Tools Buffer Overflow Vulnerabilities
BugTraq ID: 17243
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17243
Summary:
Microsoft .NET Framework SDK contains tools for assembling and disassembling MSIL files. These tools are prone to buffer-overflow vulnerabilities that attackers could exploit to cause a denial of service or potentially execute arbitrary code.
These issues were reported to affect the .NET Framework SDK version 1.1 SP1; earlier versions may also be affected. Version 2.0 may also be affected, but code execution does not seem possible.
100. LibVC VCard Processing Buffer Overflow Vulnerability
BugTraq ID: 17237
Remote: Yes
Last Updated: 2006-03-27
Relevant URL: http://www.securityfocus.com/bid/17237
Summary:
LibVC is prone to a buffer-overflow vulnerability. This issue is due to a failure in the library to perform proper bounds checks on user-supplied data before using it in a finite-sized buffer.
The issue occurs when the application handles excessive data supplied with a vcard file.
An attacker can exploit this issue to crash the affected library, effectively denying service. Arbitrary code execution is also possible, which may facilitate a compromise of the underlying system.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Patches released for zero-day IE threat
By: Robert Lemos
UPDATE: As hundreds of malicious Web sites attempt to exploit the most critical of two Internet Explorer flaws disclosed last week, two third-party firms release fixes to head off the threat.
http://www.securityfocus.com/news/11384
2. Check Point calls off Sourcefire buy
By: Robert Lemos
Citing an ongoing investigation into the deal by the U.S. Treasury Department, the companies decide to call it quits.
http://www.securityfocus.com/news/11382
3. Debit-card fraud underscores legal loopholes
By: Robert Lemos
UPDATE: Three major data leaks in the last six months are likely responsible for a recent spate of debit-card fraud, but in two cases, no one has come forward to take responsibility. Under current state laws, such silence may be legal.
http://www.securityfocus.com/news/11381
4. Virus names likely a lost cause
By: Robert Lemos
The Common Malware Enumeration Project clears up confusion for responders, but racing to name the latest virus in the media will continue to be the norm.
http://www.securityfocus.com/news/11380
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Consultant, Reading
http://www.securityfocus.com/archive/77/429173
2. [SJ-JOB] Application Security Architect, London
http://www.securityfocus.com/archive/77/429171
3. [SJ-JOB] Manager, Information Security, London
http://www.securityfocus.com/archive/77/429172
4. [SJ-JOB] Security Engineer, Sydney
http://www.securityfocus.com/archive/77/429175
5. [SJ-JOB] Security Engineer, Zurich
http://www.securityfocus.com/archive/77/429170
6. [SJ-JOB] Forensics Engineer, Falls Church
http://www.securityfocus.com/archive/77/429163
7. [SJ-JOB] Information Assurance Engineer, Falls Church
http://www.securityfocus.com/archive/77/429178
8. [SJ-JOB] Certification & Accreditation Engineer, Arlington (Crystal City)
http://www.securityfocus.com/archive/77/429156
9. [SJ-JOB] Sales Engineer, North Central USA
http://www.securityfocus.com/archive/77/429148
10. [SJ-JOB] Security Consultant, london
http://www.securityfocus.com/archive/77/429135
11. [SJ-JOB] Sr. Security Analyst, Pune
http://www.securityfocus.com/archive/77/429116
12. [SJ-JOB] Management, Melville
http://www.securityfocus.com/archive/77/429136
13. [SJ-JOB] Sales Representative, Western USA
http://www.securityfocus.com/archive/77/429100
14. [SJ-JOB] Sales Representative, North Central USA
http://www.securityfocus.com/archive/77/429102
15. [SJ-JOB] Security Consultant, All
http://www.securityfocus.com/archive/77/429177
16. [SJ-JOB] Security System Administrator, Washington D.C.
http://www.securityfocus.com/archive/77/429137
17. [SJ-JOB] Security Architect, Detroit
http://www.securityfocus.com/archive/77/429166
18. [SJ-JOB] Sr. Security Engineer, Munich
http://www.securityfocus.com/archive/77/429080
19. [SJ-JOB] Developer, Columbia
http://www.securityfocus.com/archive/77/429081
20. [SJ-JOB] Customer Support, Columbia
http://www.securityfocus.com/archive/77/429082
21. [SJ-JOB] Security Engineer, New York City
http://www.securityfocus.com/archive/77/429078
22. [SJ-JOB] Security Engineer, Washington D.C.
http://www.securityfocus.com/archive/77/429079
23. [SJ-JOB] Security Consultant, Atlanta
http://www.securityfocus.com/archive/77/428962
24. [SJ-JOB] VP, Information Security, Columbus
http://www.securityfocus.com/archive/77/428963
25. [SJ-JOB] CSO, Moscow
http://www.securityfocus.com/archive/77/428960
26. [SJ-JOB] Security Consultant, New York
http://www.securityfocus.com/archive/77/428954
27. [SJ-JOB] Security Architect, New York
http://www.securityfocus.com/archive/77/428951
28. [SJ-JOB] Security Consultant, San Francisco & LA
http://www.securityfocus.com/archive/77/428952
29. [SJ-JOB] Security Architect, San Francisco or Los Angeles
http://www.securityfocus.com/archive/77/428953
30. [SJ-JOB] Customer Service, Schaumburg
http://www.securityfocus.com/archive/77/428950
31. [SJ-JOB] Information Assurance Analyst, Battle Creek
http://www.securityfocus.com/archive/77/428789
32. [SJ-JOB] Sr. Security Engineer, NW London
http://www.securityfocus.com/archive/77/428785
33. [SJ-JOB] Chief Security Strategist, Schaumburg
http://www.securityfocus.com/archive/77/428786
34. [SJ-JOB] Security Consultant, Raleigh Durham
http://www.securityfocus.com/archive/77/428787
35. [SJ-JOB] Security Architect, Santa Barbara
http://www.securityfocus.com/archive/77/428788
36. [SJ-JOB] Manager, Information Security, Milwaukee
http://www.securityfocus.com/archive/77/428675
37. [SJ-JOB] Security Engineer, Cambridge
http://www.securityfocus.com/archive/77/428676
38. [SJ-JOB] Manager, Information Security, Newport
http://www.securityfocus.com/archive/77/428677
39. [SJ-JOB] VP / Dir / Mgr engineering, McLean
http://www.securityfocus.com/archive/77/428674
40. [SJ-JOB] Sr. Security Analyst, Edison
http://www.securityfocus.com/archive/77/428673
41. [SJ-JOB] Manager, Information Security, Richmond
http://www.securityfocus.com/archive/77/428565
42. [SJ-JOB] Manager, Information Security, Boston
http://www.securityfocus.com/archive/77/428566
43. [SJ-JOB] Sales Representative, Birmingham
http://www.securityfocus.com/archive/77/428567
44. [SJ-JOB] Account Manager, East Coast
http://www.securityfocus.com/archive/77/428563
45. [SJ-JOB] Security Consultant, Birmingham
http://www.securityfocus.com/archive/77/428564
46. [SJ-JOB] Information Assurance Analyst, Vienna
http://www.securityfocus.com/archive/77/428557
47. [SJ-JOB] Information Assurance Analyst, Vienna
http://www.securityfocus.com/archive/77/428558
48. [SJ-JOB] Management, Minneapolis
http://www.securityfocus.com/archive/77/428560
49. [SJ-JOB] Management, New York
http://www.securityfocus.com/archive/77/428559
50. [SJ-JOB] Manager, Information Security, NYC
http://www.securityfocus.com/archive/77/428561
V. INCIDENTS LIST SUMMARY
---------------------------
1. Internet SSH scans thread
http://www.securityfocus.com/archive/75/428632
2. Win2k Machine contacting Root Server???
http://www.securityfocus.com/archive/75/428630
3. A pretty neat Chase Phish
http://www.securityfocus.com/archive/75/427489
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Beating memory address randomization (secuirty) features in Unix/Linux
http://www.securityfocus.com/archive/82/429176
2. PasswordSafe 3.0 weak random number generator allows key recovery attack
http://www.securityfocus.com/archive/82/428738
3. Data Entropy Tool
http://www.securityfocus.com/archive/82/428722
4. foundstone free tool (ms05-039)
http://www.securityfocus.com/archive/82/428709
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Systrace 1.6: Phoenix Release for Linux
http://www.securityfocus.com/archive/91/428672
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
Test your Network Security Free with QualysGuard
Requiring NO software, QualysGuard will safely and accurately test your network and provide you with the necessary fixes to proactively guard your network. Try QualysGuard Risk Free with No Obligation.
http://www.securityfocus.com/cgi-bin/ib.pl