SecurityFocus Newsletter #370

Peter Laborge <[email protected]> Tue, 03 Oct 2006 16:52:43 -0600
Newsgroups gmane.comp.security.news.general
Message-ID <[email protected]>
SecurityFocus Newsletter #370
----------------------------------------

This Issue is Sponsored by: Watchfire

Methodologies & Tools for Web Application Security Assessment
With the rapid rise in the number and types of security threats, web 
application security assessments should be considered a crucial phase in 
the development of any web application. What methodology should be 
followed? What tools can accelerate the assessment process? See for 
yourself. Download this Whitepaper today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008YSf

------------------------------------------------------------------
I.    FRONT AND CENTER
        1. Recent Security Enhancements in NetBSD
        2. Beginner's guide to wireless auditing
II.   BUGTRAQ SUMMARY
        1. GnuPG Parse_Comment Remote Buffer Overflow Vulnerability
        2. Travelsized CMS Frontpage.PHP Remote File Include Vulnerability
        3. phpMyWebmin Multiple Remote File Include Vulnerabilities
        4. Yblog Multiple Cross-Site Scripting Vulnerabilities
        5. PADL Software MigtrationTools Insecure Temporary File 
Creation Vulnerability
        6. CScope Cscope.Lists Multiple Buffer Overflow Vulnerabilities
        7. PowerPortal Register User Cross-Site Scripting Vulnerability
        8. OlateDownload Multiple Input Validation Vulnerabilities
        9. PhpBB XS Multiple Remote File Include Vulnerabilities
        10. Sun Secure Global Desktop Multiple Unspecified Cross-Site 
Scripting Vulnerabilities
        11. OpenLDAP SLAPD Access Control Circumvention Vulnerability
        12. Newswriter Editfunc.inc..PHP Remote File Include Vulnerability
        13. ConPresso CMS Multiple Input Validation Vulnerabilities
        14. Mercury SiteScope Unspecified HTML Injection Vulnerability
        15. Apple Safari KHTMLParser::popOneBlock Buffer Overflow 
Vulnerability
        16. Geotarget Script.PHP Remote File Include Vulnerability
        17. Les Visiteurs Multiple Remote File Include Vulnerabilities
        18. UBB.threads Multiple Input Validation Vulnerabilities
        19. HP-UX Ignite-UX Remote Unauthorized Access and Privilege 
Escalation Vulnerabilities
        20. PHP Krazy Image Host Script Display.PHP SQL Injection 
Vulnerability
        21. Zen Cart Multiple Cross-Site Scripting Vulnerabilities
        22. PHProjekt Include Path Multiple Remote File Include 
Vulnerabilities
        23. PHPSecurePages cfpProgDir File Include Vulnerability
        24. Linux Kernel PPC970 Systems Local Denial of Service 
Vulnerability
        25. BSQ Sitestats Joomla Component Multiple Input Validation 
Vulnerabilities
        26. Linux Kernel NFS and EXT3 Combination Remote Denial of 
Service Vulnerability
        27. PHPMyProfiler Functions.PHP Remote File Include Vulnerability
        28. Klinza Professional CMS Show_Hlp.PHP Remote File Include 
Vulnerability
        29. Drupal IMCE Module Arbitrary File Deletion Vulnerability
        30. PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
        31. Novell GroupWise Messenger Server Nmma.EXE Denial of Service 
Vulnerability
        32. Linux Kernel Netfilter Conntrack_Proto_SCTP.C Denial of 
Service Vulnerability
        33. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
        34. Linux Kernel USB Driver Data Queue Local Denial of Service 
Vulnerability
        35. PostNuke Admin.PHP SQL Injection Vulnerability
        36. Jetty Directory Traversal Vulnerability
        37. Net2FTP Index.PHP Cross-Site Scripting Vulnerability
        38. HAMweather Template.PHP Script Code Injection Vulnerability
        39. JAF CMS Forum.PHP Remote File Include Vulnerability
        40. Motorola SB4200 Remote Denial of Service Vulnerability
        41. WebspotBlogging Multiple Remote File Include Vulnerabilities
        42. IBM Client Security Password Manager Design Error Vulnerability
        43. RETIRED: Mozilla Firefox Multiple Unspecified Javascript 
Vulnerabilities
        44. Microsoft WebViewFolderIcon ActiveX Control Buffer Overflow 
Vulnerability
        45. Cyrus SASL Remote Digest-MD5 Denial of Service Vulnerability
        46. Adobe Flash Player Multiple Remote Code Execution 
Vulnerabilities
        47. Macromedia Flash Malformed SWF File Multiple Vulnerabilities
        48. OpenSSL SSL_Get_Shared_Ciphers Buffer Overflow Vulnerability
        49. Apple Mac OS X Pre 10.4.8 Multiple Security Vulnerabilities
        50. OpenSSL ASN.1 Structures Denial of Service Vulnerability
        51. OpenSSL SSLv2 Null Pointer Dereference Client Denial of 
Service Vulnerability
        52. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
        53. WheatBlog Multiple HTML Injection Vulnerabilities
        54. OpenBiblio Multiple Input Validation Vulnerabilities
        55. AllMyGuests SignIn.PHP Remote File Include Vulnerability
        56. Pebble Search Functionality HTML Injection Vulnerability
        57. Multiple Vendor gethostbyname()  Buffer Overflow Vulnerability
        58. BBaCE Functions.PHP Remote File Include Vulnerability
        59. LibTIFF Next RLE Decoder Remote Heap Buffer Overflow 
Vulnerability
        60. IBM Informix Dynamic Server Installer Insecure Temporary 
File Creation Vulnerability
        61. Sunbelt Kerio Personal Firewall Multiple Local Denial of 
Service Vulnerabilities
        62. LibTIFF TiffFetchShortPair Remote Buffer Overflow Vulnerability
        63. LibTIFF EstimateStripByteCounts() Denial of Service 
Vulnerability
        64. LibTIFF Sanity Checks Multiple Denial of Service Vulnerabilities
        65. LibTIFF Library Anonymous Field Merging Denial of Service 
Vulnerability
        66. LibTIFF TiffScanLineSize Remote Buffer Overflow Vulnerability
        67. Digishop Cart.PHP Cross-Site Scripting Vulnerability
        68. LibTIFF PixarLog Decoder Remote Heap Buffer Overflow 
Vulnerability
        69. McAfee EPolicy Orchestrator and ProtectionPilot HTTP Server 
Remote Buffer Overflow Vulnerability
        70. OpenSSL Public Key Processing Denial of Service Vulnerability
        71. OpenSLP Multiple Unspecified Buffer Overflow Vulnerabilities
        72. ProRat Remote Login Authentication Bypass Vulnerability
        73. DeluxeBB Sig.PHP Remote File Include Vulnerability
        74. Loudblog Message Comment  HTML Injection Vulnerability
        75. PHP Web Scripts Easy Banner Functions.PHP Remote File 
Include Vulnerability
        76. Mozilla Firefox/Thunderbird/Seamonkey Multiple Remote 
Vulnerabilities
        77. Mozilla Firefox JavaScript Handler Race Condition Memory 
Corruption Vulnerability
        78. Mozilla Firefox Javascript Navigator Object Remote Code 
Execution Vulnerability
        79. Mozilla Foundation Products XPCOM Memory Corruption 
Vulnerability
        80. Forum82 Multiple Remote File Include Vulnerabilities
        81. Mozilla Multiple Products Remote Vulnerabilities
        82. Microsoft Indexing Service Query Validation Cross-Site 
Scripting Vulnerability
        83. BisonFTP Remote Denial Of Service Vulnerability
        84. GDB DWARF Multiple Buffer Overflow Vulnerabilities
        85. CPanel SUID Wrapper Remote Privilege Escalation Vulnerability
        86. PHP Download Download.PHP Directory Traversal Vulnerability
        87. OpenSSH Duplicated Block Remote Denial of Service Vulnerability
        88. OpenSSH SCP Shell Command Execution Vulnerability
        89. MailEnable SMTP NTLM Authentication Multiple Vulnerabilities
        90. OpenSSH Reverse DNS Lookup Access Control Bypass Vulnerability
        91. Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
        92. Apache HTTP Server Arbitrary HTTP Request Headers Security 
Weakness
        93. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
        94. VAMP Webmail Yesno.PHTML Remote File Include Vulnerability
        95. BasiliX Multiple Remote File Include Vulnerabilities
        96. Trend Micro OfficeScan ATXCONSOLE.OCX ActiveX Control Format 
String Vulnerability
        97. FFmpeg Image File Multiple Buffer Overflow Vulnerabilities
        98. SquirrelMail Compose.PHP Multiple Information Disclosure and 
Data Modification Vulnerabilities
        99. Mozilla Firefox Unspecified Javascript Remote Code Execution 
Vulnerability
        100. SiteDepth CMS Constants.PHP Remote File Include Vulnerability
III.  SECURITYFOCUS NEWS
        1. Mozilla flaws more joke than jeopardy
        2. Tag-team attack exploits IE flaw
        3. HP chief apologizes, denies he knew of hacking
        4. Web flaws race ahead in 2006
IV.   SECURITY JOBS LIST SUMMARY
        1. [SJ-JOB] Information Assurance Engineer, Clarksburg
        2. [SJ-JOB] Sr. Security Engineer, Hyderabad
        3. [SJ-JOB] Senior Software Engineer, REDWOOD CITY
        4. [SJ-JOB] Management, Charlotte
        5. [SJ-JOB] Security Engineer, Schaumburg
        6. [SJ-JOB] Software Engineer, San Francisco
        7. [SJ-JOB] Developer, Columbia
        8. [SJ-JOB] Security Engineer, Burlington
        9. [SJ-JOB] Manager, Information Security, Columbia
        10. [SJ-JOB] Senior Software Engineer, REDWOOD CITY
        11. [SJ-JOB] Security Consultant, Newport Beach
        12. [SJ-JOB] Developer, Broomfield
        13. [SJ-JOB] Information Assurance Analyst, Broomfield
        14. [SJ-JOB] Security Engineer, Broomfield
        15. [SJ-JOB] Jr. Security Analyst, LOS ANGELES
        16. [SJ-JOB] Security Consultant, berkshire
        17. [SJ-JOB] Security Architect, Broomfield
        18. [SJ-JOB] Security Engineer, berkshire
V.    INCIDENTS LIST SUMMARY
VI.   VULN-DEV RESEARCH LIST SUMMARY
VII.  MICROSOFT FOCUS LIST SUMMARY
        1. Allow regular user to unlock screensaver locked computer
        2. a question of usb token
        3. How can this happen with Windows Vista?
        4. Security Policy Anomaly
        5. SecurityFocus Microsoft Newsletter #310
        6. Microsoft Security Clamp
VIII. SUN FOCUS LIST SUMMARY
        1. LDAP in Unix
IX.   LINUX FOCUS LIST SUMMARY
X.    UNSUBSCRIBE INSTRUCTIONS
XI.   SPONSOR INFORMATION

I.   FRONT AND CENTER
---------------------
1. Recent Security Enhancements in NetBSD
By Elad Efrat
NetBSD is renowned for its focus on portability, but great care is also 
given to security. This paper presents the NetBSD philosophy on 
security, major design decisions, and its current security features. 
Following the discussion, current and future research is presented to 
provide a good look at NetBSD's direction.
http://www.securityfocus.com/infocus/1878

2. Beginner's guide to wireless auditing
By David Maynor
This article is designed as a beginner's guide to fuzzing wireless 
device drivers, starting with how to build an auditing environment, how 
to construct fuzzing tools and finally, how to interpret the results. 
This auditing environment can be used for WiFi as well as Bluetooth and 
infrared devices.
http://www.securityfocus.com/infocus/1877


II.  BUGTRAQ SUMMARY
--------------------
1. GnuPG Parse_Comment Remote Buffer Overflow Vulnerability
BugTraq ID: 19110
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19110
Summary:
GnuPG is prone to a remote buffer-overflow vulnerability because it 
fails to properly bounds-check user-supplied input before copying it to 
an insufficiently sized memory buffer.

This issue may allow remote attackers to execute arbitrary machine code 
in the context of the affected application, but this has not been confirmed.

GnuPG version 1.4.4 is vulnerable to this issue; previous versions may 
also be affected.

2. Travelsized CMS Frontpage.PHP Remote File Include Vulnerability
BugTraq ID: 20321
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20321
Summary:
Travelsized CMS is prone to a remote file-include vulnerability because 
the application fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files 
containing malicious PHP code and execute it in the context of the 
webserver process. This may allow the attacker to compromise the 
application and the underlying system; other attacks are also possible.

This issue affects version 0.4 and earlier.

3. phpMyWebmin Multiple Remote File Include Vulnerabilities
BugTraq ID: 20281
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20281
Summary:
phpMyWebmin is affected by multiple remote file-include vulnerabilities.

An attacker may leverage these issues to execute arbitrary script code 
on an affected computer with the privileges of the webserver process. 
This may potentially facilitate unauthorized access.

phpMyWebmin 1.0 and prior versions are vulnerable.

4. Yblog Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 20280
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20280
Summary:
Yblog is prone to multiple cross-site scripting vulnerabilities because 
it fails to sufficiently sanitize user-supplied input data.

An attacker may leverage these issues to have arbitrary script code 
execute in the browser of an unsuspecting user in the context of the 
affected site. This may allow the attacker to steal cookie-based 
authentication credentials and to launch other attacks.

5. PADL Software MigtrationTools Insecure Temporary File Creation 
Vulnerability
BugTraq ID: 15431
Remote: No
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/15431
Summary:
PADL Software MigrationTools creates temporary files in an insecure 
manner. An attacker with local access could potentially exploit this 
issue to obtain sensitive information in the context of the affected 
computer.

Exploitation would most likely result in loss of confidentiality or 
data. A denial of service could occur if critical files are overwritten 
in the attack. Other attacks may be possible as well.

MigrationTools version 46 is reported affected by this issue; other 
versions may also be affected.

6. CScope Cscope.Lists Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19686
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19686
Summary:
Cscope is prone to multiple buffer-overflow vulnerabilities because it 
fails to properly validate the size of attacker-supplied data before 
copying it into a finite-sized buffer.

These issues allow remote attackers to execute arbitrary machine code in 
the context of the user running the application. Failed exploit attempts 
will likely crash the application, denying service to legitimate users.

Cscope 15.x is affected by these vulnerabilities; previous versions may 
be affected as well.

7. PowerPortal Register User Cross-Site Scripting Vulnerability
BugTraq ID: 20279
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20279
Summary:
PowerPortal is prone to a cross-site scripting vulnerability because it 
fails to sufficiently sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code 
execute in the browser of an unsuspecting user in the context of the 
affected site. This may help the attacker steal cookie-based 
authentication credentials and launch other attacks.

PowerPortal 1.1 is vulnerable; other versions may also be affected.

8. OlateDownload Multiple Input Validation Vulnerabilities
BugTraq ID: 20278
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20278
Summary:
OlateDownload is prone to multiple input-validation vulnerabilities, 
including HTML-injection and SQL-injection issues, because the 
application fails to properly sanitize user-supplied input.

A successful exploit of these vulnerabilities could allow an attacker to 
inject hostile HTML and script code into vulnerable sections of the 
application, steal cookie-based authentication credentials from 
legitimate users of the site, or even exploit vulnerabilities in the 
underlying database implementation. Other attacks are also possible.

OlateDownload version 3.4.0 is vulnerable.

9. PhpBB XS Multiple Remote File Include Vulnerabilities
BugTraq ID: 20277
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20277
Summary:
phpBB XS is prone to multiple remote file-include vulnerabilities 
because it fails to sufficiently sanitize user-supplied data.

Exploiting these issues could allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

phpBB XS 0.58 and prior versions are affected by these issues.

10. Sun Secure Global Desktop Multiple Unspecified Cross-Site Scripting 
Vulnerabilities
BugTraq ID: 20276
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20276
Summary:
Sun Secure Global Desktop is prone to multiple unspecified cross-site 
scripting vulnerabilities because it fails to sufficiently sanitize 
user-supplied input data.

An attacker could exploit this vulnerability to have arbitrary script 
code execute in the context of the affected webserver. This may allow an 
attacker to steal cookie-based authentication credentials and to launch 
other attacks.

11. OpenLDAP SLAPD Access Control Circumvention Vulnerability
BugTraq ID: 19832
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19832
Summary:
OpenLDAP slapd is prone to a vulnerability that allows attackers to 
circumvent access controls.

An attacker may be able to modify any domain name regardless of the owner.

Versions prior to 2.3.25 are vulnerable.

12. Newswriter Editfunc.inc..PHP Remote File Include Vulnerability
BugTraq ID: 20237
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20237
Summary:
Newswriter is prone to a remote file-include vulnerability because it 
fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

Newswriter 1.42 and prior versions are vulnerable; other versions may 
also be affected.

13. ConPresso CMS Multiple Input Validation Vulnerabilities
BugTraq ID: 20273
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20273
Summary:
ConPresso CMS is prone to multiple input-validation vulnerabilities, 
including cross-site scripting and SQL-injection issues, because the 
application fails to properly sanitize user-supplied input.

A successful exploit of these vulnerabilities could allow an attacker to 
compromise the application, access or modify data, steal cookie-based 
authentication credentials, or even exploit vulnerabilities in the 
underlying database implementation. Other attacks are also possible.

14. Mercury SiteScope Unspecified HTML Injection Vulnerability
BugTraq ID: 20275
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20275
Summary:
Mercury SiteScope is prone to an HTML-injection vulnerability because it 
fails to sufficiently sanitize user-supplied input data.

Exploiting this issue may allow an attacker to execute HTML and script 
code in the context of the affected site, to steal cookie-based 
authentication credentials, or to control how the site is rendered to 
the user; other attacks are also possible.

Note that authenticated access to the affected application is required 
to exploit this vulnerability.

Version 8.2 is vulnerable; other versions may also be affected.

15. Apple Safari KHTMLParser::popOneBlock Buffer Overflow Vulnerability
BugTraq ID: 19250
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/19250
Summary:
Safari is prone to a buffer-overflow vulnerability. This issue is 
triggered when an attacker entices a victim user to visit a malicious 
website or to open a malicious HTML file.

A remote attacker may exploit this issue to execute arbitrary machine 
code in the context of the affected application. Failed exploit attempts 
result in crashing the application, effectively denying service to 
legitimate users.

16. Geotarget Script.PHP Remote File Include Vulnerability
BugTraq ID: 20272
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20272
Summary:
Geotarget is prone to a remote file-include vulnerability because it 
fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

17. Les Visiteurs Multiple Remote File Include Vulnerabilities
BugTraq ID: 20259
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20259
Summary:
Les Visiteurs is prone to multiple remote file-include vulnerabilities 
because it fails to sufficiently sanitize user-supplied data.

Exploiting these issues may allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

Les Visiteurs 2.0 and earlier versions are vulnerable; other versions 
may also be affected.

18. UBB.threads Multiple Input Validation Vulnerabilities
BugTraq ID: 20266
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20266
Summary:
UBB.threads is prone to multiple input-validation vulnerabilities 
because the application fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include and overwrite arbitrary 
files. These files could contain malicious PHP code and could run it in 
the context of the webserver process. This may allow the attacker to 
compromise the application and the underlying system; other attacks are 
also possible.

Version 6 (6.5.1.1) is vulnerable; other versions may also be affected.

19. HP-UX Ignite-UX Remote Unauthorized Access and Privilege Escalation 
Vulnerabilities
BugTraq ID: 20269
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20269
Summary:
HP-UX is prone to a remote unauthorized access and privilege-escalation 
vulnerabilities.

Exploiting this issue allows remote attackers to access restricted 
information or to gain administrative privileges on affected computers. 
This facilitates the complete compromise of affected computers.

Further information is currently unavailable. This BID will be updated 
as more information is disclosed.

20. PHP Krazy Image Host Script Display.PHP SQL Injection Vulnerability
BugTraq ID: 20270
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20270
Summary:
PHP Krazy Image Host Script is prone to an SQL-injection vulnerability 
because it fails to sufficiently sanitize user-supplied data before 
using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the 
application, access or modify data, or exploit latent vulnerabilities in 
the underlying database implementation.

21. Zen Cart Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 20242
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20242
Summary:
Zen Cart is prone to multiple cross-site scripting vulnerabilities 
because it fails to sufficiently sanitize user-supplied input data.

An attacker may leverage these issues to have arbitrary script code 
execute in the browser of an unsuspecting user in the context of the 
affected site. This may allow the attacker to steal cookie-based 
authentication credentials and to launch other attacks.

Zen Cart 1.3.5 is vulnerable to these issues.

22. PHProjekt Include Path Multiple Remote File Include Vulnerabilities
BugTraq ID: 20268
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20268
Summary:
Multiple remote file-include vulnerabilities affect PHProjekt because 
the application fails to properly sanitize user-supplied input before 
using it in a PHP 'include()' function call.

An attacker may leverage these issues to execute arbitrary server-side 
script code on an affected computer with the privileges of the webserver 
process.

Version 5.1.1 of PHProjekt is vulnerable to these issues; previous 
versions may be affected as well.

23. PHPSecurePages cfpProgDir File Include Vulnerability
BugTraq ID: 14201
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/14201
Summary:
phpSecurePages is prone to a remote file-include vulnerability because 
the application fails to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary server-side 
script code on an affected computer with the privileges of the webserver 
process. This may facilitate unauthorized access.

This issue affects PHPSecurePages 0.28beta; earlier versions may also be 
vulnerable.

24. Linux Kernel PPC970 Systems Local Denial of Service Vulnerability
BugTraq ID: 19615
Remote: No
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/19615
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability.

An attacker can exploit this issue to crash the kernel, denying further 
service to legitimate users.

25. BSQ Sitestats Joomla Component Multiple Input Validation Vulnerabilities
BugTraq ID: 20267
Remote: Yes
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/20267
Summary:
BSQ Sitestats is prone to multiple input-validation vulnerabilities 
because it fails to sufficiently sanitize user-supplied data.

Exploiting these issues may allow an attacker to steal cookie-based 
authentication credentials, compromise the application, access or modify 
data, or exploit latent vulnerabilities in the underlying database 
implementation; other attacks are possible.

Version 1.8.0 is vulnerable; other versions may also be affected.

26. Linux Kernel NFS and EXT3 Combination Remote Denial of Service 
Vulnerability
BugTraq ID: 19396
Remote: No
Last Updated: 2006-09-29
Relevant URL: http://www.securityfocus.com/bid/19396
Summary:
The Linux kernel is susceptible to a remote denial-of-service 
vulnerability because the EXT3 filesystem code fails to properly handle 
unexpected conditions.

Remote attackers may trigger this issue by sending crafted UDP datagrams 
to affected computers that are configured as NFS servers, causing 
filesystem errors. Depending on the mount-time options of affected 
filesystems, this may result in remounting filesystems as read-only or 
cause a kernel panic.

Linux kernel versions 2.6.14.4, 2.6.17.6, and 2.6.17.7 are vulnerable to 
this issue; other versions in the 2.6 series are also likely affected.

27. PHPMyProfiler Functions.PHP Remote File Include Vulnerability
BugTraq ID: 20324
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20324
Summary:
phpMyProfiler is prone to a remote file-include vulnerability because 
the application fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files 
containing malicious PHP code and execute it in the context of the 
webserver process. This may allow the attacker to compromise the 
application and the underlying system; other attacks are also possible.

phpMyProfiler version 0.9.6 is vulnerable; other versions may also be 
affected.

28. Klinza Professional CMS Show_Hlp.PHP Remote File Include Vulnerability
BugTraq ID: 20323
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20323
Summary:
Klinza Professional CMS is prone to a remote file-include vulnerability 
because it fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

Klinza 5.0.1 and prior versions are vulnerable; other versions may also 
be affected.

29. Drupal IMCE Module Arbitrary File Deletion Vulnerability
BugTraq ID: 20312
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20312
Summary:
The Drupal IMCE module is prone to an arbitrary file-deletion 
vulnerability because the application fails to sufficiently sanitize 
user-supplied input.

Successfully exploiting this issue allows attackers to delete arbitrary 
files with the privileges of the targeted webserver process.

30. PHPMyAdmin Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 20253
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20253
Summary:
phpMyAdmin is prone to multiple cross-site scripting vulnerabilities.

An attacker may leverage this issue to have arbitrary script code 
execute in the browser of an unsuspecting user in the context of the 
affected site. This may help the attacker steal cookie-based 
authentication credentials and launch other attacks.

31. Novell GroupWise Messenger Server Nmma.EXE Denial of Service 
Vulnerability
BugTraq ID: 20316
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20316
Summary:
Novell GroupWise Messenger server is prone to a denial-of-service 
vulnerability that occurs when the application fails to handle a client 
request with an unexpected parameter.

An attacker may exploit this issue to crash the vulnerable application, 
denying further service to legitimate users.

32. Linux Kernel Netfilter Conntrack_Proto_SCTP.C Denial of Service 
Vulnerability
BugTraq ID: 18755
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/18755
Summary:
The Linux kernel 'netfilter' module is prone to a denial-of-service 
vulnerability.

Successful exploits of this vulnerability will cause the kernel to 
crash, effectively denying service to legitimate users.

33. Linux Kernel CD-ROM Driver Local Buffer Overflow Vulnerability
BugTraq ID: 18847
Remote: No
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/18847
Summary:
The Linux kernel is prone to a local buffer-overflow vulnerability 
because it fails to properly bounds-check user-supplied input before 
using it in a memory copy operation.

This issue allows local attackers to overwrite kernel memory with 
arbitrary data, potentially allowing them to execute malicious machine 
code in the context of affected kernels. This vulnerability facilitates 
the complete compromise of affected computers.

Linux kernel version 2.6.17.3 and prior are affected by this issue.

34. Linux Kernel USB Driver Data Queue Local Denial of Service Vulnerability
BugTraq ID: 19033
Remote: No
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19033
Summary:
The Linux kernel is prone to a local denial-of-service vulnerability. 
This issue is due to a design error in the USB FTDI SIO driver.

This vulnerability allows local users to consume all available memory 
resources, denying further service to legitimate users.

This issue affects Linux kernel versions prior to 2.6.16.27.

35. PostNuke Admin.PHP SQL Injection Vulnerability
BugTraq ID: 20317
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20317
Summary:
PostNuke is prone to an SQL-injection vulnerability because it fails to 
sufficiently sanitize user-supplied data before using it in an SQL query.

Exploiting this issue could allow an attacker to compromise the 
application, access or modify data, or exploit latent vulnerabilities in 
the underlying database implementation.

Version 0.762 is vulnerable; other versions may also be affected.

36. Jetty Directory Traversal Vulnerability
BugTraq ID: 11330
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/11330
Summary:
Jetty is reported prone to a directory-traversal vulnerability because 
the application fails to properly sanitize HTTP-request URIs.

Exploiting this vulnerability allows remote attackers to retrieve the 
contents of arbitrary, potentially sensitive files located on the 
serving computer with the credentials of the affected process.

It is unclear at this time exactly which versions of Jetty are affected 
by this vulnerability. This BID will be updated as further information 
is disclosed.

This vulnerability may be related to BID 4360.

37. Net2FTP Index.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 20313
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20313
Summary:
The net2ftp program is prone to a cross-site scripting vulnerability 
because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to have arbitrary script code execute 
in the browser of an unsuspecting user in the context of the affected 
site. This may help the attacker steal cookie-based authentication 
credentials and launch other attacks.

This issue affects version 0.93; other versions may also be vulnerable.

38. HAMweather Template.PHP Script Code Injection Vulnerability
BugTraq ID: 20311
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20311
Summary:
HAMweather is prone to a script-code-injection vulnerability because it 
fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

HAMweather 3.9.8.4 and prior versions are vulnerable; other versions may 
also be affected.

39. JAF CMS Forum.PHP Remote File Include Vulnerability
BugTraq ID: 20310
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20310
Summary:
JAF CMS is prone to a remote file-include vulnerability because the 
application fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files 
containing malicious PHP code and execute it in the context of the 
webserver process. This may allow the attacker to compromise the 
application and the underlying system; other attacks are also possible.

This issue affects version 4.0 and earlier.

40. Motorola SB4200 Remote Denial of Service Vulnerability
BugTraq ID: 20309
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20309
Summary:
Motorola SB4200 is prone to a remote denial-of-service vulnerability.

This may permit an attacker to crash affected devices, denying further 
network services to legitimate users.

41. WebspotBlogging Multiple Remote File Include Vulnerabilities
BugTraq ID: 18260
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/18260
Summary:
WebspotBlogging is prone to multiple remote file-include vulnerabilities 
because the application fails to properly sanitize user-supplied input.

An attacker can exploit these issues to include arbitrary remote files 
containing malicious PHP code and execute it in the context of the 
webserver process. This may allow the attacker to compromise the 
application and the underlying system; other attacks are also possible.

42. IBM Client Security Password Manager Design Error Vulnerability
BugTraq ID: 20308
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20308
Summary:
IBM Client Security Password Manager is prone to a design error that 
degrades the integrity of client-side web security.

The vulnerability stems from the fact that the Password Manager relies 
on 'Window Title' information as part of the authentication routine it 
performs on behalf of the user. A malicious website can establish a web 
page that spoofs the same window title that the application expects to 
map. This will allow authentication to proceed with the hostile site and 
in turn establish a false sense of security on the part of visitors who 
use the affected software.

Exploiting this issue can help attackers steal user credentials. Other 
attacks are also possible.

43. RETIRED: Mozilla Firefox Multiple Unspecified Javascript Vulnerabilities
BugTraq ID: 20294
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20294
Summary:
Mozilla Firefox is prone to multiple unspecified JavaScript 
vulnerabilities because the application fails to properly sanitize 
user-supplied input before using it to create new JavaScript objects.

Successful exploits may allow an attacker to crash the application or 
execute arbitrary machine code in the context of the affected application.

Reportedly, about 30 undisclosed flaws exist.

Update (October 3, 2006): This BID is being retired because reports 
indicate that these issues are a hoax. The researchers responsible for 
disclosing these vulnerabilities have claimed that their original 
reports were incorrect. A remote denial-of-service vulnerability may 
possibly affect the browser, but this has not been confirmed. A new BID 
will be created if subsequent reports confirm the possibility of the 
potential denial-of-service issue. Please see the references for more 
information.

44. Microsoft WebViewFolderIcon ActiveX Control Buffer Overflow 
Vulnerability
BugTraq ID: 19030
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19030
Summary:
Microsoft WebViewFolderIcon ActiveX control is prone to a 
buffer-overflow vulnerability.

This issue is triggered when an attacker convinces a victim user to 
visit a malicious website.

Remote attackers may exploit this issue to execute arbitrary machine 
code in the context of the affected application, facilitating the remote 
compromise of affected computers. Failed exploit attempts likely result 
in browser crashes.

45. Cyrus SASL Remote Digest-MD5 Denial of Service Vulnerability
BugTraq ID: 17446
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/17446
Summary:
Cyrus SASL is affected by a remote denial-of-service vulnerability. This 
issue occurs before successful authentication, allowing anonymous remote 
attackers to trigger it.

This vulnerability allows remote attackers to crash services using the 
affected SASL library, denying service to legitimate users.

This issue reportedly affects version 2.1.18 of Cyrus SASL; other 
versions may also be affected.

46. Adobe Flash Player Multiple Remote Code Execution Vulnerabilities
BugTraq ID: 19980
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19980
Summary:
Adobe Flash Player is prone to multiple remote code-execution 
vulnerabilities because it fails to properly sanitize user-supplied input.

An attacker could exploit this issue by creating a media file containing 
large, dynamically generated string data and submitting it to be 
processed by the media player.

These issues allow remote attackers to execute arbitrary machine code in 
the context of the user running the application. Other attacks are also 
possible.

Adobe Flash Player 8.0.24.0 and prior, Adobe Flash Professional 8, Flash 
Basic, Adobe Flash MX, and 2004Adobe Flex 1.5 are affected.

47. Macromedia Flash Malformed SWF File Multiple Vulnerabilities
BugTraq ID: 18894
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/18894
Summary:
The Macromedia Flash plug-in is prone to multiple remote vulnerabilities.

An attacker can exploit these vulnerabilities to execute arbitrary code 
or to crash the application hosting the Flash player (typically a web 
browser). Attackers exploit these issues through maliciously malformed 
SWF files that have been placed on a website or emailed to unsuspecting 
users.

Version 8.0.24.0 of Flash is vulnerable to these issues; other versions 
may also be affected.

48. OpenSSL SSL_Get_Shared_Ciphers Buffer Overflow Vulnerability
BugTraq ID: 20249
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20249
Summary:
OpenSSL is prone to a buffer-overflow vulnerability because the library 
fails to properly bounds-check user-supplied input before copying it to 
an insufficiently sized memory buffer.

Successfully exploiting this issue may result in the execution of 
arbitrary machine code in the context of applications that use the 
affected library. Failed exploit attempts may crash applications, 
denying service to legitimate users.

49. Apple Mac OS X Pre 10.4.8 Multiple Security Vulnerabilities
BugTraq ID: 20271
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20271
Summary:
Apple Mac OS X is prone to multiple security vulnerabilities.

These issue affect Mac OS X and various applications including 
CFNetwork, Safari, Kernel, ImageIO, LoginWindow, System Preferences, 
QuickDraw Manager, and Workgroup Manager. An attacker can exploit these 
issues to execute arbitrary code, gain elevated privileges, cause 
denial-of-service conditions, and gain unauthorized access.

Apple Mac OS X versions prior to 10.4.8 are vulnerable to these issues.

50. OpenSSL ASN.1 Structures Denial of Service Vulnerability
BugTraq ID: 20248
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20248
Summary:
OpenSSL is prone to a denial-of-service vulnerability.

  An attacker may exploit this issue to cause applications that use the 
vulnerable library to consume excessive CPU and memory resources and 
crash, denying further service to legitimate users.

51. OpenSSL SSLv2 Null Pointer Dereference Client Denial of Service 
Vulnerability
BugTraq ID: 20246
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20246
Summary:
OpenSSL is prone to a denial-of-service vulnerability.

A malicious server could cause a vulnerable client application to crash, 
effectively denying service.

52. OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
BugTraq ID: 19849
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19849
Summary:
OpenSSL is prone to a vulnerability that may allow an attacker to forge 
an RSA signature. The attacker may be able to forge a PKCS #1 v1.5 
signature when an RSA key with exponent 3 is used.

An attacker may exploit this issue to sign digital certificates or RSA 
keys and take advantage of trust relationships that depend on these 
credentials, possibly posing as a trusted party and signing a 
certificate or key.

All versions of OpenSSL prior to and including 0.9.7j and 0.9.8b are 
affected by this vulnerability. Updates are available.

53. WheatBlog Multiple HTML Injection Vulnerabilities
BugTraq ID: 20306
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20306
Summary:
WheatBlog is prone to multiple HTML-injection vulnerabilities because 
the application fails to properly sanitize user-supplied input before 
using it in dynamically generated content.

Attacker-supplied HTML and script code would execute in the context of 
the affected website, potentially allowing an attacker to steal 
cookie-based authentication credentials or to control how the site is 
rendered to the user; other attacks are also possible.

54. OpenBiblio Multiple Input Validation Vulnerabilities
BugTraq ID: 20301
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20301
Summary:
OpenBiblio is prone to multiple input-validation vulnerabilities because 
the application fails to sufficiently sanitize user-supplied input. 
These include multiple local file-include vulnerabilties and an 
SQL-injection vulnerability.

A successful exploit may allow an attacker to compromise the 
application, access sensitive information, modify data, or exploit 
latent vulnerabilities in the underlying database implementation.

55. AllMyGuests SignIn.PHP Remote File Include Vulnerability
BugTraq ID: 20303
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20303
Summary:
AllMyGuests is prone to a remote file-include vulnerability because it 
fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

AllMyGuests 0.4.1 is vulnerable; other versions may also be affected.

56. Pebble Search Functionality HTML Injection Vulnerability
BugTraq ID: 20298
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20298
Summary:
Pebble is prone to an HTML-injection vulnerability because the 
application fails to properly sanitize user-supplied input before using 
it in dynamically generated content.

Attacker-supplied HTML and script code would execute in the context of 
the affected website, potentially allowing an attacker to steal 
cookie-based authentication credentials or to control how the site is 
rendered to the user; other attacks are also possible.

57. Multiple Vendor gethostbyname()  Buffer Overflow Vulnerability
BugTraq ID: 6853
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/6853
Summary:
A vulnerability has been discovered in multiple vendor implementations 
of the 'gethostbyname()' library function, which is used to resolve 
network addresses.

The 'gethostbyname()' function fails to implement sufficient bounds 
checking on data copied into local memory buffers.

Under some circumstances, attackers may exploit this issue to overwrite 
sensitive locations in memory and may leverage the issue to execute 
arbitrary commands with the privileges of the vulnerable application. 
This issue may be local or remote, depending on the particular 
applications that use the function on vulnerable systems.

Several applications may implement the 'gethostbyname()' function, thus 
exposing them to this vulnerability. Applications known to implement 
'gethostbyname()' include various implementations of 'ping', 'ftp', and 
'tftp'. Other applications may also be vulnerable.

58. BBaCE Functions.PHP Remote File Include Vulnerability
BugTraq ID: 20302
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20302
Summary:
BBaCE is prone to a remote file-include vulnerability because the 
application fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files 
containing malicious PHP code and execute it in the context of the 
webserver process. This may allow the attacker to compromise the 
application and the underlying system; other attacks are also possible.

This issue affects version 3; other versions may also be vulnerable.

59. LibTIFF Next RLE Decoder Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19282
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19282
Summary:
The Next RLE Decoder for libTIFF is prone to a remote heap 
buffer-overflow vulnerability.

This issue occurs because the application fails to check boundary 
conditions on certain RLE decoding operations.

This issue may allow attackers to execute arbitrary machine code within 
the context of the vulnerable application or to cause a denial of service.

60. IBM Informix Dynamic Server Installer Insecure Temporary File 
Creation Vulnerability
BugTraq ID: 20300
Remote: No
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20300
Summary:
The installation process for IBM Informix Dynamic Server creates 
temporary files in an insecure manner.

An attacker with local access could potentially exploit this issue to 
perform symlink attacks, overwriting arbitrary files in the context of 
the affected application.

Successfully exploiting a symlink attack may allow an attacker to 
overwrite or corrupt sensitive files. This may result in a denial of 
service; other attacks may also be possible.

IBM Informix Dynamic Server version 10.0 is vulnerable; other versions 
may also be affected.

61. Sunbelt Kerio Personal Firewall Multiple Local Denial of Service 
Vulnerabilities
BugTraq ID: 20299
Remote: No
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20299
Summary:
Sunbelt Kerio Personal Firewall is prone to multiple local 
denial-of-service vulnerabilities because the application fails to 
properly sanitize user-supplied input.

These vulnerabilities allow local attackers to crash affected systems, 
facilitating a denial-of-service condition on the local computer. Code 
execution may also be possible, but this has not been confirmed.

62. LibTIFF TiffFetchShortPair Remote Buffer Overflow Vulnerability
BugTraq ID: 19283
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19283
Summary:
LibTIFF is prone to a buffer-overflow vulnerability because the library 
fails to do proper boundary checks before copying user-supplied data 
into a finite-sized buffer.

This issue allows remote attackers to execute arbitrary machine code in 
the context of appications using the affected library. Failed exploit 
attempts will likely crash the application, denying service to 
legitimate users.

63. LibTIFF EstimateStripByteCounts() Denial of Service Vulnerability
BugTraq ID: 19284
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19284
Summary:
LibTIFF is affected by a denial-of-service vulnerability.

An attacker can exploit this vulnerability to cause a denial of service 
in applications using the affected library.

64. LibTIFF Sanity Checks Multiple Denial of Service Vulnerabilities
BugTraq ID: 19286
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19286
Summary:
LibTIFF is affected by multiple denial-of-service vulnerabilities.

An attacker can exploit these vulnerabilities to cause a denial of 
service in applications using the affected library.

65. LibTIFF Library Anonymous Field Merging Denial of Service Vulnerability
BugTraq ID: 19287
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19287
Summary:
The libTIFF library is prone to a denial-of-service vulnerability.

An attacker can exploit this issue by submitting malformed image files.

When the libTIFF library routines process a malicious TIFF file, this 
could result in abnormal behavior, cause the application to become 
unresponsive, or possibly allow malicious code to execute.

66. LibTIFF TiffScanLineSize Remote Buffer Overflow Vulnerability
BugTraq ID: 19288
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/19288
Summary:
LibTIFF is prone to a buffer-overflow vulnerability because the library 
fails to do proper boundary checks before copying user-supplied data 
into a finite-sized buffer.

This issue allows remote attackers to execute arbitrary machine code in 
the context of applications using the affected library. Failed exploit 
attempts will likely crash the application, denying service to 
legitimate users.

67. Digishop Cart.PHP Cross-Site Scripting Vulnerability
BugTraq ID: 20297
Remote: Yes
Last Updated: 2006-10-03
Relevant URL: http://www.securityfocus.com/bid/20297
Summary:
digiSHOP is prone to a cross-site scripting vulnerability because it 
fails to properly sanitize user-supplied input.

An attacker can exploit this issue to have arbitrary script code execute 
in the browser of an unsuspecting user in the context of the affected 
site. This may help the attacker steal cookie-based authentication 
credentials and launch other attacks.

This issue affects version 4.0.0; other versions may also be vulnerable.

68. LibTIFF PixarLog Decoder Remote Heap Buffer Overflow Vulnerability
BugTraq ID: 19290
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19290
Summary:
The PixarLog Decoder for libTIFF is prone to a remote heap 
buffer-overflow vulnerability.

This issue may allow attackers to execute arbitrary machine code within 
the context of the vulnerable application or to cause a denial-of-service.

69. McAfee EPolicy Orchestrator and ProtectionPilot HTTP Server Remote 
Buffer Overflow Vulnerability
BugTraq ID: 20288
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20288
Summary:
The HTTP server component of McAfee ePolicy Orchestrator and 
ProtectionPilot is prone to a remote stack-based buffer-overflow 
vulnerability that can lead to complete system compromise.

This issue arises because the application fails to perform boundary 
checks before copying user-supplied data into sensitive process buffers.

A successful attack may result in arbitrary code execution with SYSTEM 
privileges, leading to a full compromise.

McAfee ePolicy Orchestrator 3.5.0 patch 5 and prior versions as well as 
ProtectionPilot 1.1.1 patch 2 and prior versions are vulnerable to this 
issue.

70. OpenSSL Public Key Processing Denial of Service Vulnerability
BugTraq ID: 20247
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20247
Summary:
OpenSSL is prone to a denial-of-service vulnerability. This issue is due 
to a lack of validation of the lengths of public keys being used.

An attacker can exploit this issue to crash an affected server using 
OpenSSL.

71. OpenSLP Multiple Unspecified Buffer Overflow Vulnerabilities
BugTraq ID: 12792
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/12792
Summary:
OpenSLP is prone to multiple unspecified buffer-overflow vulnerabilities 
that may be triggered by malformed SLP (Service Location Protocol) packets.

If successfully exploited, these issues could allow remote code 
execution in the context of the software.

72. ProRat Remote Login Authentication Bypass Vulnerability
BugTraq ID: 20293
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20293
Summary:
ProRat is prone to an authentication-bypass vulnerability.

An attacker can exploit this issue to gain remote access to computers 
running this application. A successful exploit will lead to the complete 
compromise of affected computers.

73. DeluxeBB Sig.PHP Remote File Include Vulnerability
BugTraq ID: 20292
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20292
Summary:
DeluxeBB is prone to a remote file-include vulnerability because the 
application fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include arbitrary remote files 
containing malicious PHP code and execute it in the context of the 
webserver process. This may allow the attacker to compromise the 
application and the underlying system; other attacks are also possible.

This issue affects version 1.09; other versions may also be vulnerable.

74. Loudblog Message Comment  HTML Injection Vulnerability
BugTraq ID: 20296
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20296
Summary:
Loudblog is prone to an unspecified HTML-injection vulnerability because 
the application fails to properly sanitize user-supplied input before 
using it in dynamically generated content.

Attacker-supplied HTML and script code would execute in the context of 
the affected website, potentially allowing an attacker to steal 
cookie-based authentication credentials or to control how the site is 
rendered to the user; other attacks are also possible.

75. PHP Web Scripts Easy Banner Functions.PHP Remote File Include 
Vulnerability
BugTraq ID: 20295
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20295
Summary:
Easy Banner is prone to a remote file-include vulnerability because it 
fails to sufficiently sanitize user-supplied data.

Exploiting this issue may allow an attacker to compromise the 
application and the underlying system; other attacks are also possible.

Easy Banner Free is vulnerable; other versions may also be affected.

76. Mozilla Firefox/Thunderbird/Seamonkey Multiple Remote Vulnerabilities
BugTraq ID: 20042
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20042
Summary:
The Mozilla Foundation has released six security advisories specifying 
vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary code
- perform cross-site scripting attacks
- supply malicious data through updates
- inject arbitrary content
- execute arbitrary JavaScript
- crash affected applications and potentially execute arbitrary code.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as more 
information becomes available.

These issues are fixed in:

- Mozilla Firefox version 1.5.0.7
- Mozilla Thunderbird version 1.5.0.7
- Mozilla SeaMonkey version 1.0.5

77. Mozilla Firefox JavaScript Handler Race Condition Memory Corruption 
Vulnerability
BugTraq ID: 19488
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19488
Summary:
Mozilla Firefox is prone to a remote memory-corruption vulnerability. 
This issue is due to a race condition that may result in double-free or 
other memory-corruption issues.

Attackers may likely exploit this issue to execute arbitrary machine 
code in the context of the vulnerable application, but this has not been 
confirmed. Failed exploit attempts will likely crash the application.

Mozilla Firefox is vulnerable to this issue. Due to code-reuse, other 
Mozilla products are also likely affected.

78. Mozilla Firefox Javascript Navigator Object Remote Code Execution 
Vulnerability
BugTraq ID: 19192
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19192
Summary:
Mozilla Firefox is prone to a remote code-execution vulnerability 
because the application fails to properly sanitize user-supplied input 
before using it to create new JavaScript objects.

Successful exploits may allow an attacker to crash the application or 
execute arbitrary machine code in the context of the affected application.

This issue was previously discussed in BID 19181 (Mozilla Multiple 
Products Remote Vulnerabilities).
It has been assigned a separate BID because new information has become 
available.

79. Mozilla Foundation Products XPCOM Memory Corruption Vulnerability
BugTraq ID: 19197
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19197
Summary:
Various Mozilla Foundation products are prone to a memory-corruption 
vulnerability.

This issue occurs because the applications fail to handle simultaneous 
XPCOM events that would cause the deletion of the timer object.

An attacker can exploit this issue to execute arbitrary code.

This issue was previously discussed in BID 19181 (Mozilla Multiple 
Products Remote Vulnerabilities). It has been assigned a separate BID 
because new information has become available.

80. Forum82 Multiple Remote File Include Vulnerabilities
BugTraq ID: 20291
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20291
Summary:
Forum82 is prone to multiple remote file-include vulnerabilities because 
it fails to sufficiently sanitize user-supplied data.

This may allow an attacker to compromise the application and the 
underlying system; other attacks are also possible.

Forum82 2.5.2 and prior versions are vulnerable; other versions may also 
be affected.

81. Mozilla Multiple Products Remote Vulnerabilities
BugTraq ID: 19181
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19181
Summary:
The Mozilla Foundation has released thirteen security advisories 
specifying vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird.

These vulnerabilities allow attackers to:

- execute arbitrary machine code in the context of the vulnerable 
application
- crash affected applications
- run arbitrary script code with elevated privileges
- gain access to potentially sensitive information
- carry out cross-domain scripting attacks.

Other attacks may also be possible.

The issues described here will be split into individual BIDs as more 
information becomes available.

These issues are fixed in:

- Mozilla Firefox version 1.5.0.5
- Mozilla Thunderbird version 1.5.0.5
- Mozilla SeaMonkey version 1.0.3

82. Microsoft Indexing Service Query Validation Cross-Site Scripting 
Vulnerability
BugTraq ID: 19927
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19927
Summary:
Microsoft Indexing Service is prone to a cross-site scripting 
vulnerability because the application fails to properly sanitize 
user-supplied input before it is rendered to other users.

An attacker may leverage this issue to have arbitrary script code 
execute in the browser of an unsuspecting user, in the context of the 
victim's session. This could allow the attacker to perform actions on 
behalf of the victim, such as spoofing content or hijacking their session.

Microsoft Indexing Service is not installed or enabled by default. Even 
if installed, it is not accessible from Internet Information Services 
(IIS). This vulnerability affects only systems that have IIS and 
Indexing Service installed and that have the Indexing Service configured 
to be accessible from IIS through a web-based interface.

83. BisonFTP Remote Denial Of Service Vulnerability
BugTraq ID: 14079
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/14079
Summary:
BisonFTP is prone to a remote denial-of-service vulnerability. A remote 
attacker may exploit this issue to deny service for legitimate users.

Reports indicate that the issue may be exploited only after successful 
authentication.

84. GDB DWARF Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 19802
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19802
Summary:
GDB is prone to multiple buffer-overflow vulnerabilities because of 
insufficient bounds checking when handling DWARF and DWARF2 data.

Attackers could leverage this issue to run arbitrary code outside of a 
restricted environment; this may lead to privilege escalation.

85. CPanel SUID Wrapper Remote Privilege Escalation Vulnerability
BugTraq ID: 20163
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20163
Summary:
cPanel is prone to a remote privilege-escalation vulnerability.

A remote attacker can exploit this issue to gain administrative access 
to the affected application. This may lead to other attacks.

86. PHP Download Download.PHP Directory Traversal Vulnerability
BugTraq ID: 19872
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19872
Summary:
Php download is prone to a directory-traversal vulnerability because it 
fails to properly sanitize user-supplied input.

An attacker can exploit this vulnerability to retrieve arbitrary files 
from the vulnerable system in the context of the affected application. 
Information obtained may aid in further attacks.

The vendor reports that exploitability of this issue is limited to text 
files only.

87. OpenSSH Duplicated Block Remote Denial of Service Vulnerability
BugTraq ID: 20216
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20216
Summary:
OpenSSH is prone to a remote denial-of-service vulnerability because it 
fails to properly handle incoming duplicate blocks.

Remote attackers may exploit this issue to consume excessive CPU 
resources, potentially denying service to legitimate users.

This issue occurs only when OpenSSH is configured to accept SSH Version 
One traffic.

88. OpenSSH SCP Shell Command Execution Vulnerability
BugTraq ID: 16369
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/16369
Summary:
OpenSSH is prone to an SCP shell command-execution vulnerability because 
the application fails to properly sanitize user-supplied input before 
using it in a 'system()' function call.

This issue allows attackers to execute arbitrary shell commands with the 
privileges of users executing a vulnerable version of SCP.

This issue reportedly affects version 4.2 of OpenSSH. Other versions may 
also be affected.

89. MailEnable SMTP NTLM Authentication Multiple Vulnerabilities
BugTraq ID: 20290
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20290
Summary:
MailEnable is prone to multiple remote vulnerabilities.

These issues arise in the SMTP server during NTLM authentication and may 
facilitate arbitrary code execution or denial-of-service conditions.

MailEnable Professional 2.0 and MailEnable Enterprise 2.0 are reported 
vulnerable to these issues.

90. OpenSSH Reverse DNS Lookup Access Control Bypass Vulnerability
BugTraq ID: 7831
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/7831
Summary:
A vulnerability has been reported for OpenSSH that may allow 
unauthorized access to an OpenSSH server's login mechanism.

The vulnerability occurs because of the way OpenSSH restricts access. 
It's possible to configure OpenSSH to restrict access based on certain 
patterns. When a numeric IP address is provided as the host that is 
attempting a connection, an attacker can trick the OpenSSH server to 
allow access.

91. Portable OpenSSH GSSAPI Remote Code Execution Vulnerability
BugTraq ID: 20241
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20241
Summary:
Portable OpenSSH is prone to a remote code-execution vulnerability. The 
issue derives from a race condition in a vulnerable signal handler.

Reportedly, under specific conditions, it is theoretically possible to 
execute code remotely prior to authentication when GSSAPI authentication 
is enabled. This has not been confirmed; the chance of a successful 
exploit of this nature is considered minimal.

On non-Portable OpenSSH implementations, this same race condition can be 
exploited to cause a pre-authentication denial of service.

This issue occurs when OpenSSH and Portable OpenSSH are configured to 
accept GSSAPI authentication.

92. Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
BugTraq ID: 19661
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19661
Summary:
Apache HTTP server is prone to an HTTP request header security weakness.

An attacker may exploit this issue to  steal cookie-based authentication 
credentials and launch other attacks.

93. Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability
BugTraq ID: 15834
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/15834
Summary:
Apache's mod_imap module is prone to a cross-site scripting 
vulnerability. This issue is due to the module's failure to properly 
sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code 
executed in the browser of an unsuspecting user in the context of the 
affected site. This may facilitate the theft of cookie-based 
authentication credentials as well as other attacks.

94. VAMP Webmail Yesno.PHTML Remote File Include Vulnerability
BugTraq ID: 20289
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20289
Summary:
VAMP Webmail is prone to a remote file-include vulnerability because it 
fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file 
containing malicious PHP code and execute it in the context of the 
webserver process. This may facilitate a compromise of the application 
and the underlying system; other attacks are also possible.

VAMP Webmail 2.0beta1 and prior versions are vulnerable to this issue.

95. BasiliX Multiple Remote File Include Vulnerabilities
BugTraq ID: 20287
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20287
Summary:
BasiliX is affected by multiple remote file-include vulnerabilities.

An attacker may leverage these issues to execute arbitrary script code 
on an affected computer with the privileges of the webserver process. 
This may potentially facilitate unauthorized access.

BasiliX version 1.1.1 is reported vulnerable. Other versions may be 
affected as well.

96. Trend Micro OfficeScan ATXCONSOLE.OCX ActiveX Control Format String 
Vulnerability
BugTraq ID: 20284
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20284
Summary:
Trend Micro OfficeScan is prone to a remote format-string vulnerability. 
This vulnerability requires a certain amount of user-interaction for an 
attack to occur, such as visiting a malicious website. A successful 
exploit would let a remote attacker execute code with the privileges of 
the currently logged-in user.

Trend Micro OfficeScan Corporate Edition 7.3 is reported vulnerable. 
Other versions may be affected as well.

97. FFmpeg Image File Multiple Buffer Overflow Vulnerabilities
BugTraq ID: 20009
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20009
Summary:
FFmpeg is prone to multiple remote buffer-overflow vulnerabilities 
because the application using this library fails to properly 
bounds-check user-supplied input before copying it to an insufficiently 
sized memory buffer.

These issues allow attackers to execute arbitrary machine code within 
the context of the affected application.

Versions prior to 0.4.9_p20060530 are vulnerable to this issue.

98. SquirrelMail Compose.PHP Multiple Information Disclosure and Data 
Modification Vulnerabilities
BugTraq ID: 19486
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19486
Summary:
SquirrelMail is prone to multiple information-disclosure and 
data-modification vulnerabilities because the application fails to 
properly sanitize user-supplied input.

Successful exploits may allow an authenticated remote attacker to read 
and write email attachments or preferences from other users. This may 
lead to other attacks.

99. Mozilla Firefox Unspecified Javascript Remote Code Execution 
Vulnerability
BugTraq ID: 20282
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/20282
Summary:
Mozilla Firefox is prone to a remote code-execution vulnerability 
because the application fails to properly sanitize user-supplied input 
before using it to create new JavaScript objects.

Successful exploits may allow an attacker to crash the application or 
execute arbitrary machine code in the context of the affected application.

Details regarding this vulnerability are not currently available; this 
BID will be updated when more information becomes available.

100. SiteDepth CMS Constants.PHP Remote File Include Vulnerability
BugTraq ID: 19094
Remote: Yes
Last Updated: 2006-10-02
Relevant URL: http://www.securityfocus.com/bid/19094
Summary:
SiteDepth CMS is prone to a remote file-include vulnerability because it 
fails to properly sanitize user-supplied input.

An attacker can exploit this issue to include an arbitrary remote file 
containing malicious PHP code and execute it in the context of the 
webserver process. This may facilitate a compromise of the application 
and the underlying system; other attacks are also possible.

SiteDepth CMS 3.01 and prior versions are vulnerable to this issue.

III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Mozilla flaws more joke than jeopardy
By: Robert Lemos
Two ToorCon presenters razz the open-source browser group for an alleged 
flawed implementation of Javascript, but the lecture appears to be more 
stand-up comedy than  substantiative research.
http://www.securityfocus.com/news/11416

2. Tag-team attack exploits IE flaw
By: Robert Lemos
Attackers exploit a zero-day vulnerability to cause a large number of 
Web sites to send their visitors to rogue pages carrying a second 
attack, this time against Microsoft's Internet Explorer.
http://www.securityfocus.com/news/11415

3. HP chief apologizes, denies he knew of hacking
By: Robert Lemos
Hewlett-Packard's CEO Mark Hurd immediately replaces former chairperson 
Patricia Dunn as the company acknowledges it knew about the "pretexting" 
but not about the "hacking."
http://www.securityfocus.com/news/11414

4. Web flaws race ahead in 2006
By: Robert Lemos
Less rigor in Web programming, a growing number of software projects, 
and restrictions on Web security testing are combining to make Web-site 
vulnerabilities the most common class of security issues this year.
http://www.securityfocus.com/news/11413

IV.  SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Information Assurance Engineer, Clarksburg
http://www.securityfocus.com/archive/77/447392

2. [SJ-JOB] Sr. Security Engineer, Hyderabad
http://www.securityfocus.com/archive/77/447390

3. [SJ-JOB] Senior Software Engineer, REDWOOD CITY
http://www.securityfocus.com/archive/77/447391

4. [SJ-JOB] Management, Charlotte
http://www.securityfocus.com/archive/77/447394

5. [SJ-JOB] Security Engineer, Schaumburg
http://www.securityfocus.com/archive/77/447388

6. [SJ-JOB] Software Engineer, San Francisco
http://www.securityfocus.com/archive/77/447389

7. [SJ-JOB] Developer, Columbia
http://www.securityfocus.com/archive/77/447384

8. [SJ-JOB] Security Engineer, Burlington
http://www.securityfocus.com/archive/77/447385

9. [SJ-JOB] Manager, Information Security, Columbia
http://www.securityfocus.com/archive/77/447386

10. [SJ-JOB] Senior Software Engineer, REDWOOD CITY
http://www.securityfocus.com/archive/77/447387

11. [SJ-JOB] Security Consultant, Newport Beach
http://www.securityfocus.com/archive/77/447154

12. [SJ-JOB] Developer, Broomfield
http://www.securityfocus.com/archive/77/447165

13. [SJ-JOB] Information Assurance Analyst, Broomfield
http://www.securityfocus.com/archive/77/447166

14. [SJ-JOB] Security Engineer, Broomfield
http://www.securityfocus.com/archive/77/447139

15. [SJ-JOB] Jr. Security Analyst, LOS ANGELES
http://www.securityfocus.com/archive/77/447137

16. [SJ-JOB] Security Consultant, berkshire
http://www.securityfocus.com/archive/77/447138

17. [SJ-JOB] Security Architect, Broomfield
http://www.securityfocus.com/archive/77/447140

18. [SJ-JOB] Security Engineer, berkshire
http://www.securityfocus.com/archive/77/447136

V.   INCIDENTS LIST SUMMARY
---------------------------
VI.  VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Allow regular user to unlock screensaver locked computer
http://www.securityfocus.com/archive/88/447483

2. a question of usb token
http://www.securityfocus.com/archive/88/447484

3. How can this happen with Windows Vista?
http://www.securityfocus.com/archive/88/447296

4. Security Policy Anomaly
http://www.securityfocus.com/archive/88/447248

5. SecurityFocus Microsoft Newsletter #310
http://www.securityfocus.com/archive/88/447144

6. Microsoft Security Clamp
http://www.securityfocus.com/archive/88/446467

VIII. SUN FOCUS LIST SUMMARY
----------------------------
1. LDAP in Unix
http://www.securityfocus.com/archive/92/447230

IX. LINUX FOCUS LIST SUMMARY
----------------------------
X.  UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to 
[email protected] from the subscribed address. The 
contents of the subject or message body do not matter. You will receive 
a confirmation request message to which you will have to answer. 
Alternatively you can also visit 
http://www.securityfocus.com/newsletters and unsubscribe via the website.

If your email address has changed email [email protected] and 
ask to be manually removed.

XI.   SPONSOR INFORMATION
------------------------
This Issue is Sponsored by: Watchfire

Methodologies & Tools for Web Application Security Assessment
With the rapid rise in the number and types of security threats, web 
application security assessments should be considered a crucial phase in 
the development of any web application. What methodology should be 
followed? What tools can accelerate the assessment process? See for 
yourself. Download this Whitepaper today!

https://www.watchfire.com/securearea/whitepapers.aspx?id=701500000008YSf