SecurityFocus Newsletter #350
Peter Laborge <[email protected]> Wed, 17 May 2006 11:48:31 -0600
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #350
----------------------------------------
This issue is sponsored by: SPI Dynamics
ALERT: "How a Hacker Launches a SQL Injection Attack!" - SPI Dynamics White Paper
It's as simple as placing additional SQL commands into a Web Form input box giving hackers complete access to all your backend systems! Firewalls and IDS will not stop such attacks because SQL Injections are NOT seen as intruders. Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/sql.asp?Campaign_ID=70130000000COFe
------------------------------------------------------------------
I. FRONT AND CENTER
1. Protection from prying NSA eyes
2. The quest for ring 0
3. Malicious cryptography, part two
II. BUGTRAQ SUMMARY
1. DUware DUbanner Arbitrary File Upload Vulnerability
2. YapBB Find.PHP SQL Injection Vulnerability
3. XLoadImage Compressed Image Command Execution Vulnerability
4. Fetchmail Missing Email Header Remote Denial of Service Vulnerability
5. Fetchmail POP3 Client Buffer Overflow Vulnerability
6. Eric S. Raymond Fetchmail Unspecified Denial of Service Vulnerability
7. GnuPG Incorrect Non-Detached Signature Verification Vulnerability
8. GnuPG Detached Signature Verification Bypass Vulnerability
9. PHPBB Unauthorized HTTP Proxy Vulnerability
10. Ipswitch WhatsUp Professional Multiple Input Validation Vulnerabilities
11. Caucho Resin Viewfile Information Disclosure Vulnerability
12. Caucho Resin Remote Directory Traversal Vulnerability
13. AdderLink IP Unspecified Vulnerability
14. EZUserManager EZusermanager_pwd_forgott.PHP Remote File Include Vulnerability
15. Sphider Search.PHP Multiple Cross-Site Scripting Vulnerabilities
16. IceWarp Universal WebMail PHPSESSID Parameter Cross-Site Scripting Vulnerability
17. PHPRemoteView PRV.PHP Multiple Cross-Site Scripting Vulnerabilities
18. Lighthouse Development Squirrelcart Cart_Content.PHP Remote File Include Vulnerability
19. Pragma FortressSSH SSH_MSG_KEXINIT Remote Buffer Overflow Vulnerability
20. Sugar Suite Open Source Multiple Remote and Local File Include Vulnerabilities
21. Foing Multiple Remote File Include Vulnerabilities
22. PHP Live Helper Chat.PHP Cross-Site Scripting Vulnerability
23. Dovecot Remote Information Disclosure Vulnerability
24. phpCOIN Email Address Information Disclosure Vulnerability
25. Claroline Multiple Remote File Include Vulnerabilities
26. Chirpy! Multiple Unspecified SQL Injection Vulnerabilities
27. Libungif Null Pointer Dereference Denial of Service Vulnerability
28. RealVNC Remote Authentication Bypass Vulnerability
29. Libungif Colormap Handling Memory Corruption Vulnerability
30. Jax Guestbook Page Parameter Cross-Site Scripting Vulnerability
31. AZBoard List.ASP SQL Injection Vulnerability
32. Multiple Vendor SSH Server Remote Buffer Overflow Vulnerability
33. DeluxeBB SQL Injection Vulnerability
34. Confixx Index.PHP Cross-Site Scripting Vulnerability
35. Outgun Multiple Remote Buffer Overflow and Denial of Service Vulnerabilities
36. Graphviz Insecure Temporary File Creation Vulnerability
37. Raydium Multiple Remote Buffer Overflow and Denial Of Service Vulnerabilities
38. Microsoft Windows Impersonation Privilege Escalation Weakness
39. PHPLDAPAdmin Multiple Input Validation Vulnerabilities
40. NewsPortal Remote PHP Script Code Injection Vulnerability
41. MonoChat HTML Injection Vulnerability
42. Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.99.0
43. Sun Java Applet Font.createFont Remote Denial Of Service Vulnerability
44. GNUnet Empty UDP Datagram Remote Denial of Service Vulnerability
45. TZipBuilder ZIP File Buffer Overflow Vulnerability
46. PHPMyAgenda Agenda.PHP3 Remote File Include Vulnerability
47. Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability
48. PHP MB_Send_Mail TO Argument Header Injection Vulnerability
49. PHP Apache 2 Virtual() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
50. PHP cURL and GD Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
51. PHP File Upload GLOBAL Variable Overwrite Vulnerability
52. PHP Parse_Str Register_Globals Activation Weakness
53. PHP PHPInfo Cross-Site Scripting Vulnerability
54. PHP Group Exif Module Infinite Recursion Denial Of Service Vulnerability
55. PHP Apache 2 Local Denial of Service Vulnerability
56. Open Wiki OW.ASP Cross-Site Scripting Vulnerability
57. BoastMachine Admin.PHP Cross-Site Scripting Vulnerability
58. LiveData ICCP Server Remote Heap Overflow Vulnerability
59. PHP-Fusion Srch_Where Parameter SQL Injection Vulnerability
60. Nagios Remote Negative Content-Length Buffer Overflow Vulnerability
61. BEA WebLogic Multiple Vulnerabilities
62. BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities
63. Quagga BGPD Local Denial Of Service Vulnerability
64. BEA WebLogic Multiple Vulnerabilities
65. BEA WebLogic Server Remote Filesystem Access Vulnerability
66. MySQL Query Logging Bypass Vulnerability
67. Quagga Information Disclosure and Route Injection Vulnerabilities
68. Novell NetWare Distributed Print Services Integer Overflow Vulnerability
69. MERCUR Messaging 2005 IMAP Remote Buffer Overflow Vulnerability
70. phpMyAdmin Index.PHP Multiple Cross-Site Scripting Vulnerabilities
71. PAJAX Multiple Arbitrary PHP Code Execution Vulnerabilities
72. PHPNuke Search Module SQL Injection Vulnerability
73. Php Blue Dragon CMS VSDragonRootPath Parameter Remote File Include Vulnerability
74. Simple PHP Blog Remote Arbitrary File Upload Vulnerability
75. Apple Mac OS X Security Update 2006-003 Multiple Vulnerabilities
76. Multiple Vendor SSH2 Implementation Incorrect Field Length Vulnerabilities
77. Apple Mac OS X Multiple Security Vulnerabilities
78. RadScripts RadLance Popup.PHP Local File Include Vulnerability
79. MySQL Remote Information Disclosure and Buffer Overflow Vulnerabilities
80. PHPODP ODP.PHP Cross-Site Scripting Vulnerability
81. SAP Business Connector Input Validation Vulnerability
82. PSY Auction Multiple Input Validation Vulnerabilities
83. SAP Business Connector Remote Arbitrary File Access And Deletion Vulnerability
84. FileZilla Client Unspecified Remote Buffer Overflow Vulnerability
85. Pixaria PopPhoto CFG[popphoto_base_path] Parameter Remote File Include Vulnerability
86. WebCalendar Username Enumeration Vulnerability
87. Genecys Remote Buffer Overflow and Denial Of Service Vulnerabilities
88. Gphotos Multiple Input Validation Vulnerabilities
89. Fetchmail's FetchmailConf Utility Local Information Disclosure Vulnerability
90. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
91. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
92. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
93. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
94. XPDF DoImage Remote Buffer Overflow Vulnerability
95. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
96. Xpdf PDFTOPS Multiple Integer Overflow Vulnerabilities
97. Emacs Movemail POP3 Remote Format String Vulnerability
98. NCPFS Multiple Remote Vulnerabilities
99. NCPFS Local Buffer Overflow Vulnerability
100. XLoadImage Multiple Remote Buffer Overflow Vulnerabilities
III. SECURITYFOCUS NEWS
1. Diebold voting systems critically flawed
2. Bot software looks to improve peerage
3. Breach case could curtail Web flaw finders
4. E-mail authentication gaining steam
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Security Architect, Henderson
2. [SJ-JOB] Instructor, Atlanta
3. [SJ-JOB] Security Consultant, Tampa
4. [SJ-JOB] Security Consultant, Ft. Lauderdale
5. [SJ-JOB] Auditor, London
6. [SJ-JOB] Information Assurance Engineer, McLean
7. [SJ-JOB] Security Consultant, Charlotte
8. [SJ-JOB] Instructor, Atlanta
9. [SJ-JOB] Security Auditor, Atlanta
10. [SJ-JOB] Threat Analyst, Salt Lake City
11. [SJ-JOB] Security Engineer, Geneva
12. [SJ-JOB] Manager, Information Security, London
13. [SJ-JOB] Jr. Security Analyst, Bridgewater
V. INCIDENTS LIST SUMMARY
1. High volume of Mambo scans
VI. VULN-DEV RESEARCH LIST SUMMARY
1. Digg Security.
2. Cracking Tutorial - LinuxWorld
VII. MICROSOFT FOCUS LIST SUMMARY
1. Front End/Back End communication
2. RDP to XP clients
3. Restricting Remote Registry Access
4. Autorun in screensaver
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
1. Linux's security
2. Version 0.8 of OSSEC HIDS is now available (for Unix and Windows)
3. SF new column announcement: The quest for ring 0 (fwd)
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1. Protection from prying NSA eyes
By Mark Rasch
From the U.S. Fourth Amendment, the Stored Communications Act and U.S. wiretap laws to the Pen-register statute, Mark Rasch looks at legal protections available to the telecommunication companies and individual Americans in the wake of the NSA's massive spying program.
http://www.securityfocus.com/columnists/403
2. The quest for ring 0
By Federico Biancuzzi
Federico Biancuzzi interviews French researcher Loïc Duflot to learn more about the System Management Mode attack, how to mitigate it, what hardware is vulnerable, and why we should be concerned with recent X Server bugs.
http://www.securityfocus.com/columnists/402
3. Malicious cryptography, part two
By Frederic Raynal
This two-part article series looks at how cryptography is a double-edged sword: it is used to make us safer, but it is also being used for malicious purposes within sophisticated viruses. Part two continues the discussion of armored viruses and then looks at a Bradley worm - a worm that uses cryptography in such a way that it cannot be analyzed. Then it is shown how Skype can be used for malicious purposes, with a crypto-virus that is very difficult to detect.
http://www.securityfocus.com/infocus/1866
II. BUGTRAQ SUMMARY
--------------------
1. DUware DUbanner Arbitrary File Upload Vulnerability
BugTraq ID: 17993
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17993
Summary:
DUbanner is prone to an arbitrary file-upload vulnerability.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
This issue affects version 3.1; other versions may also be vulnerable.
2. YapBB Find.PHP SQL Injection Vulnerability
BugTraq ID: 17988
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17988
Summary:
YapBB is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
3. XLoadImage Compressed Image Command Execution Vulnerability
BugTraq ID: 12712
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/12712
Summary:
A remote command-execution vulnerability affects xloadimage. This issue is due to the application's failure to safely parse compressed images.
An attacker may leverage this by distributing a malicious image file designed to execute arbitrary commands with the privileges of an unsuspecting users.
4. Fetchmail Missing Email Header Remote Denial of Service Vulnerability
BugTraq ID: 15987
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/15987
Summary:
Fetchmail is affected by a remote denial-of-service vulnerability. This issue is due to the application's failure to handle unexpected input. This issue occurs only when Fetchmail is configured in 'multidrop' mode.
5. Fetchmail POP3 Client Buffer Overflow Vulnerability
BugTraq ID: 14349
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/14349
Summary:
Fetchmail POP3 client is prone to a buffer-overflow vulnerability. This issue presents itself because the application fails to perform boundary checks before copying user-supplied data into sensitive process buffers. This includes POP variants such as APOP and others.
A successful attack can result in overflowing a finite-sized buffer and can ultimately lead to arbitrary code execution in the context of the Fetchmail process. This may allow the attacker to gain elevated privileges.
6. Eric S. Raymond Fetchmail Unspecified Denial of Service Vulnerability
BugTraq ID: 8843
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/8843
Summary:
Fetchmail 6.2.4 is reported prone to a denial-of-service issue that may allow an attacker to crash the software by sending a specially crafted email message. Exact details of this issue are not currently known, but attackers may be able to cause a denial-of-service condition or execute arbitrary code in the vulnerable software.
This vulnerability may be related to known issues, but Symantec has not confirmed this. This BID and any other applicable BIDs will be updated as further information is available.
Fetchmail version 6.2.4 has been reported prone to this issue, but other versions may be vulnerable as well.
7. GnuPG Incorrect Non-Detached Signature Verification Vulnerability
BugTraq ID: 17058
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17058
Summary:
GnuPG is prone to a vulnerability involving incorrect verification of non-detached signatures.
A successful attack can allow an attacker to simply take a signed message, inject arbitrary data into it, and bypass verification.
Note that this issue also affects verification of signatures embedded in encrypted messages. Scripts and applications using gpg are affected, as are applications using the GPGME library.
GnuPG versions prior to 1.4.2.2 are vulnerable to this issue.
8. GnuPG Detached Signature Verification Bypass Vulnerability
BugTraq ID: 16663
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/16663
Summary:
GnuPG is affected by a detached signature verification-bypass vulnerability. This issue is due to the application's failure to properly notify scripts that an invalid detached signature was presented and that the verification process has failed.
This issue allows attackers to bypass the signature-verification process used in some automated scripts. Depending on the use of GnuPG, this may result in a false sense of security, the installation of malicious packages, the execution of attacker-supplied code, or other attacks.
9. PHPBB Unauthorized HTTP Proxy Vulnerability
BugTraq ID: 17965
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17965
Summary:
phpBB is prone to a vulnerability that could permit the application to become an unauthorized HTTP proxy.
An attacker can exploit this issue to manipulate phpBB into becoming an HTTP proxy.
10. Ipswitch WhatsUp Professional Multiple Input Validation Vulnerabilities
BugTraq ID: 17964
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17964
Summary:
WhatsUp Professional is prone to multiple input-validation vulnerabilities. The issues include remote file-include, information-disclosure, source-code disclosure, cross-site scripting, and input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploits of these vulnerabilities could allow an attacker to access or modify data, steal cookie-based authentication credentials, perform username-enumeration, access sensitive information, and gain unauthorized access to script source code. Other attacks are also possible.
11. Caucho Resin Viewfile Information Disclosure Vulnerability
BugTraq ID: 18007
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/18007
Summary:
Resin is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve the contents of arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.
12. Caucho Resin Remote Directory Traversal Vulnerability
BugTraq ID: 18005
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/18005
Summary:
Caucho Resin is prone to a remote directory-traversal vulnerability that may allow attackers to gain access to any file on an affected Caucho Resin server.
Attackers may exploit this vulnerability to be able to access potentially sensitive information.
Caucho Resin versions v3.0.17 and v3.0.18 are vulnerable to this issue. Versions prior to v3.0.17 are not vulnerable.
13. AdderLink IP Unspecified Vulnerability
BugTraq ID: 18001
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/18001
Summary:
AdderLink IP is reportedly prone to an unspecified security vulnerability in the VNC functionality. The cause and impact of this issue is currently unknown.
This BID will be updated when more information becomes available.
14. EZUserManager EZusermanager_pwd_forgott.PHP Remote File Include Vulnerability
BugTraq ID: 17998
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17998
Summary:
EZUserManager is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
EZUserManager versions 1.6 and prior versions are affected.
15. Sphider Search.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17997
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17997
Summary:
Sphider is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
16. IceWarp Universal WebMail PHPSESSID Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 17995
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17995
Summary:
IceWarp Universal WebMail is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
17. PHPRemoteView PRV.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17994
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17994
Summary:
PhpRemoteView is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
18. Lighthouse Development Squirrelcart Cart_Content.PHP Remote File Include Vulnerability
BugTraq ID: 17992
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17992
Summary:
Squirrelcart is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Squirrelcart 2.2.0 and prior versions are affected.
19. Pragma FortressSSH SSH_MSG_KEXINIT Remote Buffer Overflow Vulnerability
BugTraq ID: 17991
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17991
Summary:
A remote buffer-overflow vulnerability exits in FortressSSH.
This issue may permit remote code execution in vulnerable servers. A complete compromise leading to SYSTEM level access may be possible.
FortressSSH 4.0.7.20 is reported to be vulnerable. Other versions may be affected as well.
20. Sugar Suite Open Source Multiple Remote and Local File Include Vulnerabilities
BugTraq ID: 17987
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17987
Summary:
Sugar Suite Open Source is prone to multiple remote and local file include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process, as well as disclose sensitive information through the use of directory traversal strings '../' in the context of the webserver process.
This may allow the attacker to disclose sensitive information and compromise the application and the underlying system; other attacks are also possible.
21. Foing Multiple Remote File Include Vulnerabilities
BugTraq ID: 17963
Remote: Yes
Last Updated: 2006-05-15
Relevant URL: http://www.securityfocus.com/bid/17963
Summary:
Foing is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
22. PHP Live Helper Chat.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17960
Remote: Yes
Last Updated: 2006-05-15
Relevant URL: http://www.securityfocus.com/bid/17960
Summary:
PHP Live Helper is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
23. Dovecot Remote Information Disclosure Vulnerability
BugTraq ID: 17961
Remote: Yes
Last Updated: 2006-05-15
Relevant URL: http://www.securityfocus.com/bid/17961
Summary:
Dovecot is prone to an information-disclosure vulnerability that may allow authenticated attackers to gain access to the names of all users with mailboxes on an affected IMAP server.
Dovecot versions 1.0 stable through 1.0 beta8 are vulnerable to this issue.
24. phpCOIN Email Address Information Disclosure Vulnerability
BugTraq ID: 17959
Remote: Yes
Last Updated: 2006-05-15
Relevant URL: http://www.securityfocus.com/bid/17959
Summary:
phpCOIN is prone to an information-disclosure vulnerability. This issue is due to a failure in the application to properly validate user-supplied input.
An attacker can exploit this issue to retrieve the contents of arbitrary messages.
25. Claroline Multiple Remote File Include Vulnerabilities
BugTraq ID: 17873
Remote: Yes
Last Updated: 2006-05-15
Relevant URL: http://www.securityfocus.com/bid/17873
Summary:
Claroline is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
These issues also affect Dokeos version 1.6.4; earlier versions may also be vulnerable.
26. Chirpy! Multiple Unspecified SQL Injection Vulnerabilities
BugTraq ID: 17957
Remote: Yes
Last Updated: 2006-05-15
Relevant URL: http://www.securityfocus.com/bid/17957
Summary:
Chirpy! is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.
Successful exploits could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
27. Libungif Null Pointer Dereference Denial of Service Vulnerability
BugTraq ID: 15304
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/15304
Summary:
The libungif library is prone to a denial-of-service vulnerability. The library fails to handle exceptional conditions.
Successful exploitation of this vulnerability will cause the application using the affected library to crash, effectively denying service to legitimate users.
Version 4.1.3 and prior are considered vulnerable to this issue.
28. RealVNC Remote Authentication Bypass Vulnerability
BugTraq ID: 17978
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17978
Summary:
RealVNC is susceptible to an authentication-bypass vulnerability. This issue is due to a flaw in the authentication process of the affected package.
Exploiting this issue allows attackers to gain unauthenticated, remote access to the VNC servers.
RealVNC version 4.1.1 is vulnerable to this issue; other versions may also be affected.
29. Libungif Colormap Handling Memory Corruption Vulnerability
BugTraq ID: 15299
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/15299
Summary:
The libungif library is prone to a memory-corruption vulnerability.
Reports indicate that due to the library's improper handling of colormaps in GIF files, an attacker can trigger out-of-bounds writes and corrupt memory.
This may lead to a denial-of-service condition.
Version 4.1.3 and prior are considered vulnerable to this issue.
30. Jax Guestbook Page Parameter Cross-Site Scripting Vulnerability
BugTraq ID: 17560
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17560
Summary:
Jax Guestbook is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Version 3.50 is vulnerable to this issue; other versions may also be affected.
31. AZBoard List.ASP SQL Injection Vulnerability
BugTraq ID: 17990
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17990
Summary:
The azboard application is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied data before using it in an SQL query.
Successful exploits could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
32. Multiple Vendor SSH Server Remote Buffer Overflow Vulnerability
BugTraq ID: 17958
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17958
Summary:
Multiple SSH server implementations are prone to a remote buffer-overflow vulnerability. The applications fail to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
A successful attack may facilitate arbitrary code execution. Exploiting this vulnerability may allow an attacker to gain administrative access on targeted computers.
33. DeluxeBB SQL Injection Vulnerability
BugTraq ID: 17989
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17989
Summary:
DeluxeBB is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied cookie data before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
DeluxeBB version 1.06 is vulnerable to this issue; other versions may also be affected.
34. Confixx Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17984
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17984
Summary:
Confixx is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
35. Outgun Multiple Remote Buffer Overflow and Denial of Service Vulnerabilities
BugTraq ID: 17985
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17985
Summary:
Outgun is prone to multiple remote vulnerabilities.
Multiple buffer-overflow and denial-of-service vulnerabilities affect Outgun. These issues potentially allow remote attackers to execute arbitrary machine code and to crash the affected application.
36. Graphviz Insecure Temporary File Creation Vulnerability
BugTraq ID: 15050
Remote: No
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/15050
Summary:
Graphviz creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
Graphviz 2.2.1 is reportedly affected, but other versions may be vulnerable as well.
37. Raydium Multiple Remote Buffer Overflow and Denial Of Service Vulnerabilities
BugTraq ID: 17986
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17986
Summary:
Raydium is susceptible to multiple remote vulnerabilities:
- Multiple buffer-overflow vulnerabilities in both client and server instances.
- A format-string vulnerability in both client and server instances.
- A NULL-pointer dereference denial-of-service vulnerability in both client and server instances.
- A buffer-overflow vulnerability in client instances.
These vulnerabilities allow remote attackers to execute arbitrary machine code in the context of affected client and server instances of games that use the affected game engine software. Attackers may also crash vulnerable instances, denying service to legitimate users.
38. Microsoft Windows Impersonation Privilege Escalation Weakness
BugTraq ID: 18008
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/18008
Summary:
Microsoft Windows is susceptible to a weakness that may allow attackers to gain elevated privileges. This issue is due to the ability of services to impersonate clients after they have authenticated.
Microsoft encourages the use of the 'Local Service' and 'Network Service' accounts to mitigate the consequences of exploiting vulnerabilities in services. Attackers exploiting latent vulnerabilities in services running with these low-privilege accounts may take advantage of this weakness to gain elevated privileges.
Under certain circumstances, this issue may aid attackers that can exploit latent vulnerabilities in low-privileged services in gaining elevated privileges, allowing them to fully compromise targeted computers.
This issue is similar to the one documented in BID 8276 (Microsoft SQL Server / MSDE Named Pipes Privilege Escalation Vulnerability)LoadDocument.aspx?guid=4E4FB9BA810E48B186E99FAFC7E3462C
39. PHPLDAPAdmin Multiple Input Validation Vulnerabilities
BugTraq ID: 17643
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17643
Summary:
PHPLDAPAdmin is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of a victim user in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user, and to launch other attacks.
40. NewsPortal Remote PHP Script Code Injection Vulnerability
BugTraq ID: 18000
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/18000
Summary:
NewsPortal is prone to a remote PHP code-injection vulnerability.
An attacker can exploit this issue to facilitate a compromise of the application and the underlying system; other attacks are also possible.
41. MonoChat HTML Injection Vulnerability
BugTraq ID: 17983
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17983
Summary:
MonoChat is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
MonoChat 1.0 is reported to be affected. Other versions may be vulnerable as well.
42. Ethereal Multiple Protocol Dissector Vulnerabilities In Versions Prior To 0.99.0
BugTraq ID: 17682
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17682
Summary:
Several vulnerabilities in Ethereal have been disclosed by the vendor. The reported issues are in various protocol dissectors. These issues include:
- Buffer-overflow vulnerabilities
- Denial-of-service vulnerabilities
- Infinite loop denial-of-service vulnerabilities
- Unspecified denial-of-service vulnerabilities
- Off-by-one overflow vulnerabilities
These issues could allow remote attackers to execute arbitrary machine code in the context of the vulnerable application. Attackers could also crash the affected application.
Various vulnerabilities affect different versions of Ethereal, from 0.8.5 through to 0.10.14.
43. Sun Java Applet Font.createFont Remote Denial Of Service Vulnerability
BugTraq ID: 17981
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17981
Summary:
Sun Java is prone to a remote denial-of-service vulnerability. This issue is due to a failure in the application to properly handle certain Java applets.
Successfully exploiting this issue will cause the application to create a temporary file that will grow in an unbounded fashion, consuming all available disk space. This will likely result in a denial-of-service condition.
Sun Java JDK versions 1.4.2_11 and 1.5.0_06 are vulnerable to this issue; other versions may also be affected.
44. GNUnet Empty UDP Datagram Remote Denial of Service Vulnerability
BugTraq ID: 17980
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17980
Summary:
A denial-of-service vulnerability affects GNUnet. This issue is due to the application's failure to properly handle malformed UDP datagrams.
The vulnerability allows remote attackers from external networks to crash the application, denying further service to legitimate users.
GNUnet versions 0.7.0d and SVN revision 2780 are affected by this issue; other versions may also be affected.
45. TZipBuilder ZIP File Buffer Overflow Vulnerability
BugTraq ID: 17880
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17880
Summary:
TZipBuilder is susceptible to a buffer-overflow vulnerability. The application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
This issue allows attackers to execute arbitrary machine code in the context of users running the affected application.
Version 1.79.03.01 of TZipBuilder is vulnerable to this issue; prior versions may also be affected.
46. PHPMyAgenda Agenda.PHP3 Remote File Include Vulnerability
BugTraq ID: 17670
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/17670
Summary:
phpMyAgenda is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
phpMyAgenda 3.0 Final and prior versions are affected.
47. Multiple Vendor UNACEV2 Archive File Name Buffer Overflow Vulnerability
BugTraq ID: 14759
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/14759
Summary:
Multiple products are prone to a buffer overflow when handling ACE archives that contain files with overly long names.
This may be exploited to execute arbitrary code in the context of the user who is running the application. The vulnerability is considered remotely exploitable in nature because malicious ACE archives will likely originate from an external, untrusted source.
48. PHP MB_Send_Mail TO Argument Header Injection Vulnerability
BugTraq ID: 15571
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/15571
Summary:
PHP is susceptible to a header-injection vulnerability when sending email. This issue is due to the application's failure to properly sanitize user-supplied input.
This issue allows remote attackers to add arbitrary headers to generated email messages. The results of this vary depending on the meaning of the injected headers. This may allow attackers to use vulnerable web applications as an anonymous email proxy.
49. PHP Apache 2 Virtual() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
BugTraq ID: 15413
Remote: No
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/15413
Summary:
PHP on Apache 2 is prone to a restriction-bypass vulnerability when calling 'virtual()'. Successful exploitation could lead to disclosure of sensitive information.
This issue is reported to affect PHP versions 4.4.0 and 5.0.5; other versions may also be vulnerable.
50. PHP cURL and GD Multiple Safe_Mode and Open_Basedir Restriction Bypass Vulnerabilities
BugTraq ID: 15411
Remote: No
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/15411
Summary:
PHP cURL and GD are prone to multiple safe_mode and open_basedir restriction-bypass vulnerabilities. Successful exploitation could allow an attacker to access sensitive information.
This issue is reported to affect PHP versions 4.4.0 and 5.0.5; other versions may also be vulnerable.
51. PHP File Upload GLOBAL Variable Overwrite Vulnerability
BugTraq ID: 15250
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/15250
Summary:
PHP is susceptible to a vulnerability that allows attackers to overwrite the GLOBAL variable via HTTP POST requests.
By exploiting this issue, remote attackers may be able to overwrite the GLOBAL variable. This may allow attackers to further exploit latent vulnerabilities in PHP scripts.
52. PHP Parse_Str Register_Globals Activation Weakness
BugTraq ID: 15249
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/15249
Summary:
PHP is susceptible to a weakness that allows attackers to reenable the 'register_globals' directive. This issue is due to the application's failure to handle a memory-limit exception.
The 'register_globals' directive will remain enabled for the rest of the lifetime of the affected process. If PHP is being run as an Apache module, then the process handling the malicious request will have 'register_globals' enabled for the duration of the process's life. If PHP is being run as a CGI process, this issue is not likely exploitable.
By exploiting this issue, remote attackers may be able to enable 'register_globals'. This may allow attackers to further exploit latent vulnerabilities in PHP scripts.
53. PHP PHPInfo Cross-Site Scripting Vulnerability
BugTraq ID: 15248
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/15248
Summary:
PHP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
54. PHP Group Exif Module Infinite Recursion Denial Of Service Vulnerability
BugTraq ID: 15358
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/15358
Summary:
PHP is prone to a denial-of-service vulnerability.
This issue occurs when parsing EXIF image data in corrupt JPEG files.
An attacker can exploit this vulnerability to crash the system, effectively denying service to legitimate users.
55. PHP Apache 2 Local Denial of Service Vulnerability
BugTraq ID: 15177
Remote: No
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/15177
Summary:
PHP is prone to a local denial-of-service vulnerability when it is used as an Apache 2 module.
Reports indicate that due to a bug in the apache2handler SAPI (of the 'sapi_apache2.c' file), this issue triggers a segmentation fault and leads to a crash in the server.
This issue affects PHP versions prior to 5.1.0 final and 4.4.1 final.
56. Open Wiki OW.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 18013
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/18013
Summary:
Open Wiki is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Open Wiki 0.78 is reported to be vulnerable. Other versions may be affected as well.
57. BoastMachine Admin.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18012
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/18012
Summary:
BoastMachine is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
BoastMachine 3.1 is reported to be vulnerable. Other versions may be affected as well.
58. LiveData ICCP Server Remote Heap Overflow Vulnerability
BugTraq ID: 18010
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/18010
Summary:
LiveData ICCP Server is susceptible to a remote heap-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue allows remote attackers to crash a vulnerable server. Reports indicate that this issue does not allow attackers to execute arbitrary code, however, this has not been confirmed.
LiveData ICCP Server versions prior to 5.00.035 are vulnerable.
59. PHP-Fusion Srch_Where Parameter SQL Injection Vulnerability
BugTraq ID: 18009
Remote: Yes
Last Updated: 2006-05-17
Relevant URL: http://www.securityfocus.com/bid/18009
Summary:
PHP-Fusion is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
60. Nagios Remote Negative Content-Length Buffer Overflow Vulnerability
BugTraq ID: 17879
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17879
Summary:
Nagios is susceptible to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of hosting webservers.
Nagios versions prior to 2.3 in the 2.x series, and versions prior to 1.4 in the 1.x series are vulnerable to this issue.
61. BEA WebLogic Multiple Vulnerabilities
BugTraq ID: 17982
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17982
Summary:
BEA has released 11 advisories identifying various vulnerabilities affecting BEA WebLogic Server, WebLogic Platform, and WebLogic Express. These issues present remote and local threats and may facilitate attacks affecting the integrity, confidentiality, and availability of vulnerable computers.
62. BEA WebLogic Server and WebLogic Express Multiple Vulnerabilities
BugTraq ID: 15052
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/15052
Summary:
BEA has released 24 advisories identifying various vulnerabilities affecting BEA WebLogic Server and WebLogic Express. These issues present remote and local threats and may facilitate attacks affecting the integrity, confidentiality, and availability of vulnerable computers.
We conjecture that some of these issues may allow an attacker to completely compromise a vulnerable computer.
These issues are currently being analyzed. This BID will be updated and individual BIDs will be released when further analysis is complete.
63. Quagga BGPD Local Denial Of Service Vulnerability
BugTraq ID: 17979
Remote: No
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17979
Summary:
Quagga is prone to a local denial-of-service vulnerability.
An attacker can exploit this issue by using commands that cause the consumption of a large amount of CPU resources.
An attacker may cause the application to crash, thus denying service to legitimate users.
Version 0.98.3 is vulnerable; other versions may also be affected.
64. BEA WebLogic Multiple Vulnerabilities
BugTraq ID: 16358
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/16358
Summary:
BEA has released 10 advisories identifying various vulnerabilities affecting BEA WebLogic Server, WebLogic Portal, and WebLogic Express. These issues present remote and local threats and may facilitate attacks affecting the integrity, confidentiality, and availability of vulnerable computers.
65. BEA WebLogic Server Remote Filesystem Access Vulnerability
BugTraq ID: 17166
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17166
Summary:
BEA WebLogic Server is prone to a vulnerability that could allow remote access to the local filesystem.
WebLogic Server 6.1 is vulnerable.
66. MySQL Query Logging Bypass Vulnerability
BugTraq ID: 16850
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/16850
Summary:
MySQL is susceptible to a query-logging-bypass vulnerability. This issue is due to a discrepancy between the handling of NULL bytes in the 'mysql_real_query()' function and in the query-logging functionality.
This issue allows attackers to bypass the query-logging functionality of the database so they can cause malicious SQL queries to be improperly logged. This may help them hide the traces of their malicious activity from administrators.
This issue affects MySQL version 5.0.18; other versions may also be affected.
67. Quagga Information Disclosure and Route Injection Vulnerabilities
BugTraq ID: 17808
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17808
Summary:
Quagga is susceptible to remote information-disclosure and route-injection vulnerabilities. The application fails to properly ensure that required authentication and protocol configuration options are enforced.
These issues allow remote attackers to gain access to potentially sensitive network-routing configuration information and to inject arbitrary routes into the RIP routing table. This may aid malicious users in further attacks against targeted networks.
Quagga versions 0.98.5 and 0.99.3 are vulnerable to these issues; other versions may also be affected.
68. Novell NetWare Distributed Print Services Integer Overflow Vulnerability
BugTraq ID: 17922
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17922
Summary:
Novell NetWare Distributed Print Services is prone to an integer-overflow vulnerability.
An attacker could exploit this vulnerability to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will likely cause denial-of-service conditions. Since the vulnerable application executes with administrative privileges, this may facilitate the complete remote compromise of affected computers.
69. MERCUR Messaging 2005 IMAP Remote Buffer Overflow Vulnerability
BugTraq ID: 17138
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17138
Summary:
MERCUR Messaging 2005 is prone to a remote buffer-overflow vulnerability.
The vulnerability presents itself when the server handles specially crafted IMAP commands.
This may result in memory corruption leading to a denial-of-service condition or arbitrary code execution.
MERCUR Messaging 2005 version 5.0 SP3 is reported to be vulnerable. Other versions may be affected as well.
70. phpMyAdmin Index.PHP Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17973
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17973
Summary:
phpMyAdmin is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to 2.8.0.4 are vulnerable; other versions may also be affected.
71. PAJAX Multiple Arbitrary PHP Code Execution Vulnerabilities
BugTraq ID: 17519
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17519
Summary:
PAJAX is reported prone to multiple remote code-execution vulnerabilities. These issues may allow an attacker to gain unauthorized access to a vulnerable computer by executing arbitrary PHP code.
PAJAX versions 0.5.1 is affected by this issue. Prior versions may be affected as well.
72. PHPNuke Search Module SQL Injection Vulnerability
BugTraq ID: 15421
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/15421
Summary:
PHPNuke is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
73. Php Blue Dragon CMS VSDragonRootPath Parameter Remote File Include Vulnerability
BugTraq ID: 17977
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17977
Summary:
Php Blue Dragon CMS is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
This issue affects Php Blue Dragon CMS 2.8.0. Other versions may be affected as well.
74. Simple PHP Blog Remote Arbitrary File Upload Vulnerability
BugTraq ID: 14667
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/14667
Summary:
Simple PHP Blog is prone to a remote arbitrary file-upload vulnerability.
This issue may allow remote attackers to upload arbitrary files, including malicious scripts, and possibly to execute a script on the affected server.
Simple PHP Blog 0.4.0 is affected by this issue. Other versions may be vulnerable as well.
75. Apple Mac OS X Security Update 2006-003 Multiple Vulnerabilities
BugTraq ID: 17951
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17951
Summary:
Apple Mac OS X is reported prone to multiple security vulnerabilities.
These issue affect Mac OS X in the following applications or modules:
- AppKit
- ImageIO
- BOM
- CFNetwork
- ClamAV
- CoreFoundation
- CoreGraphics
- Finder
- FTPServer
- Flash Player
- ImageIO
- Keychain
- LaunchServices
- libcurl
- Mail
- MySQL Manager
- Preview
- QuickDraw
- QuickTime Streaming Server
- Ruby
- Safari
A remote attacker may exploit these issues to execute arbitrary code, trigger a denial-of-service condition, gain access to potentially sensitive information, or overwrite files. Other attacks may also be possible.
Apple Mac OS X 10.4.6 and prior are reported vulnerable to these issues.
76. Multiple Vendor SSH2 Implementation Incorrect Field Length Vulnerabilities
BugTraq ID: 6405
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/6405
Summary:
A vulnerability with incorrect lengths of fields in SSH packets has been reported for multiple products that use SSH2 for secure communications.
The vulnerability has been reported to affect initialization, key exchange, and negotiation phases of SSH communications. An attacker may exploit the vulnerability to perform denial-of-service attacks against vulnerable systems and possibly to execute malicious, attacker-supplied code.
Further details about the vulnerability are currently unknown. This BID will be updated as more information becomes available. This vulnerability was originally described in Bugtraq ID 6397.
77. Apple Mac OS X Multiple Security Vulnerabilities
BugTraq ID: 17634
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17634
Summary:
Apple Mac OS X is reported prone to multiple security vulnerabilities.
These issue affect Mac OS X and various applications including Safari, Preview, Finder, QuickTime, and BOMArchiveHelper. A remote attacker may exploit these issues to execute arbitrary code and/or trigger a denial-of-service condition.
Apple Mac OS X 10.4.6 and prior are reported vulnerable to these issues.
78. RadScripts RadLance Popup.PHP Local File Include Vulnerability
BugTraq ID: 17975
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17975
Summary:
RadLance is prone to a local file-include vulnerability. This may allow unauthorized users to view files and to execute local scripts.
RadLance Gold version 7.0 is reportedly affected by this issue; other versions may also be vulnerable.
79. MySQL Remote Information Disclosure and Buffer Overflow Vulnerabilities
BugTraq ID: 17780
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17780
Summary:
MySQL is susceptible to multiple remote vulnerabilities:
- A buffer-overflow vulnerability due to insufficient bounds-checking of user-supplied data before copying it to an insufficiently sized memory buffer. This issue allows remote attackers to execute arbitrary machine code in the context of affected database servers. Failed exploit attempts will likely crash the server, denying further service to legitimate users.
- Two information-disclosure vulnerabilities due to insufficient input-sanitization and bounds-checking of user-supplied data. These issues allow remote users to gain access to potentially sensitive information that may aid them in further attacks.
80. PHPODP ODP.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 17976
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17976
Summary:
phpODP is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
phpODP 1.5h is reported to be vulnerable. Other versions may be affected as well.
81. SAP Business Connector Input Validation Vulnerability
BugTraq ID: 16671
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/16671
Summary:
SAP Business Connector is susceptible to an input-validation vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input.
This issue allows remote attackers to execute phishing-style attacks against targeted SAP Business Connector administrators.
82. PSY Auction Multiple Input Validation Vulnerabilities
BugTraq ID: 17974
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17974
Summary:
PSY Auction is prone to multiple input-validation vulnerabilities. The issues include HTML-injection and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
Successful exploits of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, control how the site is rendered to the user, or exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.
83. SAP Business Connector Remote Arbitrary File Access And Deletion Vulnerability
BugTraq ID: 16668
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/16668
Summary:
SAP Business Connector is prone to a file-access/deletion vulnerability. This issue arises due to an access-validation error.
A successful attack will result in the disclosure of sensitive or privileged information. An attacker may also delete arbitrary files. This often occurs with superuser privileges, since the package is often run with elevated privileges to gain access to TCP ports lower than 1024.
84. FileZilla Client Unspecified Remote Buffer Overflow Vulnerability
BugTraq ID: 17972
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17972
Summary:
FileZilla client is prone to a remote buffer-overflow vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will likely crash the application, denying further service to legitimate users.
FileZilla versions prior to 2.2.23 are vulnerable to this issue.
85. Pixaria PopPhoto CFG[popphoto_base_path] Parameter Remote File Include Vulnerability
BugTraq ID: 17970
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17970
Summary:
Pixaria PopPhoto is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
This issue affects PopPhoto 3.5.4. Other versions may be affected as well.
86. WebCalendar Username Enumeration Vulnerability
BugTraq ID: 17853
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17853
Summary:
WebCalendar is prone to a username-enumeration vulnerability. This issue is due to a design error in the application when verifying user-supplied input.
Attackers may exploit this vulnerability to discern valid usernames. This may aid them in brute-force password cracking or other attacks.
87. Genecys Remote Buffer Overflow and Denial Of Service Vulnerabilities
BugTraq ID: 17969
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17969
Summary:
Genecys is susceptible to multiple remote vulnerabilities.
A buffer-overflow vulnerability and denial-of-service vulnerability affect Genecys and potentially allow remote attackers to execute arbitrary machine code and to crash the affected application.
Version 0.2 and prior, as well as the CVS version, are vulnerable to these issues; other versions may also be affected.
88. Gphotos Multiple Input Validation Vulnerabilities
BugTraq ID: 17967
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/17967
Summary:
Gphotos is prone to multiple input-validation vulnerabilities. The issues include information-disclosure and cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, or steal cookie-based authentication credentials. Other attacks are also possible.
89. Fetchmail's FetchmailConf Utility Local Information Disclosure Vulnerability
BugTraq ID: 15179
Remote: No
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/15179
Summary:
Fetchmail is susceptible to an information-disclosure vulnerability. This issue is due to a race condition in the 'fetchmailconf' configuration utility.
This issue allows local attackers to gain access to potentially sensitive information, including email authentication credentials, aiding them in further attacks.
Versions of Fetchmail prior to 6.2.9-rc6 include a vulnerable version of 'fetchmailconf'. Versions of 'fetchmailconf' prior to 1.43.2 and 1.49 are vulnerable.
90. XPDF DCTStream Baseline Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15727
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/15727
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. This can result in the attacker gaining unauthorized access to the vulnerable computer.
This issue is reported to present itself in the 'CTStream::readBaselineSOF' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, however, earlier versions may also be affected.
The 'kpdf' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
91. XPDF StreamPredictor Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15725
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/15725
Summary:
The 'xpdf' viewer is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
This issue is reported to present itself in the 'StreamPredictor::StreamPredictor' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.
The 'kpdf ' viewer reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
92. XPDF DCTStream Progressive Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15726
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/15726
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
Reportedly, this issue presents itself in the 'DCTStream::readProgressiveSOF' function residing in the 'xpdf/Stream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely vulnerable as well. Applications using embedded xpdf code may also be vulnerable.
The 'pdftohtml' utility also includes vulnerable versions of xpdf. Version 0.36 of pdftohtml was reported prone to this issue, but earlier versions may also be affected.
Th 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
93. XPDF JPX Stream Reader Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 15721
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/15721
Summary:
The 'xpdf' utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the application fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
Reportedly, this issue presents itself in the 'JPXStream::readCodestream' function residing in the 'xpdf/JPXStream.cc' file.
This issue is reported to affect xpdf 3.01, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may also be vulnerable.
The 'kpdf' utility reportedly incorporates vulnerable xpdf code. Version 0.5 of kpdf is prone to this issue, but other versions may also be affected.
94. XPDF DoImage Remote Buffer Overflow Vulnerability
BugTraq ID: 12070
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/12070
Summary:
The xpdf utility is reported prone to a remote buffer-overflow vulnerability. This issue exists because the applications fails to perform proper boundary checks before copying user-supplied data into process buffers. A remote attacker may execute arbitrary code in the context of a user running the application. As a result, the attacker can gain unauthorized access to the vulnerable computer.
An attacker can exploit this issue by enticing a vulnerable user to open a malformed PDF file. If the application is configured as the default handler for PDF files, this could present a viable web or email attack vector, because when the PDF is clicked from an appropriate client application, xpdf will automatically be invoked.
This issue is reported to affect xpdf 3.00, but earlier versions are likely prone to this vulnerability as well. Applications using embedded xpdf code may be vulnerable to these issues as well.
95. KPdf and KWord Multiple Unspecified Buffer and Integer Overflow Vulnerabilities
BugTraq ID: 16143
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/16143
Summary:
KPDF and KWord are prone to multiple buffer and integer overflows. Successful exploitation could result in arbitrary code execution in the context of the user running the vulnerable application.
Specific details of these issues are not currently available. This record will be updated when more information becomes available.
The following are vulnerable:
- kdegraphics package
- KPDF versions 3.4.3 and earlier
- KOffice
- KWord versions 1.4.2 and earlier
96. Xpdf PDFTOPS Multiple Integer Overflow Vulnerabilities
BugTraq ID: 11501
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/11501
Summary:
The pdftops utility is reported prone to multiple integer-overflow vulnerabilities because it fails to properly ensure that user-supplied input doesn't result in the overflowing of integer values. This may result in data being copied past the end of a memory buffer.
These overflows cause the application to allocate smaller-than-expected memory regions. Subsequent operations are likely to overwrite memory regions past the end of the allocated buffer, allowing attackers to overwrite critical memory control structures. This may allow attackers to control the flow of execution and potentially execute attacker-supplied code in the context of the affected application.
Applications using embedded xpdf code may be vulnerable to these issues as well.
97. Emacs Movemail POP3 Remote Format String Vulnerability
BugTraq ID: 12462
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/12462
Summary:
The movemail utility of Emacs is reported prone to a remote format-string vulnerability. This issue arises because the application fails to sanitize user-supplied data before passing it as the format specifier to a formatted-printing function.
A remote attacker may leverage this issue to write to arbitrary process memory, facilitating code execution. Any code execution would take place with setgid mail privileges.
98. NCPFS Multiple Remote Vulnerabilities
BugTraq ID: 12400
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/12400
Summary:
Multiple remote vulnerabilities affect ncpfs. The utility fails to manage access privileges securely and to validate the length of user-supplied strings before copying them into finite process buffers.
The first issue is a remote buffer-overflow vulnerability. The second issue is an access-validation issue due to the setuid privileges of ncpfs utilities.
An attacker may leverage these issues to execute arbitrary code with the privileges of the affected application and to access arbitrary files with the escalated privileges.
99. NCPFS Local Buffer Overflow Vulnerability
BugTraq ID: 11945
Remote: No
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/11945
Summary:
A local buffer overflow vulnerability affects ncpfs. This issue is due to the application's failure to properly validate the length of user-supplied strings before copying them into static process buffers.
A local attacker may leverage this issue to execute arbitrary code on an affected computer with superuser privileges, facilitating privilege escalation.
100. XLoadImage Multiple Remote Buffer Overflow Vulnerabilities
BugTraq ID: 15051
Remote: Yes
Last Updated: 2006-05-16
Relevant URL: http://www.securityfocus.com/bid/15051
Summary:
The xloadimage utility is affected by multiple remotely exploitable buffer-overflow vulnerabilities.
The problems present themselves when the application processes malformed image titles.
An attacker may exploit these issues to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Diebold voting systems critically flawed
By: Robert Lemos
Concerns raised by a rural county in Utah helped an electronic voting watchdog discover a critical vulnerability in Diebold Election Systems' touchscreen terminal--a flaw that state election officials and security experts warn could pose a risk to elections.
http://www.securityfocus.com/news/11391
2. Bot software looks to improve peerage
By: Robert Lemos
Threatened by investigators' ability to tap into chat-based command-and-control networks, bot masters increasingly look to peer-to-peer communications, encryption and other technologies to hide their tracks.
http://www.securityfocus.com/news/11390
3. Breach case could curtail Web flaw finders
By: Robert Lemos
Security researchers and legal experts voice concern over the prosecution of an information-technology professional for computer intrusion after he allegedly breached a university's online application system while researching a flaw without the school's permission.
http://www.securityfocus.com/news/11389
4. E-mail authentication gaining steam
By: Robert Lemos
A host of software companies, security firms and Internet service providers meet in Chicago to urge corporations and bulk e-mail senders to adopt authentication technologies.
http://www.securityfocus.com/news/11388
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Architect, Henderson
http://www.securityfocus.com/archive/77/434129
2. [SJ-JOB] Instructor, Atlanta
http://www.securityfocus.com/archive/77/434127
3. [SJ-JOB] Security Consultant, Tampa
http://www.securityfocus.com/archive/77/434128
4. [SJ-JOB] Security Consultant, Ft. Lauderdale
http://www.securityfocus.com/archive/77/434131
5. [SJ-JOB] Auditor, London
http://www.securityfocus.com/archive/77/434135
6. [SJ-JOB] Information Assurance Engineer, McLean
http://www.securityfocus.com/archive/77/434137
7. [SJ-JOB] Security Consultant, Charlotte
http://www.securityfocus.com/archive/77/434126
8. [SJ-JOB] Instructor, Atlanta
http://www.securityfocus.com/archive/77/434136
9. [SJ-JOB] Security Auditor, Atlanta
http://www.securityfocus.com/archive/77/433649
10. [SJ-JOB] Threat Analyst, Salt Lake City
http://www.securityfocus.com/archive/77/433650
11. [SJ-JOB] Security Engineer, Geneva
http://www.securityfocus.com/archive/77/433651
12. [SJ-JOB] Manager, Information Security, London
http://www.securityfocus.com/archive/77/433647
13. [SJ-JOB] Jr. Security Analyst, Bridgewater
http://www.securityfocus.com/archive/77/433648
V. INCIDENTS LIST SUMMARY
---------------------------
1. High volume of Mambo scans
http://www.securityfocus.com/archive/75/433959
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. Digg Security.
http://www.securityfocus.com/archive/82/433749
2. Cracking Tutorial - LinuxWorld
http://www.securityfocus.com/archive/82/433594
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Front End/Back End communication
http://www.securityfocus.com/archive/88/434013
2. RDP to XP clients
http://www.securityfocus.com/archive/88/433664
3. Restricting Remote Registry Access
http://www.securityfocus.com/archive/88/433671
4. Autorun in screensaver
http://www.securityfocus.com/archive/88/433357
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
1. Linux's security
http://www.securityfocus.com/archive/91/434109
2. Version 0.8 of OSSEC HIDS is now available (for Unix and Windows)
http://www.securityfocus.com/archive/91/433778
3. SF new column announcement: The quest for ring 0 (fwd)
http://www.securityfocus.com/archive/91/433658
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and ask to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This issue is sponsored by: SPI Dynamics
ALERT: "How a Hacker Launches a SQL Injection Attack!" - SPI Dynamics White Paper
It's as simple as placing additional SQL commands into a Web Form input box giving hackers complete access to all your backend systems! Firewalls and IDS will not stop such attacks because SQL Injections are NOT seen as intruders. Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/sql.asp?Campaign_ID=70130000000COFe