SecurityFocus Newsletter #429
[email protected] 29 Nov 2007 02:16:35 -0000
| Newsgroups | gmane.comp.security.news.general |
|---|---|
| Message-ID | <[email protected]> |
SecurityFocus Newsletter #429
----------------------------------------
This issue is Sponsored by: SPI Dynamics
XPATH Injection Attacks- Web Hackers New Trick: White Paper=20
One particular form of injection attack, XPath Injection, is rapidly gain=
ing in popularity due to the spread of AJAX applications and their inhere=
nt use of XML to store data. XPath Injection can be just as dangerous as =
SQL Injection, and can be even easier to exploit. Learn how to identify X=
Path Injection vulnerabilities and which methods of recourse to take to p=
revent them. Download this *FREE* white paper from SPI Dynamics for a com=
plete guide to protection!=20
https://download.spidynamics.com/1/ad/XP.asp?Campaign_ID=3D70160000000D80=
3
SECURITY BLOGS
SecurityFocus has selected a few syndicated sources that stand out as con=
veying topics of interest for our community. We are proud to offer conten=
t from Matasano at this time and will be adding more in the coming weeks.
http://www.securityfocus.com/blogs
------------------------------------------------------------------
I. FRONT AND CENTER
1.Aye, Robot, or Can Computers Contract?
2.Don't blame the IDS
II. BUGTRAQ SUMMARY
1. Pidgin HTML Processing Remote Denial Of Service Vulnerability
2. Xpdf Multiple Remote Stream.CC Vulnerabilities
3. PHP stream_wrapper_register() Function Denial of Service Vulner=
ability
4. Joomla Equipment JUser Component MosConfig_Absolute_Path Remote=
File Include Vulnerability
5. Citrix NetScaler Generic_API_Call.PL Cross-Site Scripting Vulne=
rability
6. LIVE555 Media Server ParseRTSPRequestString Remote Denial Of Se=
rvice Vulnerability
7. Invensys Wonderware InTouch Default Universal NetDDE Share Priv=
ilege Escalation Vulnerability
8. Aleris Web Publishing Server Page.ASP SQL Injection Vulnerabili=
ty
9. ISC BIND 9 Remote Cache Poisoning Vulnerability
10. Microsoft Jet DataBase Engine MDB File Parsing Remote Buffer O=
verflow Vulnerability
11. PHP Coupon Script Index.PHP SQL Injection Vulnerability
12. SWsoft Confixx Fehler.Inc.PHP Remote File Include Vulnerabilit=
y
13. BitDefender Online Scanner OScan.OCX ActiveX Control Heap Buff=
er Overflow Vulnerability
14. Nuked-Klan File Parameter News Module Cross-Site Scripting Vul=
nerability
15. IceBB HTTP_X_FORWARDED_FOR SQL Injection Vulnerability
16. ProfileCMS ID Parameter Multiple SQL Injection Vulnerabilities
17. Belkin Wireless G Router Remote Syn Flood Denial of Service Vu=
lnerability
18. p3mbo Content Injector Index.PHP SQL Injection Vulnerability
19. PHPKIT Article.PHP SQL Injection Vulnerability
20. MySpace Scripts Poll Creator Index.PHP HTML Injection Vulnerab=
ility
21. PHPSlideShow Toonchapter8.php Cross Site Scripting Vulnerabili=
ty
22. DevMass Cart Initialise.PHP Remote File Include Vulnerability
23. Aruba MC-800 Mobility Controller Screens Directory HTML Inject=
ion Vulnerability
24. Rigs of Rods Long Vehicle Name Buffer Overflow Vulnerability
25. ClamAV Unspecified Remote Code Execution Vulnerability
26. Carousel Flash Image Gallery Admin.JJGallery.PHP Remote File I=
nclude Vulnerability
27. Symantec Backup Exec Job Engine Multiple Integer Overflow Vuln=
erabilities
28. Sun Java Runtime Environment Multiple Weaknesses
29. p.mapper Multiple Remote File Include Vulnerabilities
30. Sun Java WebStart Multiple File Access And Information Disclos=
ure Vulnerabilities
31. Symantec Backup Exec Job Engine Null Pointer Dereference Denia=
l Of Service Vulnerability
32. Audacity Insecure Temporary File Creation Vulnerability
33. GNU TAR and CPIO safer_name_suffix Remote Denial of Service Vu=
lnerability
34. CPIO Filename Directory Traversal Vulnerability
35. Tencent QQ LaunchP2PShare Multiple Stack Buffer Overflow Vulne=
rabilities
36. wpQuiz Viewimage.PHP SQL Injection Vulnerability
37. Project Alumni Index.PHP Act Parameter Local File Include Vuln=
erability
38. ht://Dig Htsearch Cross Site Scripting Vulnerability
39. Mozilla Firefox Jar URI Cross-Site Scripting Vulnerability
40. Liferay Portal Forgot-Password Cross Site Scripting Vulnerabil=
ity
41. OpenSSL SSL_Get_Shared_Ciphers Off-by-One Buffer Overflow Vuln=
erability
42. OpenSSL Montgomery Exponentiation Side-Channel Local Informati=
on Disclosure Vulnerability
43. PCRE Regular Expression Library Multiple Security Vulnerabilit=
ies
44. Samba NMBD_Packets.C NetBIOS Replies Stack-Based Buffer Overfl=
ow Vulnerability
45. Samba NMBD Logon Request Remote Buffer Overflow Vulnerability
46. Samba NSS_Info Plugin Local Privilege Escalation Vulnerability
47. Linux Kernel IEEE80211 HDRLen Remote Denial Of Service Vulnera=
bility
48. Autonomy KeyView Lotus 1-2-3 File Multiple Buffer Overflow Vul=
nerabilities
49. Macrovision InstallShield Update Service Isusweb.DLL Multiple =
Remote Code Execution Vulnerabilities
50. VanDyke VShell Unspecified Denial Of Service Vulnerability
51. Info-ZIP UnZip Privilege Escalation Vulnerability
52. datecomm Social Networking Software Index.PHP Remote File Incl=
ude Vulnerability
53. Eurologon CMS files.php Directory Traversal Vulnerability
54. Weird Solutions BOOTP Turbo Unspecified Remote Vulnerability
55. Eurologon CMS ID Parameter Multiple SQL Injection Vulnerabilit=
ies
56. Computer Associates BrightStor ARCserve Backup Multiple Remote=
Vulnerabilities
57. IBM Tivoli Storage Manager Client Multiple Vulnerabilities
58. Mozilla Firefox Multiple Remote Unspecified Memory Corruption =
Vulnerabilities
59. Amber Script Show_Content.PHP Local File Include Vulnerability
60. Project Alumni View and News Multiple SQL Injection Vulnerabil=
ities
61. Softbiz Freelancers Script Multiple Vulnerabilities
62. Project Alumni Multiple Cross-Site Scripting Vulnerabilities
63. WorkingOnWeb Events.PHP SQL Injection Vulnerability
64. Mozilla Firefox and SeaMonkey Windows.Location Property HTTP R=
eferer Header Spoofing Weakness
65. IRC Services Password Parsing Remote Denial Of Service Vulnera=
bility
66. FileMaker Instant Web Publishing Cross Site Scripting Vulnerab=
ility
67. Wireshark 0.99.6 Multiple Remote Vulnerabilities
68. Old Guy's Scripts TalkBack Comments and Guestbook Multiple Rem=
ote File Include Vulnerabilities
69. AlstraSoft E-Friends Events Module SQL Injection Vulnerability
70. Code-Crafters Ability Mail Server Multiple Remote Denial Of Se=
rvice Vulnerabilities
71. I Hear U Multiple Remote Denial Of Service Vulnerabilities
72. Linux Kernel ISDN_Net.C Local Buffer Overflow Vulnerability
73. Ingate Firewall And SIParator Multiple Vulnerabilities
74. phpMyAdmin Login Page Cross-Site Scripting Vulnerability
75. JiRo's Banner System Login.ASP Multiple SQL Injection Vulnerab=
ilities
76. PHPSlideShow Directory Parameter Cross Site Scripting Vulnerab=
ility
77. Vigile CMS Multiple Vulnerabilities
78. meBiblio Index.PHP Remote File Include Vulnerability
79. X.Org X Window Server LibX11 XKEYBOARD Extension Local Buffer =
Overflow Vulnerability
80. phpBBViet PHPBB_Root_Path Parameter Remote File Include Vulner=
ability
81. HotScripts Clone SOFTWARE-DESCRIPTION.PHP SQL Injection Vulner=
ability
82. TCL/TK Tk Toolkit TKIMGGIF.C Buffer Overflow Vulnerability
83. Sciurus Hosting Panel Code Injection Vulnerability
84. AdventNet EventLog Analyzer Insecure Default MySQL Password Un=
authorized Access Vulnerability=20
85. Apple QuickTime RTSP Response Header Remote Stack Based Buffer=
Overflow Vulnerability
86. bcoos Multiple Input Validation Vulnerabilities
87. SkyPortal Multiple SQL Injection Vulnerabilities
88. Ruby on Rails Session Fixation Vulnerability
89. Aurigma Image Uploader ActiveX Control Multiple Remote Stack B=
uffer Overflow Vulnerabilities
90. IBM Websphere Application Server Multiple Vulnerabilities
91. ngIRCd JOIN Command Parsing Denial Of Service Vulnerability
92. AhnLab V3 Products ZIP File Remote Memory Corruption Vulnerabi=
lity
93. IBM WebSphere Faultactor Cross-Site Scripting Vulnerability
94. Liferay Portal Login Script Cross-Site Scripting Vulnerability
95. AIDA Web Frame.HTML Multiple Unauthorized Access Vulnerabiliti=
es
96. IBM DB2 Multiple Privilege Escalation Vulnerabilities
97. Microsoft Windows Insecure Random Number Generator Information=
Disclosure Weakness
98. Freeside cust_bill_event.cgi Cross-Site Scripting Vulnerabilit=
y
99. IBM WebSphere MQ Multiple Unspecified Remote Memory Corruption=
Vulnerabilities
100. PHP Multiple GetText Functions Denial Of Service Vulnerabilit=
ies
III. SECURITYFOCUS NEWS
1. Group drafts rules to nix credit-card storage=20
2. Task force aims to improve U.S. cybersecurity
3. Court filings double estimate of TJX breach
4. Identity thieves likely to be first-timers, strangers
IV. SECURITY JOBS LIST SUMMARY
1. [SJ-JOB] Security Consultant, NY
2. [SJ-JOB] Account Manager, Atlanta
3. [SJ-JOB] Jr. Security Analyst, Calgary
4. [SJ-JOB] Security Engineer, London
5. [SJ-JOB] Security Engineer, San Antonio
6. [SJ-JOB] Security Consultant, Any in WA, CA, VA, OR or DC
7. [SJ-JOB] Security Consultant, Chicago
8. [SJ-JOB] Security Researcher, Menlo Park
9. [SJ-JOB] Security Consultant, NY
10. [SJ-JOB] Security Consultant, Any in WA, CA, VA, OR or DC
11. [SJ-JOB] Account Manager, Atlanta
12. [SJ-JOB] Jr. Security Analyst, Calgary
13. [SJ-JOB] Security Consultant, Chicago
14. [SJ-JOB] Security Engineer, London
15. [SJ-JOB] Security Researcher, Menlo Park
16. [SJ-JOB] Security Engineer, San Antonio
V. INCIDENTS LIST SUMMARY
VI. VULN-DEV RESEARCH LIST SUMMARY
VII. MICROSOFT FOCUS LIST SUMMARY
1. Windows NT Desktop
2. Security and Implications of Hosted Exchange
VIII. SUN FOCUS LIST SUMMARY
IX. LINUX FOCUS LIST SUMMARY
X. UNSUBSCRIBE INSTRUCTIONS
XI. SPONSOR INFORMATION
I. FRONT AND CENTER
---------------------
1.Aye, Robot, or Can Computers Contract?
By Mark Rasch
A contract is usually described as a "meeting of the minds." One person m=
akes an offer for goods or services; another person sees the offer and ne=
gotiates terms; the parties enter into an agreement of the offer; and som=
e form of consideration is given in return for the provision of something=
of value. At least that's what I remember from first year law school con=
tracts class.=20
http://www.securityfocus.com/columnists/458
2.Don't blame the IDS
By Don Parker
Some years ago, I remember reading a press release from the Gartner Group=
. It was about intrusion detection systems (IDS) offering little return f=
or the monetary investment in them and furthermore, that this very same s=
ecurity technology would be obsolete by the year 2005. A rather bold stat=
ement and an even bolder prediction on their part.
http://www.securityfocus.com/columnists/457
II. BUGTRAQ SUMMARY
--------------------
1. Pidgin HTML Processing Remote Denial Of Service Vulnerability
BugTraq ID: 26205
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26205
Summary:
Pidgin is prone to a remote denial-of-service vulnerability because it fa=
ils to handle specially crafted HTML messages.
Attackers can exploit this issue to crash the application, denying servic=
e to legitimate users.
Versions prior to Pidgin 2.2.2 are vulnerable.
2. Xpdf Multiple Remote Stream.CC Vulnerabilities
BugTraq ID: 26367
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26367
Summary:
Xpdf is prone to multiple remote vulnerabilities because of flaws in vari=
ous functions in the 'Stream.cc' source file.
Attackers exploit these issues by coercing users to view specially crafte=
d PDF files with the affected application.
Successfully exploiting these issues allows attackers to execute arbitrar=
y machine code in the context of the vulnerable application. This facilit=
ates the remote compromise of affected computers.
Xpdf 3.02pl1 is vulnerable to these issues; other versions may also be af=
fected.
3. PHP stream_wrapper_register() Function Denial of Service Vulnerability
BugTraq ID: 26426
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26426
Summary:
PHP is prone to a denial-of-service vulnerability.=20
An attacker can exploit this issue to crash the affected application, den=
ying service to legitimate users.
PHP 5.2.5 and prior versions are vulnerable.
4. Joomla Equipment JUser Component MosConfig_Absolute_Path Remote File I=
nclude Vulnerability
BugTraq ID: 26499
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26499
Summary:
The JUser component for Joomla! is prone to a remote file-include vulnera=
bility because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue may allow an attacker to compromise the application=
and the underlying system; other attacks are also possible.
JUser 1.0.14 is vulnerable; other versions may also be affected.
5. Citrix NetScaler Generic_API_Call.PL Cross-Site Scripting Vulnerabilit=
y
BugTraq ID: 26491
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26491
Summary:
Citrix NetScaler is prone to a cross-site scripting vulnerability because=
the application fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.
Citrix NetScaler 8.0 build 47.8 is vulnerable; other versions may also be=
affected.
6. LIVE555 Media Server ParseRTSPRequestString Remote Denial Of Service V=
ulnerability
BugTraq ID: 26488
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26488
Summary:
LIVE555 Media Server is prone to a remote denial-of-service vulnerability=
because it fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to crash the application, resulting in d=
enial-of-service conditions.
LIVE555 Media Server 2007.11.01 is vulnerable; other versions may also be=
affected.
7. Invensys Wonderware InTouch Default Universal NetDDE Share Privilege E=
scalation Vulnerability
BugTraq ID: 26496
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26496
Summary:
Invensys Wonderware InTouch is prone to a privilege-escalation vulnerabil=
ity because of poor default permissions on a NetDDE share.
Attackers can exploit this issue to execute arbitrary applications that a=
ccept NetDDE connections. This can compromise the application and possibl=
y the underlying computer.
InTouch 8.0 is vulnerable.
8. Aleris Web Publishing Server Page.ASP SQL Injection Vulnerability
BugTraq ID: 26207
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26207
Summary:
Aleris Web Publishing Server is prone to an SQL-injection vulnerability b=
ecause it fails to sufficiently sanitize user-supplied data before using =
it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
Aleris Web Publishing Server 3.0 is vulnerable; other versions may also b=
e affected.
9. ISC BIND 9 Remote Cache Poisoning Vulnerability
BugTraq ID: 25037
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/25037
Summary:
BIND 9 is prone to a remote cache-poisoning vulnerability because of a we=
akness in its random number generator.
=20
An attacker may leverage this issue to manipulate cache data, potentially=
facilitating man-in-the-middle, site-impersonation, or denial-of-service=
attacks.
Versions up to BIND 9.4.1 are vulnerable to this issue.
10. Microsoft Jet DataBase Engine MDB File Parsing Remote Buffer Overflow=
Vulnerability
BugTraq ID: 26468
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26468
Summary:
Microsoft Jet DataBase Engine is prone to a buffer-overflow vulnerability=
because it fails to properly bounds-check user-supplied data.
Remote attackers can exploit this issue to execute arbitrary machine code=
in the context of a user running the application. Successful exploits wi=
ll compromise the affected application and possibly the underlying comput=
er. Failed attacks will likely cause denial-of-service conditions.
11. PHP Coupon Script Index.PHP SQL Injection Vulnerability
BugTraq ID: 23799
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/23799
Summary:
PHP Coupon Script is prone to an SQL-injection vulnerability because it f=
ails to sufficiently sanitize user-supplied data before using it in an SQ=
L query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database implementation.
This issue affects PHP Coupon Script 3.0; other versions may also be affe=
cted.
12. SWsoft Confixx Fehler.Inc.PHP Remote File Include Vulnerability
BugTraq ID: 26500
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26500
Summary:
SWsoft Confixx is prone to a remote file-include vulnerability because it=
fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application=
and the underlying system; other attacks are also possible.
SWsoft Confixx 3.2.1 is vulnerable; other versions may also be affected.
13. BitDefender Online Scanner OScan.OCX ActiveX Control Heap Buffer Over=
flow Vulnerability
BugTraq ID: 26210
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26210
Summary:
BitDefender Online Scanner is prone a heap-based buffer-overflow vulnerab=
ility because the application fails to perform adequate boundary checks o=
n user-supplied data.=20
Successfully exploiting this issue allows remote attackers to execute arb=
itrary code in the context of the application using the ActiveX control (=
typically Internet Explorer). Failed exploit attempts likely result in de=
nial-of-service conditions.
14. Nuked-Klan File Parameter News Module Cross-Site Scripting Vulnerabil=
ity
BugTraq ID: 26458
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26458
Summary:
Nuked-Klan is prone to a cross-site scripting vulnerability because the a=
pplication fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.
Nuked-Klan 1.7.5 is vulnerable; other versions may also be affected.
15. IceBB HTTP_X_FORWARDED_FOR SQL Injection Vulnerability
BugTraq ID: 26483
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26483
Summary:
IceBB is prone to an SQL-injection vulnerability because it fails to suff=
iciently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
IceBB 1.0-rc6 and prior versions are vulnerable.
16. ProfileCMS ID Parameter Multiple SQL Injection Vulnerabilities
BugTraq ID: 26490
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26490
Summary:
ProfileCMS is prone to multiple SQL-injection vulnerabilities because it =
fails to sufficiently sanitize user-supplied data before using it in an S=
QL query.
Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data, or exploit latent vulnerabilities in the und=
erlying database.
ProfileCMS 1.0 is vulnerable; prior versions may also be affected.
17. Belkin Wireless G Router Remote Syn Flood Denial of Service Vulnerabi=
lity
BugTraq ID: 26498
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26498
Summary:
Belkin Wireless G routers are prone to a remote denial-of-service vulnera=
bility because the devices fail to properly handle certain network traffi=
c.
Successfully exploiting this issue allows remote attackers to crash the l=
ogging system of affected devices. This may aid in obfuscating further at=
tacks.
Belkin Wireless G routers with model number F5D7230-4 are vulnerable to t=
his issue; other versions may also be affected.
18. p3mbo Content Injector Index.PHP SQL Injection Vulnerability
BugTraq ID: 26547
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26547
Summary:
p3mbo Content Injector is prone to an SQL-injection vulnerability because=
it fails to sufficiently sanitize user-supplied data before using it in =
an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
This issue affects Content Injector 1.52; other versions may also be vuln=
erable.
19. PHPKIT Article.PHP SQL Injection Vulnerability
BugTraq ID: 26546
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26546
Summary:
PHPKIT is prone to an SQL-injection vulnerability because the application=
fails to properly sanitize user-supplied input before using it in an SQL=
query.=20
A successful exploit could allow an attacker to compromise the applicatio=
n, access or modify data, or exploit vulnerabilities in the underlying da=
tabase.
PHPKIT 1.6.4 pl1 is vulnerable to this issue; other versions may be affec=
ted as well.
20. MySpace Scripts Poll Creator Index.PHP HTML Injection Vulnerability
BugTraq ID: 26544
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26544
Summary:
MySpace Scripts Poll Creator is prone to an HTML-injection vulnerability =
because the application fails to properly sanitize user-supplied input be=
fore using it in dynamically generated content.=20
=20
Attacker-supplied HTML or JavaScript code could run in the context of the=
affected site, potentially allowing an attacker to steal cookie-based au=
thentication credentials and to control how the site is rendered to the u=
ser; other attacks are also possible.
21. PHPSlideShow Toonchapter8.php Cross Site Scripting Vulnerability
BugTraq ID: 26576
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26576
Summary:
PHPSlideShow is prone to a cross-site scripting vulnerability because it =
fails to sufficiently sanitize user-supplied data.
Exploiting this issue allows attackers to execute arbitrary HTML or scrip=
t code in a user's browser session in the context of an affected site. Th=
is may allow the attacker to steal cookie-based authentication credential=
s and launch other attacks.
22. DevMass Cart Initialise.PHP Remote File Include Vulnerability
BugTraq ID: 26538
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26538
Summary:
DevMass Cart is prone to a remote file-include vulnerability because it f=
ails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application=
and the underlying system; other attacks are also possible.
DevMass Cart 1.0 is vulnerable; other versions may also be affected.
23. Aruba MC-800 Mobility Controller Screens Directory HTML Injection Vul=
nerability
BugTraq ID: 26465
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26465
Summary:
Aruba MC-800 Mobility Controller is prone to an HTML-injection vulnerabil=
ity because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script co=
de in the context of the affected site, to steal cookie-based authenticat=
ion credentials, or to control how the site is rendered to the user; othe=
r attacks are also possible.
24. Rigs of Rods Long Vehicle Name Buffer Overflow Vulnerability
BugTraq ID: 26502
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26502
Summary:
Rigs of Rods is prone to a remote buffer-overflow because the application=
fails to bounds-check user-supplied data before copying it into an insuf=
ficiently sized buffer.=20
An attacker could exploit this issue to execute arbitrary code within the=
context of the affected application. Failed exploit attempts will result=
in a denial of service.
This issue affects Rigs of Rods 0.33d and prior versions.
25. ClamAV Unspecified Remote Code Execution Vulnerability
BugTraq ID: 26463
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26463
Summary:
ClamAV is prone to an unspecified remote code-execution vulnerability.
Very few technical details are currently available. We will update this B=
ID as more information emerges.
Attackers can exploit this issue to execute arbitrary code in the context=
of the affected application.
ClamAV 0.91.1 is vulnerable; other versions may also be affected.
26. Carousel Flash Image Gallery Admin.JJGallery.PHP Remote File Include =
Vulnerability
BugTraq ID: 26471
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26471
Summary:
Carousel Flash Image Gallery is prone to a remote file-include vulnerabil=
ity because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application=
and the underlying system; other attacks are also possible.
27. Symantec Backup Exec Job Engine Multiple Integer Overflow Vulnerabili=
ties
BugTraq ID: 26029
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26029
Summary:
Symantec Backup Exec is prone to two remote integer-overflow vulnerabilit=
ies because it fails to bounds-check user-supplied data before copying it=
into an insufficiently sized buffer.
An attacker can exploit these issues to cause an infinite loop that will =
exhaust memory or consume excessive CPU resources. Successful attacks wil=
l cause denial-of-service conditions.
Symantec Backup Exec for Windows Server 11.0.6235 and 11.0.7170 are vulne=
rable.
28. Sun Java Runtime Environment Multiple Weaknesses
BugTraq ID: 25918
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/25918
Summary:
Sun Java Runtime Environment is prone to multiple weaknesses that may all=
ow JavaScript code or applets to connect to resources other than the one =
the scripts or applets were downloaded from. One of the weaknesses may al=
low an attacker to obscure a Java warning about an untrusted applet from =
the user.
These issues affect the following packages for Windows, Solaris, and Linu=
x:
JDK and JRE 6 Update 2 and earlier
JDK and JRE 5.0 Update 12 and earlier
SDK and JRE 1.4.2_15 and earlier
SDK and JRE 1.3.1_20 and earlier
29. p.mapper Multiple Remote File Include Vulnerabilities
BugTraq ID: 26614
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26614
Summary:
p.mapper is prone to multiple remote file-include vulnerabilities because=
it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the applicati=
on and the underlying system; other attacks are also possible.
These issues affect p.mapper 3.2.0 beta3; other versions may also be vuln=
erable.
30. Sun Java WebStart Multiple File Access And Information Disclosure Vul=
nerabilities
BugTraq ID: 25920
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/25920
Summary:
Sun Java Web Start is prone to multiple local file-access vulnerabilities=
and an information-disclosure vulnerability.=20
An attacker could exploit these issues to obtain sensitive information an=
d to read and write arbitrary files on the affected computer with the pri=
vileges of the user running the untrusted Java application.
31. Symantec Backup Exec Job Engine Null Pointer Dereference Denial Of Se=
rvice Vulnerability
BugTraq ID: 26028
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26028
Summary:
Symantec Backup Exec for Windows Servers is prone to a remote denial-of-s=
ervice vulnerability because the application fails to handle specially cr=
afted TCP packets.
Exploiting this issue allows remote attackers to crash the listening serv=
ice, denying further service to legitimate users.
Symantec Backup Exec for Windows Server 11.0.6235 and 11.0.7170 are vulne=
rable.
32. Audacity Insecure Temporary File Creation Vulnerability
BugTraq ID: 26608
Remote: No
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26608
Summary:
Audacity is prone to a security vulnerability because it creates temporar=
y files in an insecure manner.
An attacker with local access could potentially exploit this issue to per=
form symlink attacks, overwriting arbitrary files in the context of the a=
ffected application.=20
Successfully mounting a symlink attack may allow the attacker to delete o=
r corrupt sensitive files, which may result in a denial of service. Other=
attacks may also be possible.
This issue affects Audacity 1.3.2; other versions may also be vulnerable.
33. GNU TAR and CPIO safer_name_suffix Remote Denial of Service Vulnerabi=
lity
BugTraq ID: 26445
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26445
Summary:
GNU's tar and cpio utilities are prone to a denial-of-service vulnerabili=
ty because of insecure use of the 'alloca()' function.
Successfully exploiting this issue allows attackers to crash the affected=
utilities and possibly to execute code, but this has not been confirmed.
GNU tar and cpio utilities share the same vulnerable code and are both af=
fected. Other utilities sharing this code may also be affected.
34. CPIO Filename Directory Traversal Vulnerability
BugTraq ID: 13291
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/13291
Summary:
The cpio utility is prone to a directory-traversal vulnerability. The iss=
ue occurs when cpio is invoked on a malicious archive.=20
An archive containing an absolute path for a filename that contains '/' c=
haracters results in the file getting written using the absolute path con=
tained in the filename.=20
A remote attacker may leverage this issue using a malicious archive to co=
rrupt arbitrary files with the privileges of the user that is running the=
vulnerable software.
35. Tencent QQ LaunchP2PShare Multiple Stack Buffer Overflow Vulnerabilit=
ies
BugTraq ID: 26613
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26613
Summary:
Tencent QQ is prone to multiple stack-based buffer-overflow vulnerabiliti=
es because the application fails to perform adequate boundary checks on u=
ser-supplied data.=20
Successfully exploiting these issues allows remote attackers to execute a=
rbitrary code in the context of the application using the ActiveX control=
(typically Internet Explorer). Failed exploit attempts likely result in =
denial-of-service conditions.
These issues affect Tencent QQ 2006 and prior versions.
36. wpQuiz Viewimage.PHP SQL Injection Vulnerability
BugTraq ID: 26611
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26611
Summary:
wpQuiz is prone to an SQL-injection vulnerability because it fails to suf=
ficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
This issue affects wpQuiz 2.7; other versions may also be affected.
37. Project Alumni Index.PHP Act Parameter Local File Include Vulnerabili=
ty
BugTraq ID: 26612
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26612
Summary:
Project Alumni is prone to a local file-include vulnerability because it =
fails to properly sanitize user-supplied input.
Exploiting this issue may allow an unauthorized user to view files and ex=
ecute local scripts.
Project Alumni 1.0.9 is vulnerable to this issue; other versions may also=
be affected.
38. ht://Dig Htsearch Cross Site Scripting Vulnerability
BugTraq ID: 26610
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26610
Summary:
ht://Dig is prone to a cross-site scripting vulnerability because it fail=
s to sufficiently sanitize user-supplied data.
Exploiting this issue allows an attacker to execute arbitrary HTML or scr=
ipt code in a user's browser session in the context of an affected site. =
This may allow the attacker to steal cookie-based authentication credenti=
als and launch other attacks.
This issue affects ht://Dig 3.2.0b6; other versions may also be vulnerabl=
e.
39. Mozilla Firefox Jar URI Cross-Site Scripting Vulnerability
BugTraq ID: 26385
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26385
Summary:
Mozilla Firefox is prone to a cross-site scripting vulnerability because =
the application fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to steal cookie-based authentication c=
redentials and other sensitive data that may aid in further attacks.
40. Liferay Portal Forgot-Password Cross Site Scripting Vulnerability
BugTraq ID: 26606
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26606
Summary:
Liferay Portal is prone to a cross-site scripting vulnerability because t=
he application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.
Liferay Portal 4.3.1 is vulnerable; other versions may also be affected.
41. OpenSSL SSL_Get_Shared_Ciphers Off-by-One Buffer Overflow Vulnerabili=
ty
BugTraq ID: 25831
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/25831
Summary:
OpenSSL is prone to an off-by-one buffer-overflow vulnerability because t=
he library fails to properly bounds-check user-supplied input before copy=
ing it to an insufficiently sized memory buffer.
Successfully exploiting this issue may allow attackers to execute arbitra=
ry machine code in the context of applications that use the affected libr=
ary, but this has not been confirmed. Failed exploit attempts may crash a=
pplications, denying service to legitimate users.
=20
NOTE: This issue was introduced in the fix for the vulnerability describe=
d in BID 20249 (OpenSSL SSL_Get_Shared_Ciphers Buffer Overflow Vulnerabil=
ity).
42. OpenSSL Montgomery Exponentiation Side-Channel Local Information Disc=
losure Vulnerability
BugTraq ID: 25163
Remote: No
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/25163
Summary:
OpenSSL is prone to a local information-disclosure vulnerability because =
of an implementation flaw in the RSA algorithm.
Successfully exploiting this issue allows local attackers to gain access =
to private key information of other processes that use the affected libra=
ry. Information harvested may aid in further attacks.
OpenSSL 0.9.8 is vulnerable to this issue; other versions may also be aff=
ected.
43. PCRE Regular Expression Library Multiple Security Vulnerabilities
BugTraq ID: 26346
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26346
Summary:
PCRE regular-expression library is prone to multiple security vulnerabili=
ties.
Attackers can exploit these issues to execute arbitrary code, cause denia=
l-of-service conditions, or launch other attacks in the context of the ap=
plication using the affected library.
44. Samba NMBD_Packets.C NetBIOS Replies Stack-Based Buffer Overflow Vuln=
erability
BugTraq ID: 26455
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26455
Summary:
Samba is prone to a remote stack-based buffer-overflow vulnerability beca=
use it fails to properly bounds-check user-supplied data before copying i=
t to an insufficiently sized memory buffer.
NOTE: This issue occurs only when Samba is configured with the 'wins supp=
ort' option enabled in the host's 'smb.conf' file.
An attacker can exploit this issue to execute arbitrary code in the conte=
xt of the affected application. Successful attacks will completely compro=
mise affected computers. Failed exploit attempts will result in a denial =
of service.
Samba 3.0.0 through 3.0.26a are vulnerable.
45. Samba NMBD Logon Request Remote Buffer Overflow Vulnerability
BugTraq ID: 26454
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26454
Summary:
Samba is prone to a buffer-overflow vulnerability because it fails to per=
form adequate boundary checks on user-supplied data.
This issue occurs only when Samba is configured as a Primary or Backup Do=
main Controller.
Attackers can exploit this issue to cause denial-of-service conditions. G=
iven the nature of this issue, attackers may also be able to execute remo=
te code, but the vendor doesn't think that this is possible.
Samba 3.0.0 through 3.0.26a are vulnerable.
46. Samba NSS_Info Plugin Local Privilege Escalation Vulnerability
BugTraq ID: 25636
Remote: No
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/25636
Summary:
Samba is prone to a local privilege-escalation vulnerability due to a log=
ic error in the Winbind daemon.
An attacker can exploit this issue to gain 'groupid 0' privileges on UNIX=
computers running the vulnerable Samba software. This may aid them in fu=
rther attacks.
Samba 3.0.25 through 3.0.25c are vulnerable to this issue.
47. Linux Kernel IEEE80211 HDRLen Remote Denial Of Service Vulnerability
BugTraq ID: 26337
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26337
Summary:
The Linux kernel ieee80211 driver is prone to a remote denial-of-service =
vulnerability because it fails to perform adequate boundary checks on use=
r-supplied data.
An attacker can exploit this issue to crash a victim computer, effectivel=
y denying service.
Versions prior to Linux kernel 2.6.22.11 are vulnerable.
48. Autonomy KeyView Lotus 1-2-3 File Multiple Buffer Overflow Vulnerabil=
ities
BugTraq ID: 26604
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26604
Summary:
Autonomy KeyView is prone to multiple buffer-overflow vulnerabilities.=20
Successfully exploiting these issues could allow an attacker to execute a=
rbitrary code in the context of the user running the application. =20
Multiple applications incorporate the vulnerable KeyView component, so th=
ey are also considered vulnerable to these issues.
NOTE: These issues are similar to those described in BID 26175 (Autonomy =
KeyView Multiple Buffer Overflow Vulnerabilities) but affect a different =
component.
49. Macrovision InstallShield Update Service Isusweb.DLL Multiple Remote =
Code Execution Vulnerabilities
BugTraq ID: 26280
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26280
Summary:
InstallShield Update Service is prone to multiple remote code-execution v=
ulnerabilities because it fails to adequately sanitize user-supplied data=
.
Successfully exploiting these issues will allow an attacker to execute ar=
bitrary code with the permissions of the user running the application.
These issues affect InstallShield Update Service 5.01.100.47363 and 6.0.1=
00.60146.
50. VanDyke VShell Unspecified Denial Of Service Vulnerability
BugTraq ID: 26602
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26602
Summary:
VanDyke VShell is prone to a denial-of-service vulnerability.=20
Very few technical details are currently available. We will update this B=
ID as more information emerges.
An attacker can exploit this issue to deny access to legitimate users.
VShell 3.0.1 is vulnerable; other versions may also be affected.
51. Info-ZIP UnZip Privilege Escalation Vulnerability
BugTraq ID: 14447
Remote: No
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/14447
Summary:
Info-ZIP UnZip is prone to a privilege-escalation issue because of improp=
er handling of permissions contained in ZIP archives during decompression=
.=20
=20
If users with superuser privileges use UnZip to decompress archives with =
setuid or setgid permissions, malicious binaries may be created that allo=
w attackers to gain superuser privileges and compromise the computer.
52. datecomm Social Networking Software Index.PHP Remote File Include Vul=
nerability
BugTraq ID: 26607
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26607
Summary:
datecomm Social Networking Software is prone to a remote file-include vul=
nerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application=
and the underlying system; other attacks are also possible.
53. Eurologon CMS files.php Directory Traversal Vulnerability
BugTraq ID: 26600
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26600
Summary:
Eurologon CMS is prone to a vulnerability that lets attackers access arb=
itrary files because the application fails to sufficiently sanitize user-=
supplied input.
This issue affects the application's download module.
An attacker can exploit this issue using directory-traversal strings ('..=
/') to download arbitrary files with the privileges of the webserver proc=
ess. Information obtained may aid in further attacks.
54. Weird Solutions BOOTP Turbo Unspecified Remote Vulnerability
BugTraq ID: 26601
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26601
Summary:
Weird Solutions BOOTP Turbo is prone to an unspecified remote vulnerabili=
ty.
Very little is known about this issue at this time. We will update this B=
ID as more information emerges.
Weird Solutions BOOTP Turbo 1.2 is vulnerable; other versions may also be=
affected.
55. Eurologon CMS ID Parameter Multiple SQL Injection Vulnerabilities
BugTraq ID: 26599
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26599
Summary:
Eurologon CMS is prone to multiple SQL-injection vulnerabilities because =
it fails to sufficiently sanitize user-supplied data before using it in a=
n SQL query.
Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data, or exploit latent vulnerabilities in the und=
erlying database.
56. Computer Associates BrightStor ARCserve Backup Multiple Remote Vulner=
abilities
BugTraq ID: 26015
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26015
Summary:
Computer Associates BrightStor ARCserve is prone to multiple remote vulne=
rabilities, including buffer-overflow issues, memory-corruption issues, a=
nd privilege-escalation issues.
Successful exploits allow remote attackers to cause denial-of-service con=
ditions, execute arbitrary machine code in the context of the affected ap=
plication, or perform actions with elevated privileges. This may result i=
n a complete compromise of affected computers.
The following applications are affected:
=20
BrightStor ARCserve Backup v9.01, r11.1, r11.5, r11 for Windows
BrightStor Enterprise Backup r10.5
CA Server Protection Suite r2,=20
CA Business Protection Suite r2
CA Business Protection Suite for Microsoft Small Business Server Standar=
d Edition r2
CA Business Protection Suite for Microsoft Small Business Server Premium=
Edition r2
57. IBM Tivoli Storage Manager Client Multiple Vulnerabilities
BugTraq ID: 25743
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/25743
Summary:
IBM Tivoli Storage Manager client is prone to multiple vulnerabilities th=
at can allow attackers to crash the client, execute arbitrary code in the=
context of the application, or gain unauthorized access to a client's da=
ta.
These issues affect Tivoli Storage Manager client 5.1, V5.2, V5.3, and V=
5.4.
58. Mozilla Firefox Multiple Remote Unspecified Memory Corruption Vulnera=
bilities
BugTraq ID: 26593
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26593
Summary:
The Mozilla Foundation has released a security advisory disclosing three =
unspecified memory-corruption vulnerabilities.
Successfully exploiting these issues may allow attackers to execute code,=
facilitating the compromise of affected computers. Failed exploit attemp=
ts will likely crash the application.
Versions prior to Mozilla Firefox 2.0.0.10 and Mozilla SeaMonkey 1.1.7 ar=
e vulnerable to these issues.
59. Amber Script Show_Content.PHP Local File Include Vulnerability
BugTraq ID: 26561
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26561
Summary:
Amber Script is prone to a local file-include vulnerability because it fa=
ils to properly sanitize user-supplied input.
Exploiting this issue may allow an unauthorized user to view files and ex=
ecute local scripts.
Amber Script 1.0 is vulnerable to this issue; other versions may also be =
affected.
60. Project Alumni View and News Multiple SQL Injection Vulnerabilities
BugTraq ID: 26564
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26564
Summary:
Project Alumni is prone to multiple SQL-injection vulnerabilities because=
it fails to sufficiently sanitize user-supplied data before using it in =
an SQL query.
Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data, or exploit latent vulnerabilities in the und=
erlying database.
61. Softbiz Freelancers Script Multiple Vulnerabilities
BugTraq ID: 26569
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26569
Summary:
Softbiz Freelancers Script is prone to multiple vulnerabilities, includin=
g an SQL-injection issue and a cross-site scripting issue, because it fai=
ls to sufficiently sanitize user-supplied data.=20
Exploiting the SQL-injection issue could allow an attacker to compromise =
the application, access or modify data, or exploit latent vulnerabilities=
in the underlying database. Exploiting the cross-site scripting issue ma=
y allow the attacker to run arbitrary script code in the browser of an un=
suspecting user and steal cookie-based authentication credentials.
62. Project Alumni Multiple Cross-Site Scripting Vulnerabilities
BugTraq ID: 26565
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26565
Summary:
Project Alumni is prone to multiple cross-site scripting vulnerabilities =
because it fails to properly sanitize user-supplied input.=20
An attacker may leverage these issues to execute arbitrary script code in=
the browser of an unsuspecting user in the context of the affected site.=
This may allow the attacker to steal cookie-based authentication credent=
ials and to launch other attacks.
63. WorkingOnWeb Events.PHP SQL Injection Vulnerability
BugTraq ID: 26563
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26563
Summary:
WorkingOnWeb is prone to an SQL-injection vulnerability because it fails =
to sufficiently sanitize user-supplied data before using it in an SQL que=
ry.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
This issue affects WorkingOnWeb 2.0.1400; other versions may also be vuln=
erable.
64. Mozilla Firefox and SeaMonkey Windows.Location Property HTTP Referer =
Header Spoofing Weakness
BugTraq ID: 26589
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26589
Summary:
Mozilla Firefox and SeaMonkey are prone to a weakness that allows an atta=
cker to spoof HTTP Referer headers. This issue stems from a race conditio=
n in the affected application. The weakness arises because of a small tim=
ing difference when using a modal 'alert()' dialog, which allows users to=
generate fake HTTP Referer headers.
An attacker can exploit this issue to spoof HTTP referer headers. This ma=
y cause other security mechanisms that rely on this data to fail or to re=
turn misleading information.
This issue affects versions prior to Mozilla FireFox 2.0.0.10 and Mozill=
a SeaMonkey 1.1.7.
65. IRC Services Password Parsing Remote Denial Of Service Vulnerability
BugTraq ID: 26517
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26517
Summary:
IRC Services are prone to a remote denial-of-service vulnerability becaus=
e it fails to adequately sanitize user-supplied input.
Attackers can exploit this issue to crash the application and deny servic=
e to legitimate users.
This issue affects versions prior to IRC Services 5.0.63 and 5.1.9.
66. FileMaker Instant Web Publishing Cross Site Scripting Vulnerability
BugTraq ID: 26515
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26515
Summary:
FileMaker is prone to a cross-site scripting vulnerability because the ap=
plication fails to properly sanitize user-supplied input.
Exploiting this issue allows an attacker to execute arbitrary HTML or scr=
ipt code in a user's browser session in the context of an affected site. =
This may allow the attacker to steal cookie-based authentication credenti=
als and launch other attacks.
This issue affects the following versions of FileMaker:
FileMaker Pro 7
FileMaker Developer 7
FileMaker Server 7
FileMaker Pro 8.x
FileMaker Pro 8.x Advanced
FileMaker Server 8.x
FileMaker Server 8.x Advanced
67. Wireshark 0.99.6 Multiple Remote Vulnerabilities
BugTraq ID: 26532
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26532
Summary:
Wireshark is prone to multiple denial-of-service and buffer-overflow vuln=
erabilities.
Exploiting these issues may allow attackers to cause crashes and deny ser=
vice to legitimate users of the application. Attackers may be able to lev=
erage some of these vulnerabilities to execute arbitrary code, but this h=
as not been confirmed.
Versions prior to Wireshark 0.99.7 are affected.
68. Old Guy's Scripts TalkBack Comments and Guestbook Multiple Remote Fil=
e Include Vulnerabilities
BugTraq ID: 26520
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26520
Summary:
TalkBack Comments and Guestbook is prone to multiple remote file-include =
vulnerabilities because it fails to sufficiently sanitize user-supplied d=
ata.
Exploiting these issues may allow an attacker to compromise the applicati=
on and the underlying system; other attacks are also possible.
Talkback Comments and Guestbook 2.2.7 is vulnerable; other versions may a=
lso be affected.
69. AlstraSoft E-Friends Events Module SQL Injection Vulnerability
BugTraq ID: 26519
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26519
Summary:
AlstraSoft E-Friends is prone to an SQL-injection vulnerability because i=
t fails to sufficiently sanitize user-supplied data before using it in an=
SQL query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
AlstraSoft E-Friends 4.98 is vulnerable; other versions may also be affec=
ted.
70. Code-Crafters Ability Mail Server Multiple Remote Denial Of Service V=
ulnerabilities
BugTraq ID: 26514
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26514
Summary:
Code-Crafters Ability Mail Server is prone to multiple remote denial-of-s=
ervice vulnerabilities because the application fails to adequately saniti=
ze user-supplied input.
Attackers can exploit these issues to crash the application, resulting in=
denial-of-service conditions.
These issues affect versions prior to Ability Mail Server 2.61.
71. I Hear U Multiple Remote Denial Of Service Vulnerabilities
BugTraq ID: 26516
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26516
Summary:
Multiple denial-of-service vulnerabilities affect I Hear U because the ap=
plication fails to handle specially crafted packets.=20
=20
An attacker may leverage these issues to cause a remote denial-of-service=
condition in affected applications.
These issues affect versions prior to I Hear U 0.5.7.
72. Linux Kernel ISDN_Net.C Local Buffer Overflow Vulnerability
BugTraq ID: 26605
Remote: No
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26605
Summary:
The Linux kernel is prone to a local buffer-overflow vulnerability becaus=
e it fails to properly bounds-check user-supplied input before copying it=
into an insufficiently sized buffer.=20
An attacker can exploit this issue to cause denial-of-service conditions.=
Given the nature of this issue, the attacker may also be able to execute=
arbitrary code, but this has not been confirmed.
This issue affects version 2.6.23; other versions may also be affected.
73. Ingate Firewall And SIParator Multiple Vulnerabilities
BugTraq ID: 26486
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26486
Summary:
Ingate Firewall and SIParator products are prone to multiple vulnerabilit=
ies that include buffer-overflow, information-disclosure, and denial-of-s=
ervice issues.
An attacker may access sensitive information, cause denial-of-service con=
ditions, or potentially execute arbitrary code.
Versions prior to Ingate Firewall 4.6.0 and Ingate SIParator 4.6.0 are v=
ulnerable.
74. phpMyAdmin Login Page Cross-Site Scripting Vulnerability
BugTraq ID: 26513
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26513
Summary:
phpMyAdmin is prone to a cross-site scripting vulnerability because it fa=
ils to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal potentially sensitive information and lau=
nch other attacks.
This issue affects versions prior to phpMyAdmin 2.11.2.2.
75. JiRo's Banner System Login.ASP Multiple SQL Injection Vulnerabilities
BugTraq ID: 26479
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26479
Summary:
JiRo's Banner System is prone to multiple SQL-injection vulnerabilities b=
ecause it fails to sufficiently sanitize user-supplied data before using =
it in an SQL query.
Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data, or exploit latent vulnerabilities in the und=
erlying database.
JiRo's Banner System 2.0 is vulnerable; other versions may also be affect=
ed.
76. PHPSlideShow Directory Parameter Cross Site Scripting Vulnerability
BugTraq ID: 26575
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26575
Summary:
PHPSlideShow is prone to a cross-site scripting vulnerability because it =
fails to sufficiently sanitize user-supplied data.
Exploiting this issue allows attackers to execute arbitrary HTML or scrip=
t code in a user's browser session in the context of an affected site. Th=
is may allow the attacker to steal cookie-based authentication credential=
s and launch other attacks.
This issue affects PHPSlideShow 0.9.9.2; other versions may also be vulne=
rable.
77. Vigile CMS Multiple Vulnerabilities
BugTraq ID: 26484
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26484
Summary:
The Vigile CMS is prone to multiple vulnerabilities because it fails to p=
roperly sanitize user-supplied input.=20
An attacker may leverage these issues to execute local scripts or view fi=
les on the server, steal cookie-based authentication credentials, execut=
e arbitrary script code in a victim's browser, and use a victim's current=
ly active session to perform actions with the application.
Vigile CMS 1.4 is vulnerable; other versions may also be affected.
78. meBiblio Index.PHP Remote File Include Vulnerability
BugTraq ID: 26480
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26480
Summary:
meBiblio is prone to a remote file-include vulnerability because it fails=
to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application=
and the underlying system; other attacks are also possible.
meBiblio 0.4.5 is vulnerable; other versions may also be affected.
79. X.Org X Window Server LibX11 XKEYBOARD Extension Local Buffer Overflo=
w Vulnerability
BugTraq ID: 19905
Remote: No
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/19905
Summary:
X.Org X Window Server libX11 library is prone to a local buffer-overflow =
vulnerability because it fails to properly validate the size of attacker-=
supplied data before copying it into a finite-sized buffer.
The issue allows local attackers to execute arbitrary machine code in the=
context of a user running an application that is dynamically linked agai=
nst the library. Failed exploit attempts will likely crash the applicatio=
n, denying service to legitimate users.
X11R6 4.0 and prior versions are reported affected by this vulnerability.
80. phpBBViet PHPBB_Root_Path Parameter Remote File Include Vulnerability
BugTraq ID: 26482
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26482
Summary:
phpBBViet is prone to a remote file-include vulnerability because the app=
lication fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files cont=
aining malicious PHP code and execute it in the context of the webserver =
process. This may allow the attacker to compromise the application and th=
e underlying system; other attacks are also possible.
This issue affects phpBBViet 2.0.22; other versions may also be vulnerabl=
e.
81. HotScripts Clone SOFTWARE-DESCRIPTION.PHP SQL Injection Vulnerability
BugTraq ID: 26485
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26485
Summary:
HotScripts Clone is prone to an SQL-injection vulnerability because it fa=
ils to sufficiently sanitize user-supplied data before using it in an SQL=
query.
Exploiting this issue could allow an attacker to compromise the applicati=
on, access or modify data, or exploit latent vulnerabilities in the under=
lying database.
82. TCL/TK Tk Toolkit TKIMGGIF.C Buffer Overflow Vulnerability
BugTraq ID: 26056
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26056
Summary:
TCL/TK Tk Toolkit is prone to a buffer-overflow vulnerability because it =
fails to perform adequate boundary checks on user-supplied data before co=
pying it to an insufficiently sized buffer.
An attacker can exploit this issue to cause denial-of-service conditions.=
Given the nature of this issue, remote code execution may also be possib=
le but has not been confirmed.
Versions prior to TCL/TK 8.4.13 are vulnerable to this issue.
83. Sciurus Hosting Panel Code Injection Vulnerability
BugTraq ID: 26481
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26481
Summary:
Sciurus Hosting Panel is prone to a remote PHP code-injection vulnerabili=
ty.=20
An attacker can exploit this issue to inject and execute arbitrary malici=
ous PHP code in the context of the webserver process. This may facilitate=
a compromise of the application and the underlying system; other attacks=
are also possible.
Sciurus Hosting Panel 2.0.3 is vulnerable; other versions may also be aff=
ected.
84. AdventNet EventLog Analyzer Insecure Default MySQL Password Unauthori=
zed Access Vulnerability=20
BugTraq ID: 26304
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26304
Summary:
AdventNet EventLog Analyzer is prone to a vulnerability that can result i=
n unauthorized access to the application's SQL database.
This issue occurs because of an insecure default password.
Attackers can exploit this issue to access or modify sensitive data or to=
exploit latent vulnerabilities in the underlying database. Attackers can=
use information harvested to compromise the affected computer; other att=
acks are also possible.
EventLog Analyzer Build 4030 is vulnerable; other versions may also be af=
fected.
85. Apple QuickTime RTSP Response Header Remote Stack Based Buffer Overfl=
ow Vulnerability
BugTraq ID: 26549
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26549
Summary:
Apple QuickTime is prone to a remote buffer-overflow vulnerability becaus=
e the application fails to properly bounds-check user-supplied input befo=
re copying it to an insufficiently sized stack-based memory buffer.
This issue occurs when handling specially crafted RTSP Response headers.
Attackers can leverage this issue to execute arbitrary machine code in th=
e context of the user running the affected application. Successful exploi=
ts will compromise the application and possibly the underlying computer. =
Failed attacks will likely cause denial-of-service conditions.
QuickTime 7.3 is vulnerable to this issue; other versions may also be aff=
ected.
86. bcoos Multiple Input Validation Vulnerabilities
BugTraq ID: 26505
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26505
Summary:
The 'bcoos' program is prone to multiple input-validation vulnerabilities=
, including a local file-include issue, an arbitrary file-upload issue, a=
nd an SQL-injection issue. These issues occur because the application fai=
ls to properly sanitize user-supplied input.
Exploiting these issues may allow an unauthorized user to view files and =
execute local scripts, execute arbitrary script code, access or modify da=
ta, or exploit latent vulnerabilities in the underlying database implemen=
tation.
This issue affects bcoos 1.0.10; other versions may also be affected.
87. SkyPortal Multiple SQL Injection Vulnerabilities
BugTraq ID: 26504
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26504
Summary:
SkyPortal is prone to multiple SQL-injection vulnerabilities because it f=
ails to sufficiently sanitize user-supplied data before using it in an SQ=
L query.
Exploiting these issues could allow an attacker to compromise the applica=
tion, access or modify data, or exploit latent vulnerabilities in the und=
erlying database.
SkyPortal RC6 is vulnerable; other versions may also be affected.
88. Ruby on Rails Session Fixation Vulnerability
BugTraq ID: 26598
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26598
Summary:
Ruby on Rails is prone to a session-fixation vulnerability.
An attacker can exploit this issue to gain unauthorized access to the aff=
ected application.
This issue affects versions prior to Ruby on Rails 1.2.6.
89. Aurigma Image Uploader ActiveX Control Multiple Remote Stack Buffer O=
verflow Vulnerabilities
BugTraq ID: 26537
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26537
Summary:
Aurigma Image Uploader ActiveX control is prone to multiple stack-based b=
uffer-overflow vulnerabilities because it fails to perform adequate bound=
ary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute a=
rbitrary code in the context of the application using the ActiveX control=
(typically Internet Explorer). Failed exploit attempts likely result in =
denial-of-service conditions.
Versions prior to Aurigma Image Uploader 4.5.70 are affected.
UPDATE (November 26, 2007): Reports indicate that this issue occurs becau=
se of a buffer-overflow issue that affects a Win32API method. This has n=
ot been confirmed. We will update this BID as more information emerges.
90. IBM Websphere Application Server Multiple Vulnerabilities
BugTraq ID: 17919
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/17919
Summary:
IBM Websphere Application Server is prone to multiple vulnerabilities.=20
These issues include vulnerabilities of unknown impact, information-discl=
osure vulnerabilities, and security-bypass vulnerabilities.
Other potentially security-related issues were also addressed.
Information regarding CVE-2006-2431 has been removed. This issue is discu=
ssed in detail in BID 21018 (IBM WebSphere Faultactor Cross-Site Scriptin=
g Vulnerability).
91. ngIRCd JOIN Command Parsing Denial Of Service Vulnerability
BugTraq ID: 26489
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26489
Summary:
ngIRCd is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to deny service to legitimate users.
Versions prior to ngIRCd 0.10.3 are vulnerable.
92. AhnLab V3 Products ZIP File Remote Memory Corruption Vulnerability
BugTraq ID: 26473
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26473
Summary:
AhnLab V3 Pro 2004 and V3 Internet Security 2007 products are prone to a =
remote memory-corruption vulnerability.
Successfully exploiting this issue allows remote attackers to crash affec=
ted computers and possibly to execute code, but this has not been confirm=
ed.
93. IBM WebSphere Faultactor Cross-Site Scripting Vulnerability
BugTraq ID: 21018
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/21018
Summary:
IBM WebSphere is prone to a cross-site scripting vulnerability because it=
fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to have arbitrary script code execute=
in the browser of an unsuspecting user in the context of the affected si=
te. This may help the attacker steal cookie-based authentication credenti=
als and launch other attacks.
WebSphere Application Server 6 is vulnerable; other versions may also be =
affected.
94. Liferay Portal Login Script Cross-Site Scripting Vulnerability
BugTraq ID: 26470
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26470
Summary:
Liferay Portal is prone to a cross-site scripting vulnerability because t=
he application fails to properly sanitize user-supplied input.=20
An attacker may leverage this issue to execute arbitrary script code in t=
he browser of an unsuspecting user in the context of the affected site. T=
his may help the attacker steal cookie-based authentication credentials a=
nd launch other attacks.
Liferay Portal 4.1.0 and 4.1.1 are vulnerable; other versions may also be=
affected.
95. AIDA Web Frame.HTML Multiple Unauthorized Access Vulnerabilities
BugTraq ID: 26464
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26464
Summary:
AIDA Web is prone to multiple unauthorized access vulnerabilities.
An attacker could exploit these issues to obtain potentially sensitive in=
formation that could aid in further attacks.
96. IBM DB2 Multiple Privilege Escalation Vulnerabilities
BugTraq ID: 26450
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26450
Summary:
IBM DB2 is prone to multiple privilege-escalation vulnerabilities.
Attackers can exploit these issues to gain elevated privileges.
Very few details are available regarding these issues. We will update thi=
s BID as more information emerges.
This issue affects IBM DB2 9.1 and IBM DB2 9.1 with fix pack 1, 2, 3, and=
3a.
97. Microsoft Windows Insecure Random Number Generator Information Disclo=
sure Weakness
BugTraq ID: 26495
Remote: No
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26495
Summary:
Microsoft Windows is prone to an information-disclosure weakness.
An attacker can exploit this issue to weaken encryption and other securit=
y-related algorithms, which may aid in further attacks.
This issue affects Microsoft Windows 2000 and Microsoft Windows XP.
98. Freeside cust_bill_event.cgi Cross-Site Scripting Vulnerability
BugTraq ID: 25811
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/25811
Summary:
Freeside is prone to a cross-site scripting vulnerability.
Exploiting this issue allows attackers to execute arbitrary HTML or scrip=
t code in a user's browser session in the context of an affected site. Th=
is may allow attackers to steal cookie-based authentication credentials a=
nd launch other attacks.
=20
This issue affects Freeside v1.7.2; other versions may also be affected.
99. IBM WebSphere MQ Multiple Unspecified Remote Memory Corruption Vulner=
abilities
BugTraq ID: 26441
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26441
Summary:
IBM WebSphere MQ is affected by multiple unspecified remote memory-corrup=
tion vulnerabilities.
Successfully exploiting these issues allows remote attackers to crash aff=
ected services, denying service to legitimate users. Remote code executio=
n may also be possible, but this has not been confirmed.
IBM WebSphere MQ 6.0 is vulnerable to these issues; other versions may al=
so be affected.
100. PHP Multiple GetText Functions Denial Of Service Vulnerabilities
BugTraq ID: 26428
Remote: Yes
Last Updated: 2007-11-28
Relevant URL: http://www.securityfocus.com/bid/26428
Summary:
PHP is prone to multiple denial-of-service vulnerabilities because it fai=
ls to perform adequate boundary checks on user-supplied input.
Attackers can exploit these issues to cause denial-of-service conditions.=
Given the nature of these issues, attackers may also be able to execute =
arbitrary code, but this has not been confirmed.
PHP 5.2.5 is vulnerable; other versions may also be affected.
III. SECURITYFOCUS NEWS ARTICLES
--------------------------------
1. Group drafts rules to nix credit-card storage=20
By: Robert Lemos
The organization responsible for technical and best-practice standards in=
the payment industry plans to require the makers of merchant software to=
certify that their programs do not store sensitive data.
http://www.securityfocus.com/news/11496
2. Task force aims to improve U.S. cybersecurity
By: Robert Lemos
A blue-ribbon panel of three dozen security experts hopes to craft a stra=
tegy to improve cybersecurity by the time the next president takes office=
.
http://www.securityfocus.com/news/11494
3. Court filings double estimate of TJX breach
By: Robert Lemos
Online attackers stole information on more than 94 million credit- and de=
bit-card accounts, more than double the original estimates, according to =
court documents.
http://www.securityfocus.com/news/11493
4. Identity thieves likely to be first-timers, strangers
By: Robert Lemos
Six years of U.S. Secret Service cases reveal that the majority of identi=
ty thieves do not know their victims and do not have a prior criminal rec=
ord.
http://www.securityfocus.com/news/11492
IV. SECURITY JOBS LIST SUMMARY
-------------------------------
1. [SJ-JOB] Security Consultant, NY
http://www.securityfocus.com/archive/77/484093
2. [SJ-JOB] Account Manager, Atlanta
http://www.securityfocus.com/archive/77/484097
3. [SJ-JOB] Jr. Security Analyst, Calgary
http://www.securityfocus.com/archive/77/484092
4. [SJ-JOB] Security Engineer, London
http://www.securityfocus.com/archive/77/484094
5. [SJ-JOB] Security Engineer, San Antonio
http://www.securityfocus.com/archive/77/484095
6. [SJ-JOB] Security Consultant, Any in WA, CA, VA, OR or DC
http://www.securityfocus.com/archive/77/484096
7. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/484090
8. [SJ-JOB] Security Researcher, Menlo Park
http://www.securityfocus.com/archive/77/484091
9. [SJ-JOB] Security Consultant, NY
http://www.securityfocus.com/archive/77/484085
10. [SJ-JOB] Security Consultant, Any in WA, CA, VA, OR or DC
http://www.securityfocus.com/archive/77/484087
11. [SJ-JOB] Account Manager, Atlanta
http://www.securityfocus.com/archive/77/484088
12. [SJ-JOB] Jr. Security Analyst, Calgary
http://www.securityfocus.com/archive/77/484089
13. [SJ-JOB] Security Consultant, Chicago
http://www.securityfocus.com/archive/77/484081
14. [SJ-JOB] Security Engineer, London
http://www.securityfocus.com/archive/77/484082
15. [SJ-JOB] Security Researcher, Menlo Park
http://www.securityfocus.com/archive/77/484083
16. [SJ-JOB] Security Engineer, San Antonio
http://www.securityfocus.com/archive/77/484084
V. INCIDENTS LIST SUMMARY
---------------------------
VI. VULN-DEV RESEARCH LIST SUMMARY
-----------------------------------
VII. MICROSOFT FOCUS LIST SUMMARY
---------------------------------
1. Windows NT Desktop
http://www.securityfocus.com/archive/88/484060
2. Security and Implications of Hosted Exchange
http://www.securityfocus.com/archive/88/483800
VIII. SUN FOCUS LIST SUMMARY
----------------------------
IX. LINUX FOCUS LIST SUMMARY
----------------------------
X. UNSUBSCRIBE INSTRUCTIONS
-----------------------------
To unsubscribe send an e-mail message to sf-news-unsubscribe@securityfocu=
s.com from the subscribed address. The contents of the subject or message=
body do not matter. You will receive a confirmation request message to w=
hich you will have to answer. Alternatively you can also visit http://www=
.securityfocus.com/newsletters and unsubscribe via the website.
If your email address has changed email [email protected] and a=
sk to be manually removed.
XI. SPONSOR INFORMATION
------------------------
This issue is Sponsored by: SPI Dynamics
XPATH Injection Attacks- Web Hackers New Trick: White Paper=20
One particular form of injection attack, XPath Injection, is rapidly gain=
ing in popularity due to the spread of AJAX applications and their inhere=
nt use of XML to store data. XPath Injection can be just as dangerous as =
SQL Injection, and can be even easier to exploit. Learn how to identify X=
Path Injection vulnerabilities and which methods of recourse to take to p=
revent them. Download this *FREE* white paper from SPI Dynamics for a com=
plete guide to protection!=20
https://download.spidynamics.com/1/ad/XP.asp?Campaign_ID=3D70160000000D80=
3