Weekly Vulnerabilities Reports > August 29 to September 4, 2005

Overview

61 new vulnerabilities reported during this period, including 3 critical vulnerabilities and 25 high severity vulnerabilities. This weekly summary report vulnerabilities in 52 products from 46 vendors including Phpldapadmin Project, Cosmoshop, Astaro, Bfcommand AND Control Software, and Symantec. Vulnerabilities are notably categorized as "Command Injection", and "Path Traversal".

  • 51 reported vulnerabilities are remotely exploitables.
  • 2 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 61 reported vulnerabilities are exploitable by an anonymous user.
  • Phpldapadmin Project has the most reported vulnerabilities, with 3 reported vulnerabilities.
  • F Secure has the most reported critical vulnerabilities, with 1 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

3 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-09-02 CVE-2005-2771 F Secure
WRQ
Security Bypass vulnerability in F-Secure Ssh Server

WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) processes access and deny lists in a case-sensitive manner, when previous versions were case-insensitive, which might allow remote attackers to bypass intended restrictions and login to accounts that should be denied.

10.0
2005-08-30 CVE-2005-2655 Maildrop Unspecified vulnerability in Maildrop

lockmail in maildrop before 1.5.3 does not drop privileges before executing commands, which allows local users to gain privileges via command line arguments.

10.0
2005-08-30 CVE-2005-2017 Symantec Unspecified vulnerability in Symantec Norton Antivirus 9.0.1.1000

Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for viruses" option, which launches a help window with raised privileges, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2002-1540.

10.0

25 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-09-02 CVE-2005-2793 Phpldapadmin Project Command Injection vulnerability in PHPldapadmin Project PHPldapadmin 0.9.6/0.9.7

PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter.

7.5
2005-09-02 CVE-2005-2790 Bfcommand AND Control Software Remote vulnerability in BFCommand & Control Server Manager

BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, relies on the client to enforce permissions and perform actions such as disconnections, which allows remote attackers to bypass administrative restrictions via a modified client.

7.5
2005-09-02 CVE-2005-2789 Bfcommand AND Control Software Remote vulnerability in BFCommand & Control Server Manager

BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to bypass authentication via (1) an unknown attack vector or (2) a NULL (0x00) as a username.

7.5
2005-09-02 CVE-2005-2788 Neocrome SQL Injection vulnerability in Land Down Under

Multiple SQL injection vulnerabilities in Land Down Under (LDU) 801 and earlier allow remote attackers to execute arbitrary SQL commands via the c parameter to (1) events.php, (2) index.php, or (3) list.php.

7.5
2005-09-02 CVE-2005-2784 Cosmoshop SQL Injection vulnerability in Cosmoshop 8.10.78

SQL injection vulnerability in the login function for the administration login panel in cosmoshop 8.10.78 allows remote attackers to execute arbitrary SQL commands and bypass authentication via unspecified vectors.

7.5
2005-09-02 CVE-2005-2782 Autolinks Remote File Include vulnerability in Autolinks 2.1

PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter, which bypasses the incomplete blacklist that only checks for "http" and "https" URLs.

7.5
2005-09-02 CVE-2005-2781 Ilia Alshanetsky Unspecified vulnerability in Ilia Alshanetsky Fudforum

The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.

7.5
2005-09-02 CVE-2005-2778 Mybulletinboard SQL Injection vulnerability in MyBB Member.PHP

SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL statements via the fid parameter.

7.5
2005-09-02 CVE-2005-2777 Looking Glass Remote Command Execution vulnerability in Looking Glass Looking Glass 20040427

Looking Glass 20040427 allows remote attackers to execute arbitrary commands via shell metacharacters in the DNS lookup query field.

7.5
2005-09-02 CVE-2005-2775 Phpwebnotes Remote File Include vulnerability in PHPwebnotes 2.0.0

php_api.php in phpWebNotes 2.0.0 uses the extract function to modify key variables such as $t_path_core, which leads to a PHP file inclusion vulnerability that allows remote attackers to execute arbitrary PHP code via the t_path_core parameter.

7.5
2005-09-02 CVE-2005-2773 HP Remote Command Execution vulnerability in HP OpenView Network Node Manager

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

7.5
2005-09-02 CVE-2005-2772 University OF Minnesota Remote Buffer Overflow vulnerability in University of Minnesota Gopher 3.0.9

Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1) a long "+VIEWS:" reply, which is not properly handled in the VIfromLine function, and (2) certain arguments when launching third party programs such as a web browser from a web link, which is not properly handled in the FIOgetargv function.

7.5
2005-09-02 CVE-2005-2770 WRQ Remote Security vulnerability in WRQ Reflection for Secure IT Windows Server 6.0

WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) does not properly handle when the Windows Administrator or Guest accounts are renamed after SSH key authentication has been configured, which allows remote attackers to use the original names during login.

7.5
2005-09-02 CVE-2005-2768 Sophos Remote Heap Overflow vulnerability in Sophos Anti-Virus Library Visio Scanning

Heap-based buffer overflow in the Sophos Antivirus Library, as used by Sophos Antivirus, PureMessage, MailMonitor, and other products, allows remote attackers to execute arbitrary code via a Visio file with a crafted sub record length.

7.5
2005-09-02 CVE-2005-2767 Leapware Remote Buffer Overflow vulnerability in Leapware Leapftp 2.7.3.600/2.7.4/2.7.4.602

Buffer overflow in LeapFTP allows remote attackers to execute arbitrary code via a long Host string in a Site Queue (.lsq) file.

7.5
2005-09-02 CVE-2005-1857 Simpleproxy Remote Syslog() Format String vulnerability in Simpleproxy

Format string vulnerability in simpleproxy before 3.4 allows remote malicious HTTP proxies to execute arbitrary code via format string specifiers in a reply.

7.5
2005-08-30 CVE-2005-2654 Phpldapadmin Project Unspecified vulnerability in PHPldapadmin Project PHPldapadmin

phpldapadmin before 0.9.6c allows remote attackers to gain anonymous access to the LDAP server, even when disable_anon_bind is set, via an HTTP request to login.php with the anonymous_bind parameter set.

7.5
2005-08-30 CVE-2005-2733 Alexander Palmo Remote Arbitrary File Upload vulnerability in Alexander Palmo Simple PHP Blog 0.4.0

upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.

7.5
2005-08-30 CVE-2005-2729 Astaro Unspecified vulnerability in Astaro Security Linux 6.001

The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows remote attackers to bypass firewall rules and connect to local services.

7.5
2005-08-30 CVE-2005-2723 PHP Arena SQL Injection vulnerability in PHP Arena Pafiledb 3.1

SQL injection vulnerability in auth.php in PaFileDB 3.1, when authmethod is set to cookies, allows remote attackers to execute arbitrary SQL commands via the username value in the pafiledbcookie cookie.

7.5
2005-08-30 CVE-2005-2720 Hauri Remote Buffer Overflow vulnerability in HAURI Anti-Virus ACE Archive Handling

Stack-based buffer overflow in the ACE archive decompression library (vrAZace.dll) in HAURI Anti-Virus products including ViRobot Expert 4.0, Advanced Server, Linux Server 2.0, and LiveCall, when compressed file scanning is enabled, allows remote attackers to execute arbitrary code via an ACE archive that contains a file with a long filename.

7.5
2005-08-29 CVE-2005-2718 Mplayer Buffer Overflow vulnerability in MPlayer Audio Header

Buffer overflow in ad_pcm.c in MPlayer 1.0pre7 and earlier allows remote attackers to execute arbitrary code via crafted PCM audio data, as demonstrated using a video file with an audio header containing a large value in a stream format (strf) chunk.

7.5
2005-08-29 CVE-2005-2717 Webcalendar Remote File Include vulnerability in Webcalendar 1.0.0

PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, possibly via send_reminders.php or other scripts.

7.5
2005-08-29 CVE-2005-2716 Nokia Remote Command Execution vulnerability in Nokia Affix BTSRV Device Name

The event_pin_code_request function in the btsrv daemon (btsrv.c) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a Bluetooth device name.

7.5
2005-09-01 CVE-2005-0403 Redhat Unspecified vulnerability in Redhat Enterprise Linux and Enterprise Linux Desktop

init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty's in multi-threaded applications, which allows local users to cause a denial of service (crash) and possibly gain tty access via unknown attack vectors that trigger an access of a pointer to a freed structure.

7.2

25 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-09-02 CVE-2005-2792 Phpldapadmin Project Path Traversal vulnerability in PHPldapadmin Project PHPldapadmin 0.9.6/0.9.7

Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a ..

5.0
2005-09-02 CVE-2005-2791 Bfcommand AND Control Software Remote vulnerability in BFCommand & Control Server Manager

BFCommand & Control Server Manager BFCC 1.22_A and earlier, and BFVCC 2.14_B and earlier, allows remote attackers to cause a denial of service (refused new connections) via a series of connections and disconnections without sending the login command.

5.0
2005-09-02 CVE-2005-2787 Alexander Palmo Directory Traversal vulnerability in Alexander Palmo Simple PHP Blog 0.4.0

comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter.

5.0
2005-09-02 CVE-2005-2786 Cosmoshop Directory Traversal vulnerability in Cosmoshop 8.10.78

Directory traversal vulnerability in bestmail_edit.cgi in cosmoshop 8.10.78 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter.

5.0
2005-09-02 CVE-2005-2779 Itan Online Banking Security System The iTAN Online-Banking Security System allows remote attackers to obtain TAN numbers via a man-in-the-middle (MITM) attack while the transaction is taking place, which facilitates a "phishing" attack.
5.0
2005-09-02 CVE-2005-2774 Lithium Software Unspecified vulnerability in Lithium Software Lithium II MOD

Format string vulnerability in Lithium II mod 1.24 for Quake 2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the nickname.

5.0
2005-08-30 CVE-2005-2732 Awstats Information Disclosure vulnerability in AWStats

AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the config parameter, which reveals the path in an error message.

5.0
2005-08-30 CVE-2005-2730 Astaro Information Disclosure vulnerability in Astaro Security Linux 6.001

The HTTP proxy in Astaro Security Linux 6.0 allows remote attackers to obtain sensitive information via an invalid request, which reveals a Proxy-authorization string in an error message.

5.0
2005-08-30 CVE-2005-2728 Apache Unspecified vulnerability in Apache Http Server

The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.

5.0
2005-08-30 CVE-2005-2727 ARI Pikivirta Multiple vulnerability in ARI Pikivirta Home FTP Server 1.0.7B45

Home Ftp Server 1.0.7 stores sensitive user information and server information in the same directory as the user's home directory, which allows remote authenticated users to obtain sensitive information by obtaining ftpmembers.lst and ftpsettings.lst.

5.0
2005-08-30 CVE-2005-2726 ARI Pikivirta Multiple vulnerability in ARI Pikivirta Home FTP Server 1.0.7B45

Directory traversal vulnerability in Home Ftp Server 1.0.7 allows remote authenticated users to read arbitrary files via "C:\" (Windows drive letter) sequences in commands such as (1) LIST or (2) RETR.

5.0
2005-08-30 CVE-2005-2722 Foojan Information Disclosure vulnerability in PHP Weblog

Foojan PHP Weblog allows remote attackers to obtain sensitive information via (1) a direct request to /daylinks/index.php or (2) a negative value in the daylinkspage parameter to index.php, which reveal the path in an error message.

5.0
2005-08-30 CVE-2005-2719 Flagship Industries Denial Of Service vulnerability in Ventrilo Status Requests

Ventrilo 2.1.2 through 2.3.0 allows remote attackers to cause a denial of service (application crash) via a status packet that contains less data than specified in the packet header sent to UDP port 3784.

5.0
2005-09-02 CVE-2005-2496 Dave Mills Unspecified vulnerability in Dave Mills Ntpd

The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.

4.6
2005-09-02 CVE-2005-2783 PHP Fusion Unspecified vulnerability in PHP Fusion PHP Fusion

Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.00.107 and earlier allows remote attackers to inject arbitrary web script or HTML via nested, malformed URL BBCode tags.

4.3
2005-09-02 CVE-2005-2780 Neocrome HTML Injection vulnerability in Neocrome Land Down Under 800

Cross-site scripting (XSS) vulnerability in Land Down Under (LDU) allows remote attackers to inject arbitrary web script or HTML via a signature.

4.3
2005-09-02 CVE-2005-2776 Looking Glass Cross-Site Scripting vulnerability in Looking Glass Looking Glass 20040427

Multiple cross-site scripting (XSS) vulnerabilities in Looking Glass 20040427 allow remote attackers to inject arbitrary web script or HTML via the (1) version[fullname], (2) version[homepage], or (3) version[no] parameter to footer.php, or the (4) version[fullname], (5) version[no], (6) version[author], (7) version[email] parameter to header.php.

4.3
2005-09-02 CVE-2005-2769 Inter7 Unspecified vulnerability in Inter7 Sqwebmail 5.0.4

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other special characters, which is not properly sanitized by SqWebMail.

4.3
2005-08-31 CVE-2005-2761 Phpgroupware Unspecified vulnerability in PHPgroupware 0.9.16.000

Cross-site scripting (XSS) vulnerability in phpGroupWare 0.9.16.000 allows administrators to inject arbitrary web script or HTML by modifying the main screen message.

4.3
2005-08-30 CVE-2005-2737 Photopost Unspecified vulnerability in Photopost PHP PRO 5.1

Cross-site scripting (XSS) vulnerability in PhotoPost PHP Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.

4.3
2005-08-30 CVE-2005-2736 Yapig Unspecified vulnerability in Yapig

Cross-site scripting (XSS) vulnerability in YaPig 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.

4.3
2005-08-30 CVE-2005-2735 Phpgraphy Unspecified vulnerability in PHPgraphy 0.9.9A

Cross-site scripting (XSS) vulnerability in phpGraphy 0.9.9a and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.

4.3
2005-08-30 CVE-2005-2734 Gallery Project Unspecified vulnerability in Gallery Project Gallery

Cross-site scripting (XSS) vulnerability in Gallery 1.5.1-RC2 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.

4.3
2005-08-30 CVE-2005-2724 Inter7 Unspecified vulnerability in Inter7 Sqwebmail

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via a file attachment that is processed by the Display feature.

4.3
2005-08-30 CVE-2005-2721 Foojan Html Injection vulnerability in Foojan PHPWeblog

Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject arbitrary web script or HTML via the Referer field in the HTTP header.

4.3

8 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-09-02 CVE-2005-2785 Cosmoshop Information Disclosure vulnerability in Cosmoshop 8.10.78

cosmoshop 8.10.78 and earlier stores passwords in plaintext in the database, which allows local users to obtain sensitive information.

2.1
2005-09-02 CVE-2005-1915 Log4Sh Unspecified vulnerability in Log4Sh 1.2.3/1.2.4/1.2.5

The log4sh_readProperties function in log4sh 1.2.5 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable log4sh.$$ filenames.

2.1
2005-09-02 CVE-2005-2766 Symantec Unspecified vulnerability in Symantec Norton Antivirus 9.0.1.1.1000/9.0.4

Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain the username and password to the internal LiveUpdate server.

2.1
2005-09-01 CVE-2005-2765 Microsoft Local Security vulnerability in Microsoft Windows 2003 Server and Windows XP

The user interface in the Windows Firewall does not properly display certain malformed entries in the Windows Registry, which makes it easier for attackers with administrator privileges to hide activities if the administrator only uses the Windows Firewall interface to monitor exceptions.

2.1
2005-08-30 CVE-2005-2731 Astaro Directory Traversal vulnerability in Astaro Security Linux 6.001

Directory traversal vulnerability in Astaro Security Linux 6.0, when using Webmin, allows remote authenticated webmin users to read arbitrary files via a ..

2.1
2005-08-30 CVE-2005-2725 QNX Local Arbitrary File Disclosure vulnerability in QNX RTOS InputTrap

The inputtrap utility in QNX RTOS 6.1.0, 6.3, and possibly earlier versions does not properly check permissions when the -t flag is specified, which allows local users to read arbitrary files.

2.1
2005-08-30 CVE-2005-1856 Sukria The CD-burning feature in backup-manager 0.5.8 and earlier uses a fixed filename in a world-writable directory for logging, which allows local users to overwrite files via a symlink attack.
2.1
2005-08-30 CVE-2005-1855 Sukria
Debian
Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.
2.1