Weekly Vulnerabilities Reports > September 19 to 25, 2005

Overview

87 new vulnerabilities reported during this period, including 2 critical vulnerabilities and 35 high severity vulnerabilities. This weekly summary report vulnerabilities in 66 products from 54 vendors including Mozilla, Jelsoft, Phpmyfaq, Bugada Andrea, and Ahnlab. Vulnerabilities are notably categorized as "SQL Injection", "Cross-site Scripting", "Code", "Permissions, Privileges, and Access Controls", and "Improper Restriction of Operations within the Bounds of a Memory Buffer".

  • 74 reported vulnerabilities are remotely exploitables.
  • 4 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 86 reported vulnerabilities are exploitable by an anonymous user.
  • Mozilla has the most reported vulnerabilities, with 8 reported vulnerabilities.
  • Francisco Burzi has the most reported critical vulnerabilities, with 1 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

2 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-09-21 CVE-2005-3016 Francisco Burzi Remote Security vulnerability in PHP-Nuke

Multiple unspecified vulnerabilities in the WYSIWYG editor in PHP-Nuke before 7.9 Final have unknown impact and attack vectors.

10.0
2005-09-24 CVE-2005-3051 Igor Pavlov Buffer Errors vulnerability in Igor Pavlov 7-Zip 3.13/4.23/4.26Beta

Stack-based buffer overflow in the ARJ plugin (arj.dll) 3.9.2.0 for 7-Zip 3.13, 4.23, and 4.26 BETA, as used in products including Turbo Searcher, allows remote attackers to execute arbitrary code via a large ARJ block.

9.3

35 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-09-24 CVE-2005-3052 Jportal SQL-Injection vulnerability in jportal

SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the search field to download.php.

7.5
2005-09-24 CVE-2005-3045 MY Little Homepage SQL Injection vulnerability in MY Little Homepage MY Little Forum 1.3/1.5

SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitrary SQL commands via the phrase field.

7.5
2005-09-23 CVE-2005-2705 Mozilla Integer Overflow vulnerability in Mozilla Browser/Firefox JavaScript Engine

Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary code.

7.5
2005-09-23 CVE-2005-2702 Mozilla Unspecified vulnerability in Mozilla Firefox and Mozilla Suite

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters.

7.5
2005-09-23 CVE-2005-2701 Mozilla Heap Overflow vulnerability in Mozilla Browser/Firefox XBM Image Processing

Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.

7.5
2005-09-22 CVE-2005-3043 Mall23 SQL Injection vulnerability in Mall23 AddItem.ASP

SQL injection vulnerability in AddItem.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idOption_Dropdown_2 parameter.

7.5
2005-09-22 CVE-2005-3042 Usermin
Webmin
Remote PAM Authentication Bypass vulnerability in Webmin / Usermin

miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoofing session IDs via certain metacharacters (line feed or carriage return).

7.5
2005-09-22 CVE-2005-3039 Mall23 SQL Injection vulnerability in Mall23 Infopage.ASP

SQL injection vulnerability in infopage.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idPage parameter.

7.5
2005-09-22 CVE-2005-3034 Compuware Authentication Bypass vulnerability in Compuware Driverstudio 2.7/3.0Beta2

Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to bypass authentication via a null session.

7.5
2005-09-22 CVE-2005-3033 Cambridge Computer Corporation Denial-Of-Service vulnerability in Cambridge Computer Corporation Vxweb 1.1.4

Stack-based buffer overflow in vxWeb 1.1.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

7.5
2005-09-22 CVE-2005-3032 Cambridge Computer Corporation Remote Buffer Overflow vulnerability in Cambridge Computer Corporation Vxtftpsrv 1.7

Buffer overflow in vxTftpSrv 1.7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TFTP request with a long filename argument.

7.5
2005-09-22 CVE-2005-3031 Cambridge Computer Corporation Remote Security vulnerability in Cambridge Computer Corporation Vxftpsrv 0.9.7

Buffer overflow in vxFtpSrv 0.9.7 allows remote attackers to execute arbitrary code via a long USER name.

7.5
2005-09-21 CVE-2005-3029 Ahnlab Remote Buffer Overflow vulnerability in Ahnlab V3 Virusblock 2005, V3Net and V3Pro 2004

Stack-based buffer overflow in AhnLab V3Pro 2004 build 6.0.0.383, V3 VirusBlock 2005 build 6.0.0.383, and V3Net for Windows Server 6.0 build 6.0.0.383 allows remote attackers to execute arbitrary code via a long filname in an ACE archive.

7.5
2005-09-21 CVE-2005-3024 Jelsoft SQL-Injection vulnerability in vBulletin

Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, the (2) thread[forumid] or (3) criteria parameters to thread.php, (4) userid parameter to user.php, the (5) calendarcustomfieldid, (6) calendarid, (7) moderatorid, (8) holidayid, (9) calendarmoderatorid, or (10) calendar[0] parameters to admincalendar.php, (11) the cronid parameter to cronlog.php, (12) user[usergroupid][0] parameter to email.php, (13) help[0] parameter to help.php, the (14) limitnumber or (15) limitstart parameter to user.php, the (16) usertitleid or (17) ids parameters to usertitle.php, (18) rvt[0] parameter to language.php, (19) keep[0] parameter to phrase.php, (20) dostyleid parameter to template.php, (21) thread[forumid] parameter to thread.php, or (22) usertools.php.

7.5
2005-09-21 CVE-2005-3022 Jelsoft SQL-Injection vulnerability in vBulletin

Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, (2) userid parameter to user.php, (3) calendar parameter to admincalendar.php, (4) cronid parameter to cronlog.php, (5) usergroupid parameter to email.php, (6) help parameter to help.php, (7) rvt parameter to language.php, (8) keep parameter to phrase.php, or (9) updateprofilepic parameter to usertools.php.

7.5
2005-09-21 CVE-2005-3019 Jelsoft Moderator And Administrator SQL Injection vulnerability in VBulletin

Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php.

7.5
2005-09-21 CVE-2005-3010 Cutephp Unspecified vulnerability in Cutephp Cutenews

Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data/flood.db.php.

7.5
2005-09-21 CVE-2005-3008 Amar Sagoo Remote Python Code Execution vulnerability in Amar Sagoo Tofu 0.2

Tofu 0.2 allows remote attackers to execute arbitrary Python code via crafted pickled objects, which Tofu unpickles and executes.

7.5
2005-09-21 CVE-2005-3005 Helpdesk Software Authentication Bypass vulnerability in Helpdesk Software Hesk 0.92/0.93

Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modifying the PHPSESSID session ID parameter or cookie.

7.5
2005-09-21 CVE-2005-3004 Interakt SQL Injection vulnerability in Interakt MX Shop 3.2.0

SQL injection vulnerability in Interakt MX Shop 3.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) idp, (2) id_ctg, or (3) id_prd parameters to the pages module in index.php.

7.5
2005-09-21 CVE-2005-3003 Noosoftware SQL-Injection vulnerability in NooTopList

SQL injection vulnerability in index.php in NooTopList 1.0.0 release 17 allows remote attackers to execute arbitrary SQL commands via the (1) o or (2) sort parameters.

7.5
2005-09-21 CVE-2005-2764 Openttd Denial-Of-Service vulnerability in Openttd 0.4.0.1

Multiple buffer overflows in OpenTTD before 0.4.0.1 allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

7.5
2005-09-21 CVE-2005-0139 SGI Permissions, Privileges, and Access Controls vulnerability in SGI Irix 6.5.25/6.5.26/6.5.27

Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, which allows attackers to conduct unauthorized activities.

7.5
2005-09-21 CVE-2005-0138 SGI Code vulnerability in SGI Irix 6.5.25/6.5.26/6.5.27

rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not correctly allow access to anonymous clients that connect from a system whose hostname can not be determined.

7.5
2005-09-21 CVE-2005-2662 Masqmail Local Privilege Escalation vulnerability in MasqMail

masqmail before 0.2.18 allows remote attackers to execute arbitrary commands via crafted e-mail addresses that are not properly sanitized when creating a failed delivery message.

7.5
2005-09-20 CVE-2005-2920 Clam Anti Virus Buffer Overflow vulnerability in ClamAV UPX Compressed Executable

Buffer overflow in libclamav/upx.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to execute arbitrary code via a crafted UPX packed executable.

7.5
2005-09-20 CVE-2005-2998 Bugada Andrea Remote Security vulnerability in Bugada Andrea PHP Advanced Transfer Manager 1.30

PHP Advanced Transfer Manager 1.30 has a default password for the administrator user, which allows remote attackers to upload and execute arbitrary PHP files.

7.5
2005-09-20 CVE-2005-2996 Symantec Veritas Unspecified vulnerability in Symantec Veritas Storage Exec and Storagecentral

Multiple heap-based and stack-based buffer overflows in certain DCOM server components in VERITAS Storage Exec Storage Exec 5.3 before Hotfix 9 and StorageCentral 5.2 before Hot Fix 2 allow remote attackers to execute arbitrary code via certain ActiveX controls.

7.5
2005-09-20 CVE-2005-2968 Mozilla Unspecified vulnerability in Mozilla Firefox and Mozilla

Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.

7.5
2005-09-20 CVE-2005-2989 Deluxebb SQL Injection vulnerability in Deluxebb 1.0/1.05

Multiple SQL injection vulnerabilities in DeluxeBB 1.0 and 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter to topic.php, the uid parameter to (2) misc.php or (3) pm.php, or the fid parameter to (3) forums.php or (4) newpost.php.

7.5
2005-09-20 CVE-2005-2987 Digital Scribe SQL Injection vulnerability in Digital Scribe Digital Scribe 1.4

SQL injection vulnerability in login.php in Digital Scribe 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter.

7.5
2005-09-20 CVE-2005-2986 Ahnlab SQL Injection vulnerability in Ahnlab V3 Virusblock 2005, V3Net and V3Pro 2004

The v3flt2k.sys driver in AhnLab V3Pro 2004 Build 6.0.0.383, V3 VirusBlock 2005 Build 6.0.0.383, V3Net for Windows Server 6.0 Build 6.0.0.383 does not properly validate the source of the DeviceIoControl commands, which allows remote attackers to gain privileges.

7.5
2005-09-20 CVE-2005-2985 Aewebworks SQL Injection vulnerability in AEwebworks Aedating 3.2/4.0

SQL injection vulnerability in search_result.php in AEwebworks aeDating Script 4.0 and earlier allows remote attackers to execute arbitrary SQL statements via the Country parameter.

7.5
2005-09-20 CVE-2005-2983 Oracle SQL Injection vulnerability in Oracle Reports 1.00

SQL injection vulnerability in Oracle Reports that use Lexical References allows remote attackers to execute arbitrary SQL commands via the values in the parameter form that appears when the paramform parameter is set to yes.

7.5
2005-09-20 CVE-2005-2979 Phpoutsourcing SQL Injection vulnerability in Noah's Classifieds

SQL injection vulnerability in index.php in phpoutsourcing Noah's classifieds allows remote attackers to execute arbitrary SQL commands via the rollid parameter.

7.5

39 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-09-24 CVE-2005-3046 Phpmyfaq SQL Injection vulnerability in PHPmyfaq 1.5.1

SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.

6.8
2005-09-20 CVE-2005-2994 IBM Cross-Site Scripting vulnerability in Rational ClearQuest

Unspecified vulnerability in the web client for IBM Rational ClearQuest 2002.05.00 and 2002.05.20, and 2003.06.00 through 2003.06.15 before SR5, allows remote attackers to execute XML Style Sheets (XSS).

6.8
2005-09-24 CVE-2005-3048 Phpmyfaq Directory Traversal vulnerability in PHPmyfaq 1.5.1

Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a ..

6.4
2005-09-23 CVE-2005-2706 Mozilla Unspecified vulnerability in Mozilla Firefox and Mozilla Suite

Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.

6.4
2005-09-24 CVE-2005-3050 Phpmyfaq Information Disclosure vulnerability in PHPmyfaq 1.5.1

PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message.

5.0
2005-09-24 CVE-2005-3049 Phpmyfaq Unspecified vulnerability in PHPmyfaq 1.5.1

PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file.

5.0
2005-09-23 CVE-2005-2707 Mozilla Unspecified vulnerability in Mozilla Firefox and Mozilla Suite

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks.

5.0
2005-09-23 CVE-2005-2704 Mozilla Unspecified vulnerability in Mozilla Firefox and Mozilla Suite

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.

5.0
2005-09-23 CVE-2005-2703 Mozilla Code Injection vulnerability in Mozilla Firefox and Mozilla Suite

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.

5.0
2005-09-22 CVE-2005-3041 Opera Software Drag And Drop File Upload vulnerability in Opera Software Opera web Browser 8.0/8.01/8.02

Unspecified "drag-and-drop vulnerability" in Opera Web Browser before 8.50 on Windows allows "unintentional file uploads."

5.0
2005-09-22 CVE-2005-3040 TAC Directory Traversal vulnerability in Vista 3.0/4.0

Directory traversal vulnerability in the web interface (ISALogin.dll) for TAC Vista 4.0, and possibly other versions before 4.3, allows remote attackers to read arbitrary files via ".." sequences in the Template parameter.

5.0
2005-09-22 CVE-2005-3038 Hosting Controller Information Disclosure vulnerability in Hosting Controller Hosting Controller 6.1Hotfix2.3

Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability."

5.0
2005-09-22 CVE-2005-3035 Compuware Remote Reboot vulnerability in Compuware Driverstudio 2.7/3.0Beta2

Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to cause a denial of service (reboot) via a UDP packet sent directly to port 9110.

5.0
2005-09-21 CVE-2005-3030 Ahnlab Directory Traversal vulnerability in Ahnlab V3 Virusblock 2005, V3Net and V3Pro 2004

Directory traversal vulnerability in the archive decompression library in AhnLab V3Pro 2004 build 6.0.0.383, V3 VirusBlock 2005 build 6.0.0.383, and V3Net for Windows Server 6.0 build 6.0.0.383 allows remote attackers to write arbitrary files via a ..

5.0
2005-09-21 CVE-2005-3027 Sybari Unspecified vulnerability in Sybari Antigen 8.0

Sybari Antigen 8.0 SR2 does not properly filter SMTP messages, which allows remote attackers to bypass custom filter rules and send file attachments of arbitrary file types via a message with a subject of "Antigen forwarded attachment".

5.0
2005-09-21 CVE-2005-3026 Alstrasoft Directory Traversal vulnerability in EPay Pro

Directory traversal vulnerability in index.php in Alstrasoft Epay Pro 2.0 and earlier allows remote attackers to read arbitrary files via a ..

5.0
2005-09-21 CVE-2005-3018 Apple Unspecified vulnerability in Apple Safari

Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL.

5.0
2005-09-21 CVE-2005-3006 Opera Multiple vulnerability in Opera Web Browser Mail Client

The mail client in Opera before 8.50 opens attached files from the user's cache directory without warning the user, which might allow remote attackers to inject arbitrary web script and spoof attachment filenames.

5.0
2005-09-20 CVE-2005-3002 Xclusive Software Denial-Of-Service vulnerability in Xclusive-Software Mccs 1.0

Multi-Computer Control System (MCCS) 1.0 allows remote attackers to cause a denial of service via a malformed UDP packet.

5.0
2005-09-20 CVE-2005-2919 Clam Anti Virus Code vulnerability in Clam Anti-Virus Clamav

libclamav/fsg.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to cause a denial of service (infinite loop) via a crafted FSG packed executable.

5.0
2005-09-20 CVE-2005-2999 Bugada Andrea Remote Security vulnerability in Bugada Andrea PHP Advanced Transfer Manager 1.30

PHP Advanced Transfer Manager 1.30 allows remote attackers to obtain sensitive PHP configuration information via a direct request to test.php.

5.0
2005-09-20 CVE-2005-2997 Bugada Andrea Directory Traversal vulnerability in Bugada Andrea PHP Advanced Transfer Manager 1.30

Multiple directory traversal vulnerabilities in PHP Advanced Transfer Manager 1.30 allow remote attackers to read arbitrary files via ".." sequences in (1) the currentdir parameter to txt.php, or the current_dir parameter to (2) htm.php or (3) html.php.

5.0
2005-09-20 CVE-2005-2988 HP Information Disclosure vulnerability in LaserJet 2430

HP LaserJet 2430, and possibly other printers that use Jetdirect controls, stores information about recently printed documents without proper protection, which could allow remote attackers to obtain sensitive information via SNMP.

5.0
2005-09-22 CVE-2005-3036 Ttxn Local Security vulnerability in Ttxn File Transfer Anywhere 3.01

File Transfer Anywhere 3.01 stores sensitive password information in plaintext in the PASS value in the "File Transfer Anywhere" registry key, which allows local users to gain privileges.

4.6
2005-09-21 CVE-2005-3013 Suse Local Buffer Overflow vulnerability in Suse Linux 9.3

Buffer overflow in liby2util in Yet another Setup Tool (YaST) for SuSE Linux 9.3 allows local users to execute arbitrary code via a long Loc entry.

4.6
2005-09-20 CVE-2005-2984 Data Center Resources Unspecified vulnerability in Data Center Resources Avocent Ccm48502.1Firmware

Avocent CCM console server running firmware 2.1 CCM4850 allows remote authenticated attackers to bypass port restrictions by connecting to the server via SSH and using the connect command to access the serial port.

4.6
2005-09-24 CVE-2005-3047 Phpmyfaq Cross-Site Scripting vulnerability in PHPmyfaq 1.5.1

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php.

4.3
2005-09-22 CVE-2005-3037 Handy Address Book Cross-Site Scripting vulnerability in Handy Address Book Handy Address Book Server 1.1

Cross-site scripting (XSS) vulnerability in Handy Address Book Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the SEARCHTEXT parameter in a demos URL.

4.3
2005-09-21 CVE-2005-3025 Jelsoft Cross-Site Scripting vulnerability in vBulletin

Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/user.php or (4) admincp/usertitle.php.

4.3
2005-09-21 CVE-2005-3023 Jelsoft Cross-Site Scripting vulnerability in vBulletin

Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) announcement.php, (2) admincalendar.php, (3) bbcode.php, (4) cronadmin.php, (5) email.php, (6) faq.php, (7) forum.php, (8) image.php, (9) language.php, (10) ranks.php, (11) replacement.php, (12) replacement.php, (13) template.php, (14) template.php, (15) usergroup.php, or (16) usertitle.php.

4.3
2005-09-21 CVE-2005-3020 Jelsoft Cross-Site Scripting vulnerability in VBulletin

Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expandset parameter to template.php.

4.3
2005-09-21 CVE-2005-3017 Content2Web Cross-Site Scripting vulnerability in Content2Web 1.0.1

PHP file inclusion vulnerability in index.php in Content2Web 1.0.1 allows remote attackers to include arbitrary files via the show parameter, which can lead to resultant errors such as path disclosure, SQL error messages, and cross-site scripting (XSS).

4.3
2005-09-21 CVE-2005-3015 IBM Cross-Site Scripting vulnerability in IBM Lotus Domino and Lotus Domino Enterprise Server

Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters.

4.3
2005-09-21 CVE-2005-3014 Ensim HTML Injection vulnerability in Ensim Webppliance 3.0/3.1/3.1.1

Cross-site scripting (XSS) vulnerability in Ensim webplliance allows remote attackers to inject arbitrary web script or HTML via the Login (OCW_login_username) field.

4.3
2005-09-21 CVE-2005-3009 Cutephp Cross-Site Scripting vulnerability in CuteNews

Cross-site scripting (XSS) vulnerability in CuteNews allows remote attackers to inject arbitrary web script or HTML via the mod parameter to index.php.

4.3
2005-09-20 CVE-2005-3000 Bugada Andrea Cross-Site Scripting vulnerability in Bugada Andrea PHP Advanced Transfer Manager 1.30

Multiple cross-site scripting (XSS) vulnerabilities in viewers/txt.php in PHP Advanced Transfer Manager 1.30 allow remote attackers to inject arbitrary web script or HTML via the (1) font, (2) normalfontcolor, or (3) mess[31] parameters.

4.3
2005-09-20 CVE-2005-2982 Compaq Cross-Site Scripting vulnerability in Compaq Compaqhttpserver 2.1

Cross-site scripting (XSS) vulnerability in CompaqHTTPServer 2.1 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.

4.3
2005-09-20 CVE-2005-2981 Orionserver Cross-Site Scripting vulnerability in Orionserver Orion Application Server 1.3.8/1.4.5

Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.

4.3
2005-09-20 CVE-2005-2980 Phpoutsourcing Cross-Site Scripting vulnerability in PHPoutsourcing Noahs Classifieds 1.3

Cross-site scripting (XSS) vulnerability in index.php in phpoutsourcing Noah's classifieds 1.3 allows remote attackers to inject arbitrary web script or HTML via the rollid parameter.

4.3

11 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-09-20 CVE-2005-2995 Bacula Denial-Of-Service vulnerability in Bacula

bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconf/randpass when openssl is not available, or (2) the mtx.[PID] temporary file in mtx-changer.in.

3.6
2005-09-21 CVE-2005-3007 Opera Software Multiple vulnerability in Opera Software Opera 8.02

Opera before 8.50 allows remote attackers to spoof the content type of files via a filename with a trailing "." (dot), which might allow remote attackers to trick users into processing dangerous content.

2.6
2005-09-22 CVE-2005-3044 Linux Local Denial of Service vulnerability in Linux Kernel 64-Bit SMP Routing_ioctl()

Multiple vulnerabilities in Linux kernel before 2.6.13.2 allow local users to cause a denial of service (kernel OOPS from null dereference) via (1) fput in a 32-bit ioctl on 64-bit x86 systems or (2) sockfd_put in the 32-bit routing_ioctl function on 64-bit systems.

2.1
2005-09-21 CVE-2005-3021 Jelsoft File-Upload vulnerability in vBulletin

image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator panel to upload arbitrary files via the upload action.

2.1
2005-09-21 CVE-2005-3012 Simplecdr X Unspecified vulnerability in Simplecdr-X 1.3.3

The MasterDataCD::createImage function in masterdatacd.cpp for SimpleCDR-X 1.3.3 creates the .temp temporary directory with insecure permissions, which allows local users to read sensitive ISO images.

2.1
2005-09-21 CVE-2005-2663 Masqmail Local Privilege Escalation vulnerability in MasqMail

masqmail before 0.2.18 allows local users to overwrite arbitrary files via a symlink attack on a log file.

2.1
2005-09-20 CVE-2005-3001 SUN Denial-Of-Service vulnerability in SUN Solaris 10.0

Unspecified vulnerability in the "tl" driver in Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors.

2.1
2005-09-20 CVE-2005-2991 Ncompress Local Security vulnerability in ncompress

ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.

2.1
2005-09-20 CVE-2005-2990 Linecontrol Local Password Disclosure vulnerability in Linecontrol Java Client 0.8

AuthInfo.java in LineContol Java Client (jlc) before 0.8.1 stores sensitive information such as user passwords in log files.

2.1
2005-09-20 CVE-2005-2993 HP Remote Denial Of Service vulnerability in HP-UX FTPD

Unspecified vulnerability in the FTP Daemon (ftpd) for HP Tru64 UNIX 4.0F PK8 and other versions up to HP Tru64 UNIX 5.1B-3, and HP-UX B.11.00, B.11.04, B.11.11, and B.11.23, allows remote authenticated users to cause a denial of service (hang).

1.7
2005-09-21 CVE-2005-3011 GNU Link Following vulnerability in GNU Texinfo 4.8

The sort_offline function for texindex in texinfo 4.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.

1.2