Weekly Vulnerabilities Reports > August 29 to September 4, 2005
Overview
60 new vulnerabilities reported during this period, including 3 critical vulnerabilities and 25 high severity vulnerabilities. This weekly summary report vulnerabilities in 51 products from 45 vendors including Phpldapadmin Project, Cosmoshop, Astaro, Bfcommand AND Control Software, and Symantec. Vulnerabilities are notably categorized as "Command Injection", and "Path Traversal".
- 50 reported vulnerabilities are remotely exploitables.
- 2 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 60 reported vulnerabilities are exploitable by an anonymous user.
- Phpldapadmin Project has the most reported vulnerabilities, with 3 reported vulnerabilities.
- F Secure has the most reported critical vulnerabilities, with 1 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
3 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2005-09-02 | CVE-2005-2771 | F Secure WRQ | Security Bypass vulnerability in F-Secure Ssh Server WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) processes access and deny lists in a case-sensitive manner, when previous versions were case-insensitive, which might allow remote attackers to bypass intended restrictions and login to accounts that should be denied. | 10.0 |
2005-08-30 | CVE-2005-2655 | Maildrop | Unspecified vulnerability in Maildrop lockmail in maildrop before 1.5.3 does not drop privileges before executing commands, which allows local users to gain privileges via command line arguments. | 10.0 |
2005-08-30 | CVE-2005-2017 | Symantec | Unspecified vulnerability in Symantec Norton Antivirus 9.0.1.1000 Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for viruses" option, which launches a help window with raised privileges, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2002-1540. | 10.0 |
25 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2005-09-02 | CVE-2005-2793 | Phpldapadmin Project | Command Injection vulnerability in PHPldapadmin Project PHPldapadmin 0.9.6/0.9.7 PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter. | 7.5 |
2005-09-02 | CVE-2005-2790 | Bfcommand AND Control Software | Remote vulnerability in BFCommand & Control Server Manager BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, relies on the client to enforce permissions and perform actions such as disconnections, which allows remote attackers to bypass administrative restrictions via a modified client. | 7.5 |
2005-09-02 | CVE-2005-2789 | Bfcommand AND Control Software | Remote vulnerability in BFCommand & Control Server Manager BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to bypass authentication via (1) an unknown attack vector or (2) a NULL (0x00) as a username. | 7.5 |
2005-09-02 | CVE-2005-2788 | Neocrome | SQL Injection vulnerability in Land Down Under Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitrary SQL commands via the c parameter to (1) events.php, (2) index.php, or (3) list.php. | 7.5 |
2005-09-02 | CVE-2005-2784 | Cosmoshop | SQL Injection vulnerability in Cosmoshop 8.10.78 SQL injection vulnerability in the login function for the administration login panel in cosmoshop 8.10.78 allows remote attackers to execute arbitrary SQL commands and bypass authentication via unspecified vectors. | 7.5 |
2005-09-02 | CVE-2005-2782 | Autolinks | Remote File Include vulnerability in Autolinks 2.1 PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs. | 7.5 |
2005-09-02 | CVE-2005-2781 | Ilia Alshanetsky | Unspecified vulnerability in Ilia Alshanetsky Fudforum The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code. | 7.5 |
2005-09-02 | CVE-2005-2778 | Mybulletinboard | SQL Injection vulnerability in MyBB Member.PHP SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL statements via the fid parameter. | 7.5 |
2005-09-02 | CVE-2005-2777 | Looking Glass | Remote Command Execution vulnerability in Looking Glass Looking Glass 20040427 Looking Glass 20040427 allows remote attackers to execute arbitrary commands via shell metacharacters in the DNS lookup query field. | 7.5 |
2005-09-02 | CVE-2005-2775 | Phpwebnotes | Remote File Include vulnerability in PHPwebnotes 2.0.0 php_api.php in phpWebNotes 2.0.0 uses the extract function to modify key variables such as $t_path_core, which leads to a PHP file inclusion vulnerability that allows remote attackers to execute arbitrary PHP code via the t_path_core parameter. | 7.5 |
2005-09-02 | CVE-2005-2773 | HP | Remote Command Execution vulnerability in HP OpenView Network Node Manager HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl. | 7.5 |
2005-09-02 | CVE-2005-2772 | University OF Minnesota | Remote Buffer Overflow vulnerability in University of Minnesota Gopher 3.0.9 Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1) a long "+VIEWS:" reply, which is not properly handled in the VIfromLine function, and (2) certain arguments when launching third party programs such as a web browser from a web link, which is not properly handled in the FIOgetargv function. | 7.5 |
2005-09-02 | CVE-2005-2770 | WRQ | Remote Security vulnerability in WRQ Reflection for Secure IT Windows Server 6.0 WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) does not properly handle when the Windows Administrator or Guest accounts are renamed after SSH key authentication has been configured, which allows remote attackers to use the original names during login. | 7.5 |
2005-09-02 | CVE-2005-2768 | Sophos | Remote Heap Overflow vulnerability in Sophos Anti-Virus Library Visio Scanning Heap-based buffer overflow in the Sophos Antivirus Library, as used by Sophos Antivirus, PureMessage, MailMonitor, and other products, allows remote attackers to execute arbitrary code via a Visio file with a crafted sub record length. | 7.5 |
2005-09-02 | CVE-2005-2767 | Leapware | Remote Buffer Overflow vulnerability in Leapware Leapftp 2.7.3.600/2.7.4/2.7.4.602 Buffer overflow in LeapFTP allows remote attackers to execute arbitrary code via a long Host string in a Site Queue (.lsq) file. | 7.5 |
2005-09-02 | CVE-2005-1857 | Simpleproxy | Remote Syslog() Format String vulnerability in Simpleproxy Format string vulnerability in simpleproxy before 3.4 allows remote malicious HTTP proxies to execute arbitrary code via format string specifiers in a reply. | 7.5 |
2005-08-30 | CVE-2005-2654 | Phpldapadmin Project | Unspecified vulnerability in PHPldapadmin Project PHPldapadmin phpldapadmin before 0.9.6c allows remote attackers to gain anonymous access to the LDAP server, even when disable_anon_bind is set, via an HTTP request to login.php with the anonymous_bind parameter set. | 7.5 |
2005-08-30 | CVE-2005-2733 | Alexander Palmo | Remote Arbitrary File Upload vulnerability in Alexander Palmo Simple PHP Blog 0.4.0 upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code. | 7.5 |
2005-08-30 | CVE-2005-2729 | Astaro | Unspecified vulnerability in Astaro Security Linux 6.001 The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows remote attackers to bypass firewall rules and connect to local services. | 7.5 |
2005-08-30 | CVE-2005-2723 | PHP Arena | SQL Injection vulnerability in PHP Arena Pafiledb 3.1 SQL injection vulnerability in auth.php in PaFileDB 3.1, when authmethod is set to cookies, allows remote attackers to execute arbitrary SQL commands via the username value in the pafiledbcookie cookie. | 7.5 |
2005-08-30 | CVE-2005-2720 | Hauri | Remote Buffer Overflow vulnerability in HAURI Anti-Virus ACE Archive Handling Stack-based buffer overflow in the ACE archive decompression library (vrAZace.dll) in HAURI Anti-Virus products including ViRobot Expert 4.0, Advanced Server, Linux Server 2.0, and LiveCall, when compressed file scanning is enabled, allows remote attackers to execute arbitrary code via an ACE archive that contains a file with a long filename. | 7.5 |
2005-08-29 | CVE-2005-2718 | Mplayer | Buffer Overflow vulnerability in MPlayer Audio Header Buffer overflow in ad_pcm.c in MPlayer 1.0pre7 and earlier allows remote attackers to execute arbitrary code via crafted PCM audio data, as demonstrated using a video file with an audio header containing a large value in a stream format (strf) chunk. | 7.5 |
2005-08-29 | CVE-2005-2717 | Webcalendar | Remote File Include vulnerability in Webcalendar 1.0.0 PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, possibly via send_reminders.php or other scripts. | 7.5 |
2005-08-29 | CVE-2005-2716 | Nokia | Remote Command Execution vulnerability in Nokia Affix BTSRV Device Name The event_pin_code_request function in the btsrv daemon (btsrv.c) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a Bluetooth device name. | 7.5 |
2005-09-01 | CVE-2005-0403 | Redhat | Unspecified vulnerability in Redhat Enterprise Linux and Enterprise Linux Desktop init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty's in multi-threaded applications, which allows local users to cause a denial of service (crash) and possibly gain tty access via unknown attack vectors that trigger an access of a pointer to a freed structure. | 7.2 |
24 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2005-09-02 | CVE-2005-2792 | Phpldapadmin Project | Path Traversal vulnerability in PHPldapadmin Project PHPldapadmin 0.9.6/0.9.7 Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. | 5.0 |
2005-09-02 | CVE-2005-2791 | Bfcommand AND Control Software | Remote vulnerability in BFCommand & Control Server Manager BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to cause a denial of service (refused new connections) via a series of connections and disconnections without sending the login command. | 5.0 |
2005-09-02 | CVE-2005-2787 | Alexander Palmo | Directory Traversal vulnerability in Alexander Palmo Simple PHP Blog 0.4.0 comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter. | 5.0 |
2005-09-02 | CVE-2005-2786 | Cosmoshop | Directory Traversal vulnerability in Cosmoshop 8.10.78 Directory traversal vulnerability in bestmail_edit.cgi in cosmoshop 8.10.78 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter. | 5.0 |
2005-09-02 | CVE-2005-2779 | Itan Online Banking Security System | The iTAN Online-Banking Security System allows remote attackers to obtain TAN numbers via a man-in-the-middle (MITM) attack while the transaction is taking place, which facilitates a "phishing" attack. | 5.0 |
2005-09-02 | CVE-2005-2774 | Lithium Software | Unspecified vulnerability in Lithium Software Lithium II MOD Format string vulnerability in Lithium II mod 1.24 for Quake 2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the nickname. | 5.0 |
2005-08-30 | CVE-2005-2732 | Awstats | Information Disclosure vulnerability in AWStats AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the config parameter, which reveals the path in an error message. | 5.0 |
2005-08-30 | CVE-2005-2730 | Astaro | Information Disclosure vulnerability in Astaro Security Linux 6.001 The HTTP proxy in Astaro Security Linux 6.0 allows remote attackers to obtain sensitive information via an invalid request, which reveals a Proxy-authorization string in an error message. | 5.0 |
2005-08-30 | CVE-2005-2727 | ARI Pikivirta | Multiple vulnerability in ARI Pikivirta Home FTP Server 1.0.7B45 Home Ftp Server 1.0.7 stores sensitive user information and server information in the same directory as the user's home directory, which allows remote authenticated users to obtain sensitive information by obtaining ftpmembers.lst and ftpsettings.lst. | 5.0 |
2005-08-30 | CVE-2005-2726 | ARI Pikivirta | Multiple vulnerability in ARI Pikivirta Home FTP Server 1.0.7B45 Directory traversal vulnerability in Home Ftp Server 1.0.7 allows remote authenticated users to read arbitrary files via "C:\" (Windows drive letter) sequences in commands such as (1) LIST or (2) RETR. | 5.0 |
2005-08-30 | CVE-2005-2722 | Foojan | Information Disclosure vulnerability in PHP Weblog Foojan PHP Weblog allows remote attackers to obtain sensitive information via (1) a direct request to /daylinks/index.php or (2) a negative value in the daylinkspage parameter to index.php, which reveal the path in an error message. | 5.0 |
2005-08-30 | CVE-2005-2719 | Flagship Industries | Denial Of Service vulnerability in Ventrilo Status Requests Ventrilo 2.1.2 through 2.3.0 allows remote attackers to cause a denial of service (application crash) via a status packet that contains less data than specified in the packet header sent to UDP port 3784. | 5.0 |
2005-09-02 | CVE-2005-2496 | Dave Mills | Unspecified vulnerability in Dave Mills Ntpd The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended. | 4.6 |
2005-09-02 | CVE-2005-2783 | PHP Fusion | Unspecified vulnerability in PHP Fusion PHP Fusion Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags. | 4.3 |
2005-09-02 | CVE-2005-2780 | Neocrome | HTML Injection vulnerability in Neocrome Land Down Under 800 Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) allows remote attackers to inject arbitrary web script or HTML via a signature. | 4.3 |
2005-09-02 | CVE-2005-2776 | Looking Glass | Cross-Site Scripting vulnerability in Looking Glass Looking Glass 20040427 Multiple cross-site scripting (XSS) vulnerabilities in Looking Glass 20040427 allow remote attackers to inject arbitrary web script or HTML via the (1) version[fullname], (2) version[homepage], or (3) version[no] parameter to footer.php, or the (4) version[fullname], (5) version[no], (6) version[author], (7) version[email] parameter to header.php. | 4.3 |
2005-09-02 | CVE-2005-2769 | Inter7 | Unspecified vulnerability in Inter7 Sqwebmail 5.0.4 Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other special characters, which is not properly sanitized by SqWebMail. | 4.3 |
2005-08-31 | CVE-2005-2761 | Phpgroupware | Unspecified vulnerability in PHPgroupware 0.9.16.000 Cross-site scripting (XSS) vulnerability in phpGroupWare 0.9.16.000 allows administrators to inject arbitrary web script or HTML by modifying the main screen message. | 4.3 |
2005-08-30 | CVE-2005-2737 | Photopost | Unspecified vulnerability in Photopost PHP PRO 5.1 Cross-site scripting (XSS) vulnerability in PhotoPost PHP Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag. | 4.3 |
2005-08-30 | CVE-2005-2736 | Yapig | Unspecified vulnerability in Yapig Cross-site scripting (XSS) vulnerability in YaPig 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag. | 4.3 |
2005-08-30 | CVE-2005-2735 | Phpgraphy | Unspecified vulnerability in PHPgraphy 0.9.9A Cross-site scripting (XSS) vulnerability in phpGraphy 0.9.9a and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag. | 4.3 |
2005-08-30 | CVE-2005-2734 | Gallery Project | Unspecified vulnerability in Gallery Project Gallery Cross-site scripting (XSS) vulnerability in Gallery 1.5.1-RC2 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag. | 4.3 |
2005-08-30 | CVE-2005-2724 | Inter7 | Unspecified vulnerability in Inter7 Sqwebmail Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via a file attachment that is processed by the Display feature. | 4.3 |
2005-08-30 | CVE-2005-2721 | Foojan | Html Injection vulnerability in Foojan PHPWeblog Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject arbitrary web script or HTML via the Referer field in the HTTP header. | 4.3 |
8 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2005-09-02 | CVE-2005-2785 | Cosmoshop | Information Disclosure vulnerability in Cosmoshop 8.10.78 cosmoshop 8.10.78 and earlier stores passwords in plaintext in the database, which allows local users to obtain sensitive information. | 2.1 |
2005-09-02 | CVE-2005-1915 | Log4Sh | Unspecified vulnerability in Log4Sh 1.2.3/1.2.4/1.2.5 The log4sh_readProperties function in log4sh 1.2.5 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable log4sh.$$ filenames. | 2.1 |
2005-09-02 | CVE-2005-2766 | Symantec | Unspecified vulnerability in Symantec Norton Antivirus 9.0.1.1.1000/9.0.4 Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain the username and password to the internal LiveUpdate server. | 2.1 |
2005-09-01 | CVE-2005-2765 | Microsoft | Local Security vulnerability in Microsoft Windows 2003 Server and Windows XP The user interface in the Windows Firewall does not properly display certain malformed entries in the Windows Registry, which makes it easier for attackers with administrator privileges to hide activities if the administrator only uses the Windows Firewall interface to monitor exceptions. | 2.1 |
2005-08-30 | CVE-2005-2731 | Astaro | Directory Traversal vulnerability in Astaro Security Linux 6.001 Directory traversal vulnerability in Astaro Security Linux 6.0, when using Webmin, allows remote authenticated webmin users to read arbitrary files via a .. | 2.1 |
2005-08-30 | CVE-2005-2725 | QNX | Local Arbitrary File Disclosure vulnerability in QNX RTOS InputTrap The inputtrap utility in QNX RTOS 6.1.0, 6.3, and possibly earlier versions does not properly check permissions when the -t flag is specified, which allows local users to read arbitrary files. | 2.1 |
2005-08-30 | CVE-2005-1856 | Sukria | The CD-burning feature in backup-manager 0.5.8 and earlier uses a fixed filename in a world-writable directory for logging, which allows local users to overwrite files via a symlink attack. | 2.1 |
2005-08-30 | CVE-2005-1855 | Sukria Debian | Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information. | 2.1 |