SecurityFocus Newsletter #355

Conrad Schilbe <[email protected]> Tue, 20 Jun 2006 16:32:29 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #355
----------------------------------------

This issue is sponsored by: SPI Dynamics
ALERT: "How A Hacker Launches A Cross-Site Scripting Attack" - White Paper
Cross-site scripting vulnerabilities in web apps allow hackers to compromise confidential information, steal cookies and create requests that can be mistaken for those of a valid user!! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!

https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=70160000000CY4R

------------------------------------------------------------------
I.    FRONT AND CENTER
       1. Phishing with Rachna Dhamija
       2. Ajax security basics
II.   BUGTRAQ SUMMARY
       1. Simple File Manager FM.php Cross-Site Scripting Vulnerability
       2. Sendmail Malformed MIME Message Denial Of Service Vulnerability
       3. Typespeed Remote Buffer Overflow Vulnerability
       4. HotPlugCMS Index.PHP SQL Injection Vulnerability
       5. PHPNuke Module's Name Multiple SQL Injection Vulnerabilities
       6. Mambo Weblinks SQL Injection Vulnerability
       7. Bitweaver CMS Multiple Cross-Site Scripting Vulnerabilities
       8. Cline Communications Multiple SQL Injection Vulnerabilities
       9. DotWidget For Articles Multiple Remote File Include Vulnerabilities
       10. RahnemaCo Page.PHP PageID Remote File Include Vulnerability
       11. OpenSSH DynamicForward Inadvertent GatewayPorts Activation Vulnerability
       12. TinyMuw Videopage.PHP and Quickchat.PHP HTML Injection Vulnerabilitiy
       13. Simple Poll PHP Default Administrator Password Vulnerability
       14. Eprayer Your Name Field HTML Injection Vulnerability
       15. PostgreSQL Multibyte Character Encoding SQL Injection Vulnerabilities
       16. Indexu Multiple Remote File Include Vulnerabilities
       17. MCGuestbook Multiple Remote File Include Vulnerabilities
       18. Ji-takz Remote File Include Vulnerability
       19. AxentForum viewposts.cfm Cross-Site Scripting Vulnerability
       20. IPostMX 2005 Userlogin.CFM and Account.CFM Cross-Site Scripting Vulnerabilities
       21. DHCDBD Remote Denial of Service Vulnerability
       22. Nucleus CMS Multiple Remote File Include Vulnerabilities
       23. SaPHPLesson Show.PHP SQL Injection Vulnerability
       24. Zeroboard Arbitrary File Upload Vulnerability
       25. Dave Carrigan Auth_LDAP Remote Format String Vulnerability
       26. VBZoom Forum.php SQL Injection Vulnerability
       27. Sharky E-Shop Meny2.ASP Cross-Site Scripting Vulnerability 
       28. Sharky E-Shop Search_Prod_List.ASP Cross-Site Scripting Vulnerability
       29. CavoxCms Index.PHP SQL Injection Vulnerability
       30. Free Realty Propview.PHP SQL Injection Vulnerability
       31. The Edge eCommerce Shop ProductDetail.ASP Cross-Site Scripting Vulnerability
       32. OpenSSH SCP Shell Command Execution Vulnerability
       33. Toshiba Bluetooth Stack TOSRFBD.SYS Remote Denial of Service Vulnerability
       34. DPVision Tradingeye Shop Details.CFM Cross-Site Scripting Vulnerability
       35. NetPBM Pamtofits Remote Off-By-One Buffer Overflow Vulnerability
       36. TPL Design TplShop Category.PHP SQL Injection Vulnerability
       37. vBulletin Portal.PHP SQL Injection Vulnerability
       38. SWSoft Confixx Pro Tools_Ftp_Pwaendern.PHP Cross-Site Scripting Vulnerability
       39. GNU Tar Invalid Headers Buffer Overflow Vulnerability
       40. Xarancms Xarancms_haupt.PHP SQL Injection Vulnerability
       41. Cisco CallManager Cross-Site Scripting Vulnerability
       42. Singapore Gallery Index.PHP Directory Traversal and Cross-Site Scripting Vulnerabilities
       43. DotNetNuke Unspecified Security Vulnerability
       44. MAXDEV CMS PNuserapi.PHP SQL Injection Vulnerability
       45. CMS MUNDO Control Panel SQL Injection Vulnerability
       46. Microsoft Windows Routing and Remote Access Remote Code Execution Vulnerability
       47. Microsoft Windows Routing and Remote Access RASMAN Registry Remote Code Execution Vulnerability
       48. WebWasher Remote ARJ Decoder Denial of Service Vulnerability
       49. OpenVPN Client Remote Code Execution Vulnerability
       50. Todd Miller Sudo Local Privilege Escalation Vulnerability
       51. VBulletin Profile.PHP Cross-Site Scripting Vulnerability
       52. CHM Lib Extract_chmlib Directory Traversal Vulnerability
       53. PunBB Multiple Input Validation Vulnerabilities
       54. VMware Player Malformed VMX File Denial of Service Vulnerability
       55. XScreenSaver Local Password Disclosure Vulnerability
       56. Microsoft MDAC RDS.Dataspace ActiveX Control Remote Code Execution Vulnerability
       57. Tux Paint Insecure Temporary File Creation Vulnerability
       58. ASP Stats Generator Pages.ASP SQL Injection Vulnerability
       59. Awstats Configuration File Remote Arbitrary Command Execution Vulnerability
       60. AWStats Remote Arbitrary Command Execution Vulnerability
       61. Retired: vBulletin Multiple Cross-Site Scripting Vulnerabilities
       62. TWiki Homepage Creation Privilege Escalation Vulnerability
       63. Qto File Manager index.php Cross-Site Scripting Vulnerability
       64. Microsoft Excel Unicode Link Memory Corruption Vulnerability
       65. Microsoft Excel Unspecified Remote Code Execution Vulnerability
       66. PHP Live Helper Initiate.PHP Remote File Include Vulnerability
       67. e107 Search.PHP Cross-Site Scripting Vulnerability
       68. CMS Faethon Multiple Cross-Site Scripting Vulnerabilities
       69. Clubpage Multiple Input Validation Vulnerabilities
       70. Linux Kernel XT_SCTP-netfilter Remote Denial of Service Vulnerability
       71. BtitTracker Torrents.PHP SQL Injection Vulnerabilities
       72. Ralf Image Gallery Multiple Input Validation Vulnerabilities
       73. NC Linklist Index.PHP Cross-Site Scripting Vulnerabilities
       74. Open-Realty Search.inc.PHP SQL Injection Vulnerability
       75. V3 Chat Instant Messenger Multiple Input validation Vulnerabilities
       76. PHPMyForum Topic.php Cross-Site Scripting Vulnerability
       77. PHPMyDirectory Multiple Cross-Site Scripting Vulnerabilities
       78. Hitachi Groupmax Unexpected Request Remote Denial of Service Vulnerability
       79. Micro CMS MicroCMS-include.PHP Remote File Include Vulnerability
       80. Arctic Index.PHP Cross-Site Scripting Vulnerability
       81. Dragons Kingdom Script Multiple HTML Injection Vulnerabilities
       82. Datecomm Multiple Cross-Site Scripting Vulnerabilities
       83. Nullsoft Winamp Malformed MIDI File Remote Buffer Overflow Vulnerability
       84. VUBB Index.php SQL Injection Vulnerability
       85. GNOME Foundation GDM .ICEauthority Improper File Permissions Vulnerability
       86. Eduha Meeting Index.PHP Arbitrary File Upload Vulnerability
       87. Mozilla Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
       88. Multiple OkScripts Products Search Cross-Site Scripting Vulnerabilities
       89. CMS Faethon Multiple Remote File Include Vulnerabilities
       90. Bible Portal Rtf_parser.PHP Remote File Include Vulnerability
       91. MPCS Comment.php Cross-Site Scripting Vulnerability
       92. OpenSSH GSSAPI Credential Disclosure Vulnerability
       93. SAPHPLesson Multiple SQL Injection Vulnerabilities
       94. Easy CMS Choose_file.PHP Arbitrary File Upload Vulnerability
       95. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
       96. VBZoom Multiple SQL Injection Vulnerabilities
       97. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
       98. Phaziz Guestbook Multiple HTML Injection Vulnerabilities
       99. SixCMS List.PHP Cross-Site Scripting Vulnerability
       100. SixCMS Detail.PHP Directory Traversal Vulnerability
III.  SECURITYFOCUS NEWS
       1. SCADA industry debates flaw disclosure
       2. Researchers eye machines to analyze malware
       3. Cybersecurity contests go national
       4. Veterans Affairs warns of massive privacy breach
IV.   SECURITY JOBS LIST SUMMARY
       1. [SJ-JOB] Channel / Business Development, Boston
       2. [SJ-JOB] Principal Software Engineer, New York
       3. [SJ-JOB] Security Auditor, Los Angeles
       4. [SJ-JOB] Auditor, Los Angeles
       5. [SJ-JOB] Sr. Security Engineer, New Brunswick
       6. [SJ-JOB] Director, Information Security, Wilmington
       7. [SJ-JOB] Auditor, San Francisco
       8. [SJ-JOB] Security Consultant, Los Angeles
       9. [SJ-JOB] Security Architect, Parsippany
       10. [SJ-JOB] Manager, Information Security, Baltimore
       11. [SJ-JOB] Security Consultant, San Francisco
       12. [SJ-JOB] Sr. Security Engineer, New York City
       13. [SJ-JOB] Security Auditor, San Francisco
       14. [SJ-JOB] Security Engineer, Los Angeles
       15. [SJ-JOB] Sales Engineer, Boston
       16. [SJ-JOB] Security Engineer, Chicago
       17. [SJ-JOB] Regional Channel Manager, Charlotte
       18. [SJ-JOB] Sales Engineer, Dallas
       19. [SJ-JOB] Regional Channel Manager, Orlando
       20. [SJ-JOB] Regional Channel Manager, Chicago
       21. [SJ-JOB] Senior Software Engineer, Huntsville
       22. [SJ-JOB] Security Engineer, New Castle
       23. [SJ-JOB] Jr. Security Analyst, New Castle
       24. [SJ-JOB] Jr. Security Analyst, Warren
       25. [SJ-JOB] Account Manager, Chicago
       26. [SJ-JOB] Account Manager, Atlanta
       27. [SJ-JOB] Account Manager, Denver
       28. [SJ-JOB] Sales Engineer, New York
       29. [SJ-JOB] Account Manager, Herndon
       30. [SJ-JOB] Sales Engineer, Chicago
       31. [SJ-JOB] Account Manager, New York
       32. [SJ-JOB] Security Director, Anywhere
       33. [SJ-JOB] Security Architect, NEW YORK CITY
       34. [SJ-JOB] Security Architect, Dallas
       35. [SJ-JOB] Sales Engineer, Chicago
       36. [SJ-JOB] Security Architect, San Diego
       37. [SJ-JOB] Sales Engineer, san Francisco
       38. [SJ-JOB] VP of Regional Sales, San Francisco
       39. [SJ-JOB] Sales Representative, New York
       40. [SJ-JOB] VP of Regional Sales, San Francisco
       41. [SJ-JOB] Sales Engineer, New York
       42. [SJ-JOB] Certification & Accreditation Engineer, Landover
       43. [SJ-JOB] Management, Atlanta
       44. [SJ-JOB] Security Engineer, Livingston
       45. [SJ-JOB] Security Engineer, Livingston
       46. [SJ-JOB] Certification & Accreditation Engineer, Landover
       47. [SJ-JOB] Senior Software Engineer, San Mateo
       48. [SJ-JOB] Management, Atlanta
       49. [SJ-JOB] Account Manager, Atlanta
       50. [SJ-JOB] Channel / Business Development, New York
       51. [SJ-JOB] Account Manager, Los Angeles
       52. [SJ-JOB] Jr. Security Analyst, New Castle
       53. [SJ-JOB] Account Manager, San Jose
       54. [SJ-JOB] Security Product Manager, Redwood Shores
       55. [SJ-JOB] Account Manager, Charlotte
       56. [SJ-JOB] Channel / Business Development, New York
       57. [SJ-JOB] Security Engineer, Mountain View
       58. [SJ-JOB] Channel / Business Development, Boston
       59. [SJ-JOB] Senior Software Engineer, redwood Shores
       60. [SJ-JOB] Account Manager, Redwood Shores
       61. [SJ-JOB] Senior Software Engineer, Redwood Shores
       62. [SJ-JOB] Software Engineer, Redwood Shores
       63. [SJ-JOB] Technical Support Engineer, Redwood Shores
       64. [SJ-JOB] CISO, Carson City
       65. [SJ-JOB] Senior Software Engineer, Redwood Shores
       66. [SJ-JOB] Quality Assurance, Redwood Shores
       67. [SJ-JOB] Senior Software Engineer, Redwood Shores
       68. [SJ-JOB] Quality Assurance, Redwood Shores
       69. [SJ-JOB] Sr. Security Analyst, Arlington
       70. [SJ-JOB] Security Researcher, Redwood Shores
       71. [SJ-JOB] Jr. Security Analyst, Fort Lauderdale
       72. [SJ-JOB] Security Engineer, Richmond
       73. [SJ-JOB] Security Consultant, Chicago
       74. [SJ-JOB] Sr. Security Analyst, Calgary
       75. [SJ-JOB] Director, Information Security, San Diego
       76. [SJ-JOB] Security Consultant, Chicago
       77. [SJ-JOB] Security Architect, Calgary
       78. [SJ-JOB] Security Consultant, philadelphia
       79. [SJ-JOB] Sales Representative, Emeryville
V.    INCIDENTS LIST SUMMARY
       1. Microsoft Excel 0-day Vulnerability FAQ document written
       2. honeytrap 0.6.1 released
       3. Excel zero day in the wild
       4. Website Defacement
VI.   VULN-DEV RESEARCH LIST SUMMARY
       1. SyScan'06 Highlight - Attacking Microsoft New Operating System (Vista)
       2. SinFP 2.00 - a major release with many new features
       3. Yahoo Messenger 7.0.0.438 Crash Tested
       4. Black Hat Speakers + 2005 Content on-line
VII.  MICROSOFT FOCUS LIST SUMMARY
       1. Securing an encryption key within software.
       2. SecurityFocus Microsoft Newsletter #295
       3. Controlling specific USB devices on Windows XP
VIII. SUN FOCUS LIST SUMMARY
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Phishing with Rachna Dhamija
By Federico Biancuzzi
Federico Biancuzzi interviews Rachna Dhamija, co-author of the paper "Why Phishing Works" and creator of Dynamic Security Skins. They discuss the human factor, how easy it is to recreate a credible browser window made with images, some new anti-phishing features included in the upcoming version of some popular browsers, and the power of letting a user personalize his interface. 
http://www.securityfocus.com/columnists/407

2. Ajax security basics
Jaswinder S. Hayre and Jayasankar Kelath
Ajax technologies have been very visible on the web over the past year, due to their interactive nature. Companies are now thinking of how they too can leverage it, web developers are trying to learn it, security professionals are thinking of how to secure it, and penetration testers are thinking of how to hack it.


II.  BUGTRAQ SUMMARY
--------------------
1. Simple File Manager FM.php Cross-Site Scripting Vulnerability
BugTraq ID: 18534
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18534
Summary:
Simple File Manager is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

2. Sendmail Malformed MIME Message Denial Of Service Vulnerability
BugTraq ID: 18433
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18433
Summary:
Sendmail is prone to a denial-of-service vulnerability. This issue is due to a failure in the application to properly handle malformed multi-part MIME messages.

An attacker can exploit this issue to crash the sendmail process during delivery.

3. Typespeed Remote Buffer Overflow Vulnerability
BugTraq ID: 18194
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18194
Summary:
Typespeed is susceptible to a remote buffer-overflow vulnerability. This issue is due to a failure in the application to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

This issue allows remote attackers to execute arbitrary machine code in the context of affected applications, aiding them in the compromise of affected computers.

Typespeed versions 0.4.1 and 0.4.4 are vulnerable to this issue; other versions may also be affected.

4. HotPlugCMS Index.PHP SQL Injection Vulnerability
BugTraq ID: 18488
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18488
Summary:
HotPlugCMS is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

5. PHPNuke Module's Name Multiple SQL Injection Vulnerabilities
BugTraq ID: 18493
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18493
Summary:
Module's Name is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

6. Mambo Weblinks SQL Injection Vulnerability
BugTraq ID: 18492
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18492
Summary:
Mambo is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

7. Bitweaver CMS Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 17406
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/17406
Summary:
Bitweaver CMS is prone to multiple cross-site scripting vulnerabilities. Thess issues are due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

8. Cline Communications Multiple SQL Injection Vulnerabilities
BugTraq ID: 18491
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18491
Summary:
Cline Communications is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

9. DotWidget For Articles Multiple Remote File Include Vulnerabilities
BugTraq ID: 18479
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18479
Summary:
dotWidget for Articles is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Some of these issue may be related to those discussed in BID 18258 (DotWidget CMS Multiple Remote File Include Vulnerabilities).

10. RahnemaCo Page.PHP PageID Remote File Include Vulnerability
BugTraq ID: 18490
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18490
Summary:
RahnemaCo is prone to a remote file-include vulnerability.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

11. OpenSSH DynamicForward Inadvertent GatewayPorts Activation Vulnerability
BugTraq ID: 14727
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/14727
Summary:
OpenSSH is susceptible to a vulnerability that causes improper activation of the 'GatewayPorts' option, allowing unintended hosts to use the SSH SOCKS proxy. 

Specifically, if the 'DynamicForward' option is activated, 'GatewayPorts' is also unconditionally enabled. 

This vulnerability allows remote attackers to use the SOCKS proxy to make arbitrary TCP connections through the configured SSH session, allowing them to attack computers and services through a connection that was wrongly thought to be secure. 

This issue affects OpenSSH 4.0, and 4.1.

12. TinyMuw Videopage.PHP and Quickchat.PHP HTML Injection Vulnerabilitiy
BugTraq ID: 18483
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18483
Summary:
TinyMuw is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied HTML and script code before using it in dynamically generated content.

An attacker could exploit this vulnerability to inject hostile HTML and script code into the affected site. This may help the attacker steal cookie-based authentication credentials or control how the site is rendered to the user; other attacks are also possible.

13. Simple Poll PHP Default Administrator Password Vulnerability
BugTraq ID: 18486
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18486
Summary:
Simple PHP Poll is prone to an authentication-bypass vulnerability. The issue occurs because the administrator password is hardcoded into the application.

An attacker can exploit this issue to bypass authentication and gain access to the affected application's administrative section. This could aid in further attacks on the affected computer.

14. Eprayer Your Name Field HTML Injection Vulnerability
BugTraq ID: 18485
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18485
Summary:
Eprayer is prone to an HTML-injection vulnerability because it fails to properly sanitize HTML and script code from user-supplied input to the prayer request form.

An attacker could exploit this vulnerability to inject hostile HTML and script code into the browser session of other users of the application.

15. PostgreSQL Multibyte Character Encoding SQL Injection Vulnerabilities
BugTraq ID: 18092
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18092
Summary:
PostgreSQL is prone to SQL-injection vulnerabilities. These issues are due to a potential mismatch of multibyte character conversions between PostgreSQL servers and client applications.

A successful exploit could allow an attacker to execute arbitrary SQL statements on affected servers. This may allow the attacker to compromise the targeted computer, access or modify data, or exploit other latent vulnerabilities.

PostgreSQL versions prior to 7.3.15, 7.4.13, 8.0.8, and 8.1.4 are vulnerable to these issues.

16. Indexu Multiple Remote File Include Vulnerabilities
BugTraq ID: 18477
Remote: Yes
Last Updated: 2006-06-16
Relevant URL: http://www.securityfocus.com/bid/18477
Summary:
Indexu is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

17. MCGuestbook Multiple Remote File Include Vulnerabilities
BugTraq ID: 18476
Remote: Yes
Last Updated: 2006-06-16
Relevant URL: http://www.securityfocus.com/bid/18476
Summary:
mcGuestbook is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

18. Ji-takz Remote File Include Vulnerability
BugTraq ID: 18474
Remote: Yes
Last Updated: 2006-06-16
Relevant URL: http://www.securityfocus.com/bid/18474
Summary:
Ji-takz is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input to the application.

An attacker may leverage this issue to have an arbitrary remote file containing malicious script code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system. Other attacks are also possible.

19. AxentForum viewposts.cfm Cross-Site Scripting Vulnerability
BugTraq ID: 18473
Remote: Yes
Last Updated: 2006-06-16
Relevant URL: http://www.securityfocus.com/bid/18473
Summary:
aXentForum is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script and HTML code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

20. IPostMX 2005 Userlogin.CFM and Account.CFM Cross-Site Scripting Vulnerabilities
BugTraq ID: 18460
Remote: Yes
Last Updated: 2006-06-16
Relevant URL: http://www.securityfocus.com/bid/18460
Summary:
IPostmx 2005 is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to execute arbitrary HTML and script code in the browser of a victim user in the context of the webserver process. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

21. DHCDBD Remote Denial of Service Vulnerability
BugTraq ID: 18459
Remote: Yes
Last Updated: 2006-06-16
Relevant URL: http://www.securityfocus.com/bid/18459
Summary:
DHCDBD is prone to a remote denial-of-service vulnerability. 

The issue presents itself when the application handles malformed data and accesses out-of-bounds memory. 

DHCDBD 1.10 and 1.22 are vulnerable to this issue; other versions may also be affected.

22. Nucleus CMS Multiple Remote File Include Vulnerabilities
BugTraq ID: 18475
Remote: Yes
Last Updated: 2006-06-16
Relevant URL: http://www.securityfocus.com/bid/18475
Summary:
Nucleus CMS is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

23. SaPHPLesson Show.PHP SQL Injection Vulnerability
BugTraq ID: 18117
Remote: Yes
Last Updated: 2006-06-16
Relevant URL: http://www.securityfocus.com/bid/18117
Summary:
SaPHPLesson is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

24. Zeroboard Arbitrary File Upload Vulnerability
BugTraq ID: 18465
Remote: Yes
Last Updated: 2006-06-16
Relevant URL: http://www.securityfocus.com/bid/18465
Summary:
Zeroboard is prone to an arbitrary file-upload vulnerability. 

An attacker can exploit this vulnerability to upload a malicious '.htaccess' file that will remove restrictions on further file-uploads and executions.

Note that to exploit this vulnerability, the Apache 'mod_mime' module must be installed and the web directory must be configured with the Apache 'AllowOverride All' or 'AllowOverride FileInfo' webserver directives.

This issue affects versions 4.1pl8 and prior.

25. Dave Carrigan Auth_LDAP Remote Format String Vulnerability
BugTraq ID: 16177
Remote: Yes
Last Updated: 2006-06-16
Relevant URL: http://www.securityfocus.com/bid/16177
Summary:
Dave Carrigan's auth_ldap is susceptible to a remote format-string vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in the format-specifier of a formatted printing function. 

This issue likely arises only if auth_ldap has been enabled and is used for user authentication. 

This issue allows remote attackers to execute arbitrary machine code in the context of Apache webservers that use the affected module. This may facilitate the compromise of affected computers.

26. VBZoom Forum.php SQL Injection Vulnerability
BugTraq ID: 18472
Remote: Yes
Last Updated: 2006-06-16
Relevant URL: http://www.securityfocus.com/bid/18472
Summary:
VBZooM is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

27. Sharky E-Shop Meny2.ASP Cross-Site Scripting Vulnerability 
BugTraq ID: 18532
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18532
Summary:
Sharky E-Shop is prone to a cross-site scripting vulnerability.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

28. Sharky E-Shop Search_Prod_List.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 18530
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18530
Summary:
Sharky E-Shop is prone to a cross-site scripting vulnerability.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

29. CavoxCms Index.PHP SQL Injection Vulnerability
BugTraq ID: 18533
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18533
Summary:
CavoxCms is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

30. Free Realty Propview.PHP SQL Injection Vulnerability
BugTraq ID: 18531
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18531
Summary:
Free Realty is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

31. The Edge eCommerce Shop ProductDetail.ASP Cross-Site Scripting Vulnerability
BugTraq ID: 18528
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18528
Summary:
The Edge eCommerce Shop is affected by a cross-site scripting vulnerability.

An attacker may leverage this issue to have arbitrary script code run in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

32. OpenSSH SCP Shell Command Execution Vulnerability
BugTraq ID: 16369
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/16369
Summary:
OpenSSH is susceptible to an SCP shell command-execution vulnerability. This issue is due to the application's failure to properly sanitize user-supplied input before using it in a 'system()' function call.

This issue allows attackers to execute arbitrary shell commands with the privileges of users executing a vulnerable version of SCP.

This issue reportedly affects version 4.2 of OpenSSH. Other versions may also be affected.

33. Toshiba Bluetooth Stack TOSRFBD.SYS Remote Denial of Service Vulnerability
BugTraq ID: 18527
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18527
Summary:
Toshiba Bluetooth Stack is prone to a remote denial-of-service vulnerability.

Reports indicate that a successful attack can corrupt memory and restart a vulnerable computer. 
Toshiba Bluetooth Stack for Windows versions 4.0.23 and prior are reported to be affected.

34. DPVision Tradingeye Shop Details.CFM Cross-Site Scripting Vulnerability
BugTraq ID: 18526
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18526
Summary:
DPVision Tradingeye Shop is prone to a cross-site scripting vulnerability.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

35. NetPBM Pamtofits Remote Off-By-One Buffer Overflow Vulnerability
BugTraq ID: 18525
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18525
Summary:
Netpbm 'pnmtofits' is prone to an off-by-one buffer-overflow vulnerability.

The issue presents itself when the application processes a malicious file. A remote attacker may exploit this issue to trigger a denial-of-service condition. The attacker might also be able to execute arbitrary code, but this has not been confirmed.

Netpbm versions 10.30 to 10.33 are vulnerable to this issue.

36. TPL Design TplShop Category.PHP SQL Injection Vulnerability
BugTraq ID: 18524
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18524
Summary:
tplShop is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

37. vBulletin Portal.PHP SQL Injection Vulnerability
BugTraq ID: 18197
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18197
Summary:
vBulletin is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

38. SWSoft Confixx Pro Tools_Ftp_Pwaendern.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18523
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18523
Summary:
SWSoft Confixx Pro is affected by a cross-site scripting vulnerability.

An attacker may leverage this issue to have arbitrary script code run in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

39. GNU Tar Invalid Headers Buffer Overflow Vulnerability
BugTraq ID: 16764
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/16764
Summary:
GNU Tar is prone to a buffer overflow when handling invalid headers. Successful exploitation could potentially lead to arbitrary code execution, but this has not been confirmed.

Tar versions 1.14 and above are vulnerable.

40. Xarancms Xarancms_haupt.PHP SQL Injection Vulnerability
BugTraq ID: 18520
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18520
Summary:
Xarancms is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

41. Cisco CallManager Cross-Site Scripting Vulnerability
BugTraq ID: 18504
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18504
Summary:
Cisco CallManager is prone to a cross-site scripting vulnerability. This issue is due to a failure in the web-interface to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting administrative user in the context of the affected site. This may help the attacker launch other attacks.

42. Singapore Gallery Index.PHP Directory Traversal and Cross-Site Scripting Vulnerabilities
BugTraq ID: 18518
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18518
Summary:
singapore gallery is prone to directory-traversal and cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. 

An attacker can exploit the directory-traversal vulnerabilities to retrieve arbitrary files from the vulnerable system in the context of the webserver process.

The cross-site scripting vulnerability allows an attacker to leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

43. DotNetNuke Unspecified Security Vulnerability
BugTraq ID: 18522
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18522
Summary:
DotNetNuke is prone to an unspecified security vulnerability. This issue is most likely due to a failure in the application to properly sanitize user-supplied data.

Reports indicate that an attacker can exploit this issue to compromise the application and to upload files to the affected computer.

Very little information is available on this issue; this BID will be updated as more information becomes available.

44. MAXDEV CMS PNuserapi.PHP SQL Injection Vulnerability
BugTraq ID: 17399
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/17399
Summary:
MAXDEV CMS is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

45. CMS MUNDO Control Panel SQL Injection Vulnerability
BugTraq ID: 18451
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18451
Summary:
CMS Mundo is prone an SQL injection vulnerability. 

An attacker can gain administrative access to the application through exploiting this vulnerability. Other attacks are also possible, depending on the nature of the affected query and the underlying database implementation.

46. Microsoft Windows Routing and Remote Access Remote Code Execution Vulnerability
BugTraq ID: 18325
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18325
Summary:
Microsoft Windows Routing and Remote Access is prone to a memory-corruption vulnerability. This issue is due to the software's failure to properly bounds-check user-supplied network data before copying it to an insufficiently sized memory buffer.

This issue allows remote attackers to execute arbitrary machine code on affected computers with SYSTEM-level privileges. This facilitates the complete compromise of affected computers.

Exploiting this issue on Microsoft Windows XP SP2 or Windows Server 2003 requires valid login credentials. Anonymous attacks are possible with Windows 2000 and Windows XP versions prior to SP2.

47. Microsoft Windows Routing and Remote Access RASMAN Registry Remote Code Execution Vulnerability
BugTraq ID: 18358
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18358
Summary:
Microsoft Windows Routing and Remote Access is prone to a memory-corruption vulnerability. This issue is due to the software's failure to properly bounds-check user-supplied network data before copying it to an insufficiently sized memory buffer.

This issue allows remote attackers to execute arbitrary machine code on affected computers with SYSTEM-level privileges. This facilitates the complete compromise of affected computers.

Exploiting this issue on Microsoft Windows XP SP2 or Windows Server 2003 requires valid login credentials. Anonymous attacks are possible with Windows 2000 and Windows XP versions prior to SP2.

48. WebWasher Remote ARJ Decoder Denial of Service Vulnerability
BugTraq ID: 18521
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18521
Summary:
WebWasher is susceptible to a remote denial-of-service vulnerability. This issue is due to the application's failure to properly handle malformed archive files.

This issue allows remote attackers to crash the affected application, potentially denying service to legitimate users.

Versions of WebWasher prior to version 5.3.0 build 2252 are vulnerable to this issue.

49. OpenVPN Client Remote Code Execution Vulnerability
BugTraq ID: 17392
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/17392
Summary:
OpenVPN is reported prone to a remote code-execution vulnerability. This issue is due to a lack of proper sanitization of server-supplied data.

A remote attacker may exploit this issue to execute arbitrary code with elevated privileges on a vulnerable computer to gain unauthorized access.

To be vulnerable to this issue, client OpenVPN computers must be configured to use 'up' or 'down' scripts and must have either the 'pull' configuration directive or a 'client' macro set up.

OpenVPN versions 2.0.0 through 2.0.5 are affected by this issue.

50. Todd Miller Sudo Local Privilege Escalation Vulnerability
BugTraq ID: 15191
Remote: No
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/15191
Summary:
Sudo is prone to a local privilege-escalation vulnerability. 

The vulnerability presents itself because the application fails to properly sanitize malicious data supplied through environment variables. 

A successful attack may result in a complete compromise.

51. VBulletin Profile.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 16128
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/16128
Summary:
VBulletin is prone to a cross-site scripting vulnerability.  This issue is due to a failure in the application to properly sanitize user-supplied input. 
 
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site.  This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

52. CHM Lib Extract_chmlib Directory Traversal Vulnerability
BugTraq ID: 18511
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18511
Summary:
CHM Lib is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input. 

An attacker can exploit this vulnerability to place malicious files and to overwrite files in arbitrary locations on the vulnerable system, in the context of the user running the application. Successful exploits may aid in further attacks.

53. PunBB Multiple Input Validation Vulnerabilities
BugTraq ID: 17827
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/17827
Summary:
PunBB is prone to an HTML-injection vulnerability and a cross-site scripting vulnerability. These issues are due to a failure in the application to properly sanitize user-supplied input. 

Attacker-supplied HTML and script code would be executed in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user.

54. VMware Player Malformed VMX File Denial of Service Vulnerability
BugTraq ID: 18515
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18515
Summary:
VMware Player is susceptible to a denial-of-service vulnerability. This issue is due to the application's failure to properly handle excessively long data.

This issue allows remote attackers to cause affected applications to crash, denying service to legitimate users. This occurs when unsuspecting users try to open malformed VMX files.

VMware Player is vulnerable to this issue. Due to code reuse among VMware products, other applications are also potentially affected as well.

55. XScreenSaver Local Password Disclosure Vulnerability
BugTraq ID: 17471
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/17471
Summary:
XScreenSaver is prone to a local password-disclosure vulnerability. This issue is due to a flaw in the application that may result in the screen-unlock password being passed onto other applications that are already running on the computer.

This may disclose the password used to unlock the applications. The login password is typically used to unlock XScreenSaver, so this issue may reveal login passwords to attackers.

This issue is currently known to affect users who are running RDesktop on the locked computer, due to the interaction between the applications. This may result in the disclosure of the login password across the network. Other unknown applications in conjunction with XScreenSaver may result in a similar issue.

Version 4.14, and 4.16 are vulnerable to this issue; other versions may also be affected.

56. Microsoft MDAC RDS.Dataspace ActiveX Control Remote Code Execution Vulnerability
BugTraq ID: 17462
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/17462
Summary:
The Microsoft MDAC RDS.Dataspace ActiveX control is vulnerable to remote code execution.  An attacker could exploit this issue to execute code in the context of the user visiting a malicious web page.

57. Tux Paint Insecure Temporary File Creation Vulnerability
BugTraq ID: 16250
Remote: No
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/16250
Summary:
Tux Paint creates temporary files in an insecure manner. 
 
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.

58. ASP Stats Generator Pages.ASP SQL Injection Vulnerability
BugTraq ID: 18512
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18512
Summary:
ASP Stats Generator is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
 
ASP Stats Generator versions 2.1.1 and prior are reported vulnerable; other versions may also be affected.

59. Awstats Configuration File Remote Arbitrary Command Execution Vulnerability
BugTraq ID: 18327
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18327
Summary:
Awstats is prone to an arbitrary command-execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker can exploit this vulnerability to execute arbitrary shell commands in the context of the webserver process. This may help attackers compromise the underlying system; other attacks are also possible.

60. AWStats Remote Arbitrary Command Execution Vulnerability
BugTraq ID: 17844
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/17844
Summary:
AWStats is prone to an arbitrary command-execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker can exploit this vulnerability to execute arbitrary shell commands in the context of the webserver process. This may help attackers compromise the underlying system; other attacks are also possible.

61. Retired: vBulletin Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18444
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18444
Summary:
vBulletin is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

The vendor reports that this issue is specific to one site and is due to a misconfiguration of the vBulletin code; therefore, this BID is being retired.

62. TWiki Homepage Creation Privilege Escalation Vulnerability
BugTraq ID: 18506
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18506
Summary:
TWiki is prone to a vulnerability that could permit privilege escalation. This issue is due to a design error in the application; it fails to properly reset security settings. 

An attacker with a valid account can exploit this vulnerability to elevate privileges to that of an administrator of the application. This may permit the attacker to alter site content; other attacks are also possible.

63. Qto File Manager index.php Cross-Site Scripting Vulnerability
BugTraq ID: 18510
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18510
Summary:
Qto file manager is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

64. Microsoft Excel Unicode Link Memory Corruption Vulnerability
BugTraq ID: 18500
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18500
Summary:
Microsoft Excel is prone to a memory-corruption vulnerability. This issue is due to the application's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

Successfully exploiting this issue causes the affected application to crash, denying service to legitimate users. Attackers may also be able to execute arbitrary code in the context of targeted users, but this has not been confirmed.

Note that Microsoft Office applications include functionality to embed Office files as objects contained in other Office files. As an example, Microsoft Word files may contain embedded malicious Microsoft Excel files, making Word documents another possible attack vector.

Microsoft Excel versions 2002 SP3 and 2003 SP2 are vulnerable to this issue; other versions may also be affected.

65. Microsoft Excel Unspecified Remote Code Execution Vulnerability
BugTraq ID: 18422
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18422
Summary:
Microsoft Excel is prone to an unspecified remote code-execution vulnerability. Insufficient details are currently available to elaborate further.

Successfully exploiting this issue allows attackers to execute arbitrary code in the context of targeted users.

Attackers are actively exploiting this vulnerability in targeted attacks and to install malicious software.

Note that MS Office applications include functionality to embed Office files as objects contained in other Microsoft Office files. As an example, Microsoft Word files may contain embedded malicious Microsoft Excel files, making Word documents another possible attack vector.

This BID will be updated as further information becomes available.

66. PHP Live Helper Initiate.PHP Remote File Include Vulnerability
BugTraq ID: 18509
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18509
Summary:
PHP Live Helper is prone to a remote file-include vulnerability.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

67. e107 Search.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18508
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18508
Summary:
e107 is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.

68. CMS Faethon Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18505
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18505
Summary:
CMS Faethon is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize HTML and script code from user-supplied input to several parameters before returning to the user.

An attacker could exploit these vulnerabilities to inject hostile HTML and script code into the browser session of other users of the application.

69. Clubpage Multiple Input Validation Vulnerabilities
BugTraq ID: 18552
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18552
Summary:
Clubpage is prone to multiple input-validation vulnerabilities. The issues include cross-site scripting and SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. 

A successful exploit of these vulnerabilities could allow an attacker to compromise the application, access or modify data, steal cookie-based authentication credentials, or even exploit vulnerabilities in the underlying database implementation. Other attacks are also possible.

70. Linux Kernel XT_SCTP-netfilter Remote Denial of Service Vulnerability
BugTraq ID: 18550
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18550
Summary:
The Linux kernel SCTP netfilter module is susceptible to a remote denial-of-service vulnerability. 

This issue allows remote attackers to cause affected kernels to enter into an infinite-loop condition, denying service to legitimate users. 

Kernel versions prior to 2.6.17.1 are vulnerable to this issue.

This issue is reportedly similar to the one documented in BID 17806 (Linux Kernel SCTP-netfilter Remote Denial of Service Vulnerability).

71. BtitTracker Torrents.PHP SQL Injection Vulnerabilities
BugTraq ID: 18549
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18549
Summary:
BtitTracker is prone to multiple SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

72. Ralf Image Gallery Multiple Input Validation Vulnerabilities
BugTraq ID: 18548
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18548
Summary:
Ralf Image Gallery is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. 

An attacker can exploit the directory-traversal vulnerabilities to retrieve arbitrary files from the vulnerable system in the context of the webserver process.

The cross-site scripting vulnerabilities allow an attacker to leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

The remote file-include issues allow an attacker to include arbitrary remote files containing malicious PHP code and execute them in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

73. NC Linklist Index.PHP Cross-Site Scripting Vulnerabilities
BugTraq ID: 18546
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18546
Summary:
NC Linklist is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize HTML and script code from user-supplied input to several parameters before returning to the user.

An attacker could exploit these vulnerabilities to inject hostile HTML and script code into the browser session of other users of the application.

74. Open-Realty Search.inc.PHP SQL Injection Vulnerability
BugTraq ID: 18545
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18545
Summary:
Open-Realty is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

75. V3 Chat Instant Messenger Multiple Input validation Vulnerabilities
BugTraq ID: 18543
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18543
Summary:
V3 Chat Instant Messenger is prone to multiple cross-site scripting and SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks. 

Also a successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

76. PHPMyForum Topic.php Cross-Site Scripting Vulnerability
BugTraq ID: 18542
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18542
Summary:
phpMyForum is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Versions 4.1.3 and prior are reported to be vulnerable; other versions may also be affected.

77. PHPMyDirectory Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18539
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18539
Summary:
phpMyDirectory is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

78. Hitachi Groupmax Unexpected Request Remote Denial of Service Vulnerability
BugTraq ID: 18538
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18538
Summary:
Hitachi Groupmax Mail and Address Server are prone to an unspecified denial-of-service vulnerability while processing unexpected requests. 
 
This issue allows remote attackers to crash affected servers, denying service to legitimate users. 
 
Further information is not currently available; this BID will be updated as new information is disclosed.

79. Micro CMS MicroCMS-include.PHP Remote File Include Vulnerability
BugTraq ID: 18537
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18537
Summary:
Micro CMS is prone to a remote file-include vulnerability.

An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.

Version 0.3.5 is reported to be vulnerable; other versions may also be affected.

80. Arctic Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18536
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18536
Summary:
Arctic is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

81. Dragons Kingdom Script Multiple HTML Injection Vulnerabilities
BugTraq ID: 18535
Remote: Yes
Last Updated: 2006-06-20
Relevant URL: http://www.securityfocus.com/bid/18535
Summary:
Dragons Kingdom Script is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize HTML and script code from user-supplied input.

An attacker could exploit this vulnerability to inject hostile HTML and script code into the browser session of other users of the application.

82. Datecomm Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 18502
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18502
Summary:
Datecomm is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

83. Nullsoft Winamp Malformed MIDI File Remote Buffer Overflow Vulnerability
BugTraq ID: 18507
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18507
Summary:
Winamp is prone to a buffer-overflow vulnerability when handling specially crafted files. 
An attacker may exploit this issue to gain unauthorized access to a computer with the privileges of the user that activated the vulnerable application.

Winamp versions prior to 5.22 are reported prone to this issue.

84. VUBB Index.php SQL Injection Vulnerability
BugTraq ID: 18516
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18516
Summary:
vuBB is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

85. GNOME Foundation GDM .ICEauthority Improper File Permissions Vulnerability
BugTraq ID: 17635
Remote: No
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/17635
Summary:
GDM is prone to an improper file-permissions vulnerability.

An attacker can exploit this issue to gain access to sensitive or privileged information that may facilitate a complete compromise of the vulnerable computer.

86. Eduha Meeting Index.PHP Arbitrary File Upload Vulnerability
BugTraq ID: 18499
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18499
Summary:
Eduha Meeting is prone to an arbitrary file-upload vulnerability. 

An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. 

This may facilitate unauthorized access or privilege escalation; other attacks are also possible.

87. Mozilla Firefox, SeaMonkey, and Thunderbird Multiple Remote Vulnerabilities
BugTraq ID: 18228
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18228
Summary:
The Mozilla Foundation has released thirteen security advisories specifying security vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable application
- crash affected applications
- run JavaScript code with elevated privileges, potentially allowing the remote execution of machine code 
- gain access to potentially sensitive information.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as further information becomes available.

These issues are fixed in:
- Mozilla Firefox version 1.5.0.4
- Mozilla Thunderbird version 1.5.0.4
- Mozilla SeaMonkey version 1.0.2

88. Multiple OkScripts Products Search Cross-Site Scripting Vulnerabilities
BugTraq ID: 18442
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18442
Summary:
Multiple OkScripts products are prone to cross-site scripting vulnerabilities. The affected products are OkMall, QuickLinks, and OkArticles. The software fails to sanitize input before displaying it to users. 


An attacker may exploit these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

89. CMS Faethon Multiple Remote File Include Vulnerabilities
BugTraq ID: 18489
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18489
Summary:
CMS Faethon is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input to the application.

An attacker may leverage these issues to have an arbitrary remote file containing malicious script code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system. Other attacks are also possible.

90. Bible Portal Rtf_parser.PHP Remote File Include Vulnerability
BugTraq ID: 18494
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18494
Summary:
Bible Portal is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input to the application.

An attacker may leverage this issue to have an arbitrary remote file containing malicious script code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system. Other attacks are also possible.

91. MPCS Comment.php Cross-Site Scripting Vulnerability
BugTraq ID: 18470
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18470
Summary:
MPCS is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

92. OpenSSH GSSAPI Credential Disclosure Vulnerability
BugTraq ID: 14729
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/14729
Summary:
OpenSSH is susceptible to a GSSAPI credential-delegation vulnerability. 

Specifically, if a user has GSSAPI authentication configured, and 'GSSAPIDelegateCredentials' is enabled, their Kerberos credentials will be forwarded to remote hosts. This occurs even when the user employs authentication methods other than GSSAPI to connect, which is not usually expected. 

This vulnerability allows remote attackers to improperly gain access to GSSAPI credentials, allowing them to use those credentials to access resources granted to the original principal. 

This issue affects versions of OpenSSH prior to 4.2.

93. SAPHPLesson Multiple SQL Injection Vulnerabilities
BugTraq ID: 18501
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18501
Summary:
The saphplesson module is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries. 

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

94. Easy CMS Choose_file.PHP Arbitrary File Upload Vulnerability
BugTraq ID: 18496
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18496
Summary:
Easy CMS  is prone to an arbitrary file-upload vulnerability. 

An attacker can exploit this vulnerability to upload malicious script code, which will be executed in the context of the webserver process.

An attacker may compromise the application by uploading and executing malicious PHP scripts with arbitrary filename extensions, because the application fails to sanitize illegal file extensions.

95. Sendmail Asynchronous Signal Handling Remote Code Execution Vulnerability
BugTraq ID: 17192
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/17192
Summary:
Sendmail is prone to a remote code-execution vulnerability.

Remote attackers may leverage this issue to execute arbitrary code with the privileges of the application, which typically runs as superuser.

Sendmail versions prior to 8.13.6 are vulnerable to this issue.

96. VBZoom Multiple SQL Injection Vulnerabilities
BugTraq ID: 18497
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18497
Summary:
VBZooM is prone to multiple SQL-injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.

97. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
BugTraq ID: 15834
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/15834
Summary:
Apache's mod_imap module is prone to a cross-site scripting vulnerability. This issue is due to the module's failure to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

98. Phaziz Guestbook Multiple HTML Injection Vulnerabilities
BugTraq ID: 18495
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18495
Summary:
Phaziz Guestbook is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize HTML and script code from user-supplied input.

An attacker could exploit this vulnerability to inject hostile HTML and script code into the browser session of other users of the application.

99. SixCMS List.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 18393
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18393
Summary:
SixCMS is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

100. SixCMS Detail.PHP Directory Traversal Vulnerability
BugTraq ID: 18395
Remote: Yes
Last Updated: 2006-06-19
Relevant URL: http://www.securityfocus.com/bid/18395
Summary:
SixCMS is prone to a directory-traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input. 

An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. SCADA industry debates flaw disclosure
By: Robert Lemos
Vulnerability researchers bring in US-CERT to referee the outing of an infrastructure bug, ruffling feathers as vendors and researchers clash over how disclosure should be handled. Sound familiar?
http://www.securityfocus.com/news/11396

2. Researchers eye machines to analyze malware
By: Robert Lemos
Automated classification of malicious software could make recognition of threats faster and names more consistent, but researchers cannot agree on what such a system should look like.
http://www.securityfocus.com/news/11395

3. Cybersecurity contests go national
By: Robert Lemos
America's heartland has become an incubator for competitions pitting high-school and college students against teams of hackers in defense of a corporate network.
http://www.securityfocus.com/news/11394

4. Veterans Affairs warns of massive privacy breach
By: Robert Lemos
The records of nearly 26.5 million veterans--including names, social security numbers and dates of birth--were stolen from the home of a federal employee.
http://www.securityfocus.com/news/11393

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Channel / Business Development, Boston
http://www.securityfocus.com/archive/77/437872

2. [SJ-JOB] Principal Software Engineer, New York
http://www.securityfocus.com/archive/77/437874

3. [SJ-JOB] Security Auditor, Los Angeles
http://www.securityfocus.com/archive/77/437871

4. [SJ-JOB] Auditor, Los Angeles
http://www.securityfocus.com/archive/77/437873

5. [SJ-JOB] Sr. Security Engineer, New Brunswick
http://www.securityfocus.com/archive/77/437863

6. [SJ-JOB] Director, Information Security, Wilmington
http://www.securityfocus.com/archive/77/437866

7. [SJ-JOB] Auditor, San Francisco
http://www.securityfocus.com/archive/77/437867

8. [SJ-JOB] Security Consultant, Los Angeles
http://www.securityfocus.com/archive/77/437868

9. [SJ-JOB] Security Architect, Parsippany
http://www.securityfocus.com/archive/77/437869

10. [SJ-JOB] Manager, Information Security, Baltimore
http://www.securityfocus.com/archive/77/437870

11. [SJ-JOB] Security Consultant, San Francisco
http://www.securityfocus.com/archive/77/437834

12. [SJ-JOB] Sr. Security Engineer, New York City
http://www.securityfocus.com/archive/77/437864

13. [SJ-JOB] Security Auditor, San Francisco
http://www.securityfocus.com/archive/77/437865

14. [SJ-JOB] Security Engineer, Los Angeles
http://www.securityfocus.com/archive/77/437827

15. [SJ-JOB] Sales Engineer, Boston
http://www.securityfocus.com/archive/77/437842

16. [SJ-JOB] Security Engineer, Chicago
http://www.securityfocus.com/archive/77/437843

17. [SJ-JOB] Regional Channel Manager, Charlotte
http://www.securityfocus.com/archive/77/437840

18. [SJ-JOB] Sales Engineer, Dallas
http://www.securityfocus.com/archive/77/437841

19. [SJ-JOB] Regional Channel Manager, Orlando
http://www.securityfocus.com/archive/77/437810

20. [SJ-JOB] Regional Channel Manager, Chicago
http://www.securityfocus.com/archive/77/437839

21. [SJ-JOB] Senior Software Engineer, Huntsville
http://www.securityfocus.com/archive/77/437838

22. [SJ-JOB] Security Engineer, New Castle
http://www.securityfocus.com/archive/77/437828

23. [SJ-JOB] Jr. Security Analyst, New Castle
http://www.securityfocus.com/archive/77/437829

24. [SJ-JOB] Jr. Security Analyst, Warren
http://www.securityfocus.com/archive/77/437830

25. [SJ-JOB] Account Manager, Chicago
http://www.securityfocus.com/archive/77/437825

26. [SJ-JOB] Account Manager, Atlanta
http://www.securityfocus.com/archive/77/437826

27. [SJ-JOB] Account Manager, Denver
http://www.securityfocus.com/archive/77/437821

28. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/437822

29. [SJ-JOB] Account Manager, Herndon
http://www.securityfocus.com/archive/77/437824

30. [SJ-JOB] Sales Engineer, Chicago
http://www.securityfocus.com/archive/77/437819

31. [SJ-JOB] Account Manager, New York
http://www.securityfocus.com/archive/77/437820

32. [SJ-JOB] Security Director, Anywhere
http://www.securityfocus.com/archive/77/437730

33. [SJ-JOB] Security Architect, NEW YORK CITY
http://www.securityfocus.com/archive/77/437734

34. [SJ-JOB] Security Architect, Dallas
http://www.securityfocus.com/archive/77/437748

35. [SJ-JOB] Sales Engineer, Chicago
http://www.securityfocus.com/archive/77/437728

36. [SJ-JOB] Security Architect, San Diego
http://www.securityfocus.com/archive/77/437732

37. [SJ-JOB] Sales Engineer, san Francisco
http://www.securityfocus.com/archive/77/437749

38. [SJ-JOB] VP of Regional Sales, San Francisco
http://www.securityfocus.com/archive/77/437719

39. [SJ-JOB] Sales Representative, New York
http://www.securityfocus.com/archive/77/437724

40. [SJ-JOB] VP of Regional Sales, San Francisco
http://www.securityfocus.com/archive/77/437739

41. [SJ-JOB] Sales Engineer, New York
http://www.securityfocus.com/archive/77/437744

42. [SJ-JOB] Certification & Accreditation Engineer, Landover
http://www.securityfocus.com/archive/77/437726

43. [SJ-JOB] Management, Atlanta
http://www.securityfocus.com/archive/77/437740

44. [SJ-JOB] Security Engineer, Livingston
http://www.securityfocus.com/archive/77/437720

45. [SJ-JOB] Security Engineer, Livingston
http://www.securityfocus.com/archive/77/437729

46. [SJ-JOB] Certification & Accreditation Engineer, Landover
http://www.securityfocus.com/archive/77/437731

47. [SJ-JOB] Senior Software Engineer, San Mateo
http://www.securityfocus.com/archive/77/437733

48. [SJ-JOB] Management, Atlanta
http://www.securityfocus.com/archive/77/437737

49. [SJ-JOB] Account Manager, Atlanta
http://www.securityfocus.com/archive/77/437679

50. [SJ-JOB] Channel / Business Development, New York
http://www.securityfocus.com/archive/77/437692

51. [SJ-JOB] Account Manager, Los Angeles
http://www.securityfocus.com/archive/77/437694

52. [SJ-JOB] Jr. Security Analyst, New Castle
http://www.securityfocus.com/archive/77/437678

53. [SJ-JOB] Account Manager, San Jose
http://www.securityfocus.com/archive/77/437684

54. [SJ-JOB] Security Product Manager, Redwood Shores
http://www.securityfocus.com/archive/77/437685

55. [SJ-JOB] Account Manager, Charlotte
http://www.securityfocus.com/archive/77/437686

56. [SJ-JOB] Channel / Business Development, New York
http://www.securityfocus.com/archive/77/437680

57. [SJ-JOB] Security Engineer, Mountain View
http://www.securityfocus.com/archive/77/437687

58. [SJ-JOB] Channel / Business Development, Boston
http://www.securityfocus.com/archive/77/437691

59. [SJ-JOB] Senior Software Engineer, redwood Shores
http://www.securityfocus.com/archive/77/437674

60. [SJ-JOB] Account Manager, Redwood Shores
http://www.securityfocus.com/archive/77/437677

61. [SJ-JOB] Senior Software Engineer, Redwood Shores
http://www.securityfocus.com/archive/77/437670

62. [SJ-JOB] Software Engineer, Redwood Shores
http://www.securityfocus.com/archive/77/437673

63. [SJ-JOB] Technical Support Engineer, Redwood Shores
http://www.securityfocus.com/archive/77/437675

64. [SJ-JOB] CISO, Carson City
http://www.securityfocus.com/archive/77/437676

65. [SJ-JOB] Senior Software Engineer, Redwood Shores
http://www.securityfocus.com/archive/77/437668

66. [SJ-JOB] Quality Assurance, Redwood Shores
http://www.securityfocus.com/archive/77/437669

67. [SJ-JOB] Senior Software Engineer, Redwood Shores
http://www.securityfocus.com/archive/77/437672

68. [SJ-JOB] Quality Assurance, Redwood Shores
http://www.securityfocus.com/archive/77/437667

69. [SJ-JOB] Sr. Security Analyst, Arlington
http://www.securityfocus.com/archive/77/437632

70. [SJ-JOB] Security Researcher, Redwood Shores
http://www.securityfocus.com/archive/77/437634

71. [SJ-JOB] Jr. Security Analyst, Fort Lauderdale
http://www.securityfocus.com/archive/77/437625

72. [SJ-JOB] Security Engineer, Richmond
http://www.securityfocus.com/archive/77/437627

73. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/437628

74. [SJ-JOB] Sr. Security Analyst, Calgary
http://www.securityfocus.com/archive/77/437629

75. [SJ-JOB] Director, Information Security, San Diego
http://www.securityfocus.com/archive/77/437637

76. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/437622

77. [SJ-JOB] Security Architect, Calgary
http://www.securityfocus.com/archive/77/437623

78. [SJ-JOB] Security Consultant, philadelphia
http://www.securityfocus.com/archive/77/437626

79. [SJ-JOB] Sales Representative, Emeryville
http://www.securityfocus.com/archive/77/437621

V.   INCIDENTS LIST SUMMARY
---------------------------
1. Microsoft Excel 0-day Vulnerability FAQ document written
http://www.securityfocus.com/archive/75/437581

2. honeytrap 0.6.1 released
http://www.securityfocus.com/archive/75/437559

3. Excel zero day in the wild
http://www.securityfocus.com/archive/75/437431

4. Website Defacement
http://www.securityfocus.com/archive/75/436335

VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
1. SyScan'06 Highlight - Attacking Microsoft New Operating System (Vista)
http://www.securityfocus.com/archive/82/437752

2. SinFP 2.00 - a major release with many new features
http://www.securityfocus.com/archive/82/437337

3. Yahoo Messenger 7.0.0.438 Crash Tested
http://www.securityfocus.com/archive/82/437094

4. Black Hat Speakers + 2005 Content on-line
http://www.securityfocus.com/archive/82/437093

VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Securing an encryption key within software.
http://www.securityfocus.com/archive/88/437386

2. SecurityFocus Microsoft Newsletter #295
http://www.securityfocus.com/archive/88/437275

3. Controlling specific USB devices on Windows XP
http://www.securityfocus.com/archive/88/437076

VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to [email protected] from the subscribed address. The contents of the subject or message body do not matter. You will receive a confirmation request message to which you will have to answer. Alternatively you can also visit http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This issue is sponsored by: SPI Dynamics
ALERT: "How A Hacker Launches A Cross-Site Scripting Attack" - White Paper
Cross-site scripting vulnerabilities in web apps allow hackers to compromise confidential information, steal cookies and create requests that can be mistaken for those of a valid user!! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!

https://download.spidynamics.com/1/ad/xss.asp?Campaign_ID=70160000000CY4R