Weekly Vulnerabilities Reports > February 27 to March 5, 2006

Overview

85 new vulnerabilities reported during this period, including 2 critical vulnerabilities and 26 high severity vulnerabilities. This weekly summary report vulnerabilities in 75 products from 60 vendors including Apple, NCP Network Communications, Mozilla, Argosoft, and Microsoft. Vulnerabilities are notably categorized as "Resource Management Errors", "SQL Injection", "Path Traversal", "Code Injection", and "Cross-site Scripting".

  • 72 reported vulnerabilities are remotely exploitables.
  • 6 reported vulnerabilities have public exploit available.
  • 5 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 75 reported vulnerabilities are exploitable by an anonymous user.
  • Apple has the most reported vulnerabilities, with 6 reported vulnerabilities.
  • Novell has the most reported critical vulnerabilities, with 1 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

2 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-03-03 CVE-2006-0979 Nidelven IT Information Disclosure vulnerability in Nidelven IT Issue Dealer 0.9.95

Unspecified vulnerability in the local weblog publisher in Nidelven IT Issue Dealer before 0.9.96 has unknown impact and attack vectors.

10.0
2006-02-27 CVE-2006-0736 Novell Remote Buffer Overflow vulnerability in Novell Linux Desktop and Open Enterprise Server

Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors.

10.0

26 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-03-03 CVE-2006-0988 Microsoft Denial-Of-Service vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows NT

The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.

7.8
2006-02-27 CVE-2006-0900 Freebsd Remote NFS RPC Request Denial of Service vulnerability in Freebsd 6.0

nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the ProtoVer NFS test suite.

7.8
2006-03-03 CVE-2006-0973 Phpwebsite SQL Injection vulnerability in PHPWebSite Topics.PHP

SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter.

7.5
2006-03-03 CVE-2006-0970 Activecampaign Remote Security vulnerability in SupportTrio

PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.

7.5
2006-03-03 CVE-2006-0969 Pixelartkingdom Remote Security vulnerability in Top Sites

PHP remote file inclusion vulnerability in index.php in Top sites de PixelArtKingdom allows remote attackers to include and execute arbitrary files via the page parameter.

7.5
2006-03-02 CVE-2006-0962 Vubb SQL Injection vulnerability in Vubb 0.2

SQL injection vulnerability in vuBB 0.2 allows remote attackers to execute arbitrary SQL commands via the pass parameter in a cookie.

7.5
2006-03-02 CVE-2006-0961 Cilem SQL Injection vulnerability in Cilem Haber 1.1

SQL injection vulnerability in yazdir.asp in Cilem Hiber 1.1 allows remote attackers to execute arbitrary SQL commands via the haber_id parameter.

7.5
2006-03-02 CVE-2006-0959 Mybulletinboard SQL Injection vulnerability in Mybulletinboard 1.0.3/1.0.4

SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands by setting the comma variable value via the comma parameter in a cookie.

7.5
2006-03-02 CVE-2006-0957 Zoneo Soft Remote PHP Script Code Injection vulnerability in freeForum

Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP headers, which are stored in Data/flood.db.php.

7.5
2006-03-02 CVE-2006-0384 Apple Multiple vulnerability in Apple Mac OS X Security Update 2006-001

automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names".

7.5
2006-03-01 CVE-2006-0947 Thomson Cross-Site Scripting vulnerability in Thomson SpeedTouch 500 Series

Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface.

7.5
2006-03-01 CVE-2006-0944 Archangelmgt Authentication Bypass vulnerability in Archangelmgt Weblog 0.90.02

Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1.

7.5
2006-03-01 CVE-2006-0943 Pwsphp SQL-Injection vulnerability in Pwsphp 1.2.3

SQL injection vulnerability in the sondages module in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

7.5
2006-03-01 CVE-2006-0942 Pwsphp SQL Injection vulnerability in PwsPHP

SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the aff_news_form parameter, a different vulnerability than CVE-2005-1509.

7.5
2006-03-01 CVE-2006-0940 Cynical Games Input Validation vulnerability in Cynical Games Shoutlive 1.1.0

Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via variables that are written to settings.php.

7.5
2006-03-01 CVE-2006-0939 DCI Designs SQL Injection vulnerability in Dci-Designs Dci-Taskeen 1.03

SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php.

7.5
2006-02-28 CVE-2006-0919 OI SQL-Injection vulnerability in OI Email Marketing System 3.0

SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.

7.5
2006-02-28 CVE-2006-0918 Ritlabs Remote Buffer Overflow vulnerability in Ritlabs the BAT 3.60.07

Buffer overflow in RITLabs The Bat! 3.60.07 allows remote attackers to execute arbitrary code via a long Subject field.

7.5
2006-02-28 CVE-2006-0916 Mozilla Information Disclosure vulnerability in Bugzilla User Credentials

Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain.

7.5
2006-02-28 CVE-2006-0915 Mozilla Unspecified vulnerability in Mozilla Bugzilla 2.16.10

Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error.

7.5
2006-02-28 CVE-2006-0908 Francisco Burzi SQL-Injection vulnerability in Francisco Burzi PHP-Nuke 7.8Patched3.2

PHP-Nuke 7.8 Patched 3.2 allows remote attackers to bypass SQL injection protection mechanisms via /%2a (/*) sequences with the "ad_click" word in the query string, as demonstrated via the kala parameter.

7.5
2006-02-28 CVE-2006-0907 Francisco Burzi SQL-Injection vulnerability in Francisco Burzi PHP-Nuke 7.8

SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands via encoded /%2a (/*) sequences in the query string, which bypasses regular expressions that are intended to protect against SQL injection, as demonstrated via the kala parameter.

7.5
2006-02-28 CVE-2006-0906 TOP Line SQL Injection vulnerability in TOP Line D3Jeeb PRO 3

SQL injection vulnerability in D3Jeeb Pro 3 allows remote attackers to execute arbitrary SQL commands via the catid parameter in (1) fastlinks.php and (2) catogary.php.

7.5
2006-02-27 CVE-2006-0899 4Images Remote File Include vulnerability in 4images

Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.

7.5
2006-03-02 CVE-2006-0968 NCP Network Communications Multiple vulnerability in NCP Network Communications Secure Client 8.11Build146

The ncprwsnt service in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to execute arbitrary code by modifying the connect.bat script, which is automatically executed by the service after a connection is established.

7.2
2006-02-27 CVE-2006-0901 SUN Local Denial Of Service vulnerability in Sun Solaris HSFS Filesystem

Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code.

7.2

45 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-03-01 CVE-2006-0945 Archangelmgt Code Injection vulnerability in Archangelmgt Weblog 0.90.02

PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary PHP code via a URL ending in a NULL (%00) in the index parameter.

6.5
2006-02-28 CVE-2006-0936 Free Host Shop Unspecified vulnerability in Free Host Shop Website Generator 3.3

Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00.

6.5
2006-02-28 CVE-2006-0921 Fckeditor Unspecified vulnerability in Fckeditor 2.0Fc

Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a ..

6.4
2006-02-28 CVE-2006-0914 Mozilla Improper Input Validation vulnerability in Mozilla Bugzilla

Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error.

5.5
2006-02-28 CVE-2006-0913 Mozilla SQL Injection vulnerability in Bugzilla Whinedays

SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi.

5.5
2006-03-03 CVE-2006-0995 EMC Dantz Remote Denial of Service vulnerability in EMC Dantz Retrospect Backup Client

EMC Dantz Retrospect 7 backup client 7.0.107, and other versions before 7.0.109, and 6.5 before 6.5.138 allows remote attackers to cause a denial of service (client termination and loss of backup service) via a malformed packet to TCP port 497, which triggers an assert error.

5.0
2006-03-03 CVE-2006-0987 ISC Denial-Of-Service vulnerability in ISC Bind 9.3.2

The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.

5.0
2006-03-03 CVE-2006-0986 Wordpress Information Disclosure vulnerability in WordPress

WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory; and (7) edit-form-advanced.php, (8) admin-functions.php, (9) edit-link-form.php, (10) edit-page-form.php, (11) admin-footer.php, and (12) menu.php in the wp-admin directory; and possibly (13) list directory contents of the wp-includes directory.

5.0
2006-03-03 CVE-2006-0982 Mcafee Security Bypass vulnerability in Mcafee Virex 7.7

The on-access scanner for McAfee Virex 7.7 for Macintosh, in some circumstances, might not activate when malicious content is accessed from the web browser, and might not prevent the content from being saved, which allows remote attackers to bypass virus protection, as demonstrated using the EICAR test file.

5.0
2006-03-03 CVE-2006-0977 Craig Morrison Unspecified vulnerability in Craig Morrison MTS PRO

Craig Morrison Mail Transport System Professional (aka MTS Pro) acts as an open relay when configured to relay all mail through an external SMTP server, which allows remote attackers to relay mail by connecting to the MTS Pro server, then sending a MAIL FROM that specifies a domain that is local to the server.

5.0
2006-03-03 CVE-2006-0976 Spid Path Traversal vulnerability in Spid 1.3.1

Directory traversal vulnerability in scan_lang_insert.php in Boris Herbiniere-Seve SPiD 1.3.1 allows remote attackers to read arbitrary files via the lang parameter.

5.0
2006-03-03 CVE-2006-0972 Fscripts SQL Injection vulnerability in Fscripts Fantastic News 2.1.1

SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page parameter.

5.0
2006-03-03 CVE-2006-0971 Lionel Reyero Directory Traversal vulnerability in Lionel Reyero Directcontact 0.3B

Directory traversal vulnerability in Lionel Reyero DirectContact 0.3b allows remote attackers to read arbitrary files via a ..

5.0
2006-03-02 CVE-2006-0960 Compex Denial Of Service vulnerability in Compex NetPassage WPE54G

uConfig agent in Compex NetPassage WPE54G router allows remote attackers to cause a denial of service (unresposiveness) via crafted datagrams to UDP port 7778.

5.0
2006-03-02 CVE-2006-0383 Apple Multiple vulnerability in Apple Mac OS X Security Update 2006-001

IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the "incorrect handling of error conditions".

5.0
2006-02-28 CVE-2006-0937 UNU Networks Information Disclosure vulnerability in UNU Networks Mailgust 1.9

U.N.U.

5.0
2006-02-28 CVE-2006-0932 Pear Directory Traversal vulnerability in Pear Archive ZIP 1.1

Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive.

5.0
2006-02-28 CVE-2006-0931 Pear Path Traversal vulnerability in Pear Archive TAR

Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive.

5.0
2006-02-28 CVE-2006-0928 Argosoft Remote Information Disclosure vulnerability in Argosoft Mail Server 1.8

The POP3 Server in ArGoSoft Mail Server Pro 1.8 allows remote attackers to obtain sensitive information via the _DUMP command, which reveals the operating system, registered user, and registration code.

5.0
2006-02-28 CVE-2006-0925 ALT N Remote Format String vulnerability in Alt-N MDaemon IMAP Server

Format string vulnerability in the IMAP4rev1 server in Alt-N MDaemon 8.1.1 and possibly 8.1.4 allows remote attackers to cause a denial of service (CPU consumption) by creating and then listing folders whose names contain format string specifiers.

5.0
2006-02-28 CVE-2006-0922 Devellion Unspecified vulnerability in Devellion Cubecart

CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows remote attackers to upload arbitrary files via a modified CurrentFolder parameter in a direct request to admin/filemanager/upload.php.

5.0
2006-02-28 CVE-2006-0912 Oreka Remote Denial of Service vulnerability in Oreka RTP Packet Handling

Oreka before 0.5 allows remote attackers to cause a denial of service (application crash) via a "certain RTP sequence."

5.0
2006-02-28 CVE-2006-0911 Ipswitch Resource Management Errors vulnerability in Ipswitch Whatsup Professional2006

NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Login.asp, possibly involving the (1) "In]" and (2) "b;tnLogIn" parameters, or (3) malformed btnLogIn parameters, possibly involving missing "[" (open bracket) or "[" (closing bracket) characters, as demonstrated by "&btnLogIn=[Log&In]=&" or "&b;tnLogIn=[Log&In]=&" in the URL.

5.0
2006-02-28 CVE-2006-0910 Invision Power Services Remote Security vulnerability in Invision Power Board

Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1) sources/loginauth/convert/, (2) sources/portal_plugins/, (3) cache/skin_cache/cacheid_2/, (4) ips_kernel/PEAR/, (5) ips_kernel/PEAR/Text/, (6) ips_kernel/PEAR/Text/Diff/, (7) ips_kernel/PEAR/Text/Diff/Renderer/, (8) style_images/1/folder_rte_files/, (9) style_images/1/folder_js_skin/, (10) style_images/1/folder_rte_images/, and (11) upgrade/ and its subdirectories.

5.0
2006-02-28 CVE-2006-0909 Invision Power Services Information Disclosure vulnerability in Invision Power Board

Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages, including (1) PEAR/Text/Diff/Renderer/inline.php, (2) PEAR/Text/Diff/Renderer/unified.php, (3) PEAR/Text/Diff3.php, (4) class_db.php, (5) class_db_mysql.php, and (6) class_xml.php in the ips_kernel/ directory; (7) mysql_admin_queries.php, (8) mysql_extra_queries.php, (9) mysql_queries.php, and (10) mysql_subsm_queries.php in the sources/sql directory; (11) sources/acp_loaders/acp_pages_components.php; (12) sources/action_admin/member.php and (13) sources/action_admin/paysubscriptions.php; (14) login.php, (15) messenger.php, (16) moderate.php, (17) paysubscriptions.php, (18) register.php, (19) search.php, (20) topics.php, (21) and usercp.php in the sources/action_public directory; (22) bbcode/class_bbcode.php, (23) bbcode/class_bbcode_legacy.php, (24) editor/class_editor_rte.php, (25) editor/class_editor_std.php, (26) post/class_post.php, (27) post/class_post_edit.php, (28) post/class_post_new.php, (29) and post/class_post_reply.php in the sources/classes directory; (30) sources/components_acp/registration_DEPR.php; (31) sources/handlers/han_paysubscriptions.php; (32) func_usercp.php; (33) search_mysql_ftext.php, and (34) search_mysql_man.php in the sources/lib/ directory; and (35) convert/auth.php.bak, (36) external/auth.php, and (37) ldap/auth.php in the sources/loginauth directory.

5.0
2006-03-02 CVE-2006-0965 NCP Network Communications Multiple vulnerability in NCP Network Communications Secure Client 8.11Build146

NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass security protections and configure privileged options via a long argument to ncpmon.exe, which provides access to alternate privileged menus, possibly due to a buffer overflow.

4.6
2006-03-02 CVE-2006-0964 NCP Network Communications Multiple vulnerability in NCP Network Communications Secure Client 8.11Build146

Client Firewall in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass firewall program execution rules by replacing an allowed program with an arbitrary program.

4.6
2006-03-02 CVE-2006-0963 Stlport Project Classic Buffer Overflow vulnerability in Stlport Project Stlport 5.0.2

Multiple buffer overflows in STLport 5.0.2 might allow local users to execute arbitrary code via (1) long locale environment variables to a strcpy function call in c_locale_glibc2.c and (2) long arguments to unspecified functions in num_put_float.cpp.

4.6
2006-03-03 CVE-2006-0985 Wordpress Cross-Site Scripting vulnerability in WordPress

Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters.

4.3
2006-03-03 CVE-2006-0984 EJ3 Cross-Site Scripting vulnerability in EJ3 Topo 2.2.178

Cross-site scripting (XSS) vulnerability in inc_header.php in EJ3 TOPo 2.2.178 allows remote attackers to inject arbitrary web script or HTML via the gTopNombre parameter.

4.3
2006-03-03 CVE-2006-0983 David Barrett Cross-Site Scripting vulnerability in David Barrett Qwikiwiki 1.4

Cross-site scripting (XSS) vulnerability in index.php in QwikiWiki 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

4.3
2006-03-03 CVE-2006-0980 JAY Eckles Cross-Site Scripting vulnerability in JAY Eckles CGI Calendar 2.7

Multiple cross-site scripting (XSS) vulnerabilities in Jay Eckles CGI Calendar 2.7 allow remote attackers to inject arbitrary web script or HTML via the year parameter in (1) index.cgi and (2) viewday.cgi.

4.3
2006-03-03 CVE-2006-0978 Argosoft HTML Injection vulnerability in Argosoft Mail Server 1.8.8.5

Multiple cross-site scripting (XSS) vulnerabilities in the View Headers (aka viewheaders) functionality in ArGoSoft Mail Server Pro 1.8.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the Subject header, (2) the From header, and (3) certain other unspecified headers.

4.3
2006-03-03 CVE-2006-0974 Battleaxe Software Cross-Site Scripting vulnerability in Battleaxe Software Bttlxeforum 2.0

Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter.

4.3
2006-03-02 CVE-2006-0958 Zoneo Soft HTML Injection vulnerability in freeForum

Cross-site scripting (XSS) vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) subject parameters.

4.3
2006-03-01 CVE-2006-0946 Thomson Cross-Site Scripting vulnerability in Thomson SpeedTouch 500 Series

Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter to the LocalNetwork page.

4.3
2006-03-01 CVE-2006-0941 Cynical Games Input Validation vulnerability in Cynical Games Shoutlive 1.1.0

Multiple cross-site scripting (XSS) vulnerabilities in post.php in ShoutLIVE 1.1.0 allow remote attackers to inject arbitrary web script or HTML via certain variables when posting new messages.

4.3
2006-03-01 CVE-2006-0938 EZ Cross-Site Scripting vulnerability in EZ Publish

Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the RefererURL parameter.

4.3
2006-02-28 CVE-2006-0934 Limbo CMS HTML Injection vulnerability in Limbo CMS Limbo CMS 1.0.4.2

Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the message field in the Contact Form.

4.3
2006-02-28 CVE-2006-0933 Phpx HTML Injection vulnerability in PHPx 3.5.9

Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a url XCode tag in a posted message.

4.3
2006-02-28 CVE-2006-0924 Brown Bear Software Cross-Site Scripting vulnerability in Brown Bear Software Ical 3.10

Cross-site scripting (XSS) vulnerability in Brown Bear iCal 3.10 allows remote attackers to inject arbitrary web script or HTML via the Calendar Text field when a new event is added.

4.3
2006-02-28 CVE-2006-0923 Myphpnuke Cross-Site Scripting vulnerability in MyPHPNuke

Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the letter parameter in reviews.php and (2) the dcategory parameter in download.php.

4.3
2006-03-03 CVE-2006-0981 E Merge Remote Directory Traversal vulnerability in E-Merge Winace 2.6

Directory traversal vulnerability in e-merge WinAce 2.6 and earlier allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.

4.0
2006-02-28 CVE-2006-0930 Argosoft Directory Traversal vulnerability in Argosoft Mail Server 1.8

Directory traversal vulnerability in Webmail in ArGoSoft Mail Server Pro 1.8 allows remote authenticated users to read arbitrary files via a ..

4.0
2006-02-28 CVE-2006-0929 Argosoft Remote Directory Traversal vulnerability in Argosoft Mail Server 1.8.8.1

Directory traversal vulnerability in the IMAP server in ArGoSoft Mail Server Pro 1.8.8.1 allows remote authenticated users to create arbitrary folders via a ..

4.0

12 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-03-03 CVE-2006-0389 Apple Multiple vulnerability in Apple Mac OS X Security Update 2006-001

Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vectors involving RSS feeds.

2.6
2006-03-03 CVE-2006-0388 Apple Code Injection vulnerability in Apple mac OS X and mac OS X Server

Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources.

2.6
2006-02-28 CVE-2006-0935 Microsoft Denial Of Service vulnerability in Microsoft Word 2003

Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz.

2.6
2006-02-28 CVE-2006-0927 JGS XA
Woltlab
Cross-Site Scripting vulnerability in JGS-Gallery Module

Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid parameter in (c) jgs_galerie_slideshow.php.

2.6
2006-02-28 CVE-2006-0926 Smithmicro Remote Directory Traversal vulnerability in StuffIt and ZipMagic

Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt Expander 9.0.0.21 Engine 9.0.0.21 allow remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.

2.6
2006-03-02 CVE-2006-0967 NCP Network Communications Resource Management Errors vulnerability in NCP Network Communications Secure Client 8.11Build146

NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to cause a denial of service (memory usage and cpu utilization) via a flood of arbitrary UDP datagrams to ports 0 to 65000.

2.1
2006-03-02 CVE-2006-0966 NCP Network Communications Resource Management Errors vulnerability in NCP Network Communications Secure Client 8.11Build146

NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to cause a denial of service (CPU consumption) via a large number of arguments to ncprwsnt.exe, possibly due to a buffer overflow.

2.1
2006-02-28 CVE-2006-0917 Melange Information Disclosure vulnerability in Melange Chat System 1.10

Melange Chat Server (aka M-Chat), when accessed via a web browser, automatically sends cookies and other sensitive information for a server to any port specified in the associated link, which allows local users on that server to read the cookies from HTTP headers and possibly gain sensitive information, such as credentials, by setting up a listening port and reading the credentials when the victim clicks on the link.

2.1
2006-03-03 CVE-2006-0391 Apple Multiple vulnerability in Apple Mac OS X Security Update 2006-001

Directory traversal vulnerability in the BOM framework in Mac OS X 10.x before 10.3.9 and 10.4 before 10.4.5 allows user-assisted attackers to overwrite or create arbitrary files via an archive that is handled by BOMArchiveHelper.

1.7
2006-03-03 CVE-2006-0386 Apple Multiple vulnerability in Apple Mac OS X Security Update 2006-001

FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled.

1.7
2006-03-02 CVE-2006-0956 Nufw Remote TLS Connection Handling Denial of Service vulnerability in Nufw Firewall 1.0.20

nuauth in NuFW before 1.0.21 does not properly handle blocking TLS sockets, which allows remote authenticated users to cause a denial of service (service hang) by flooding packets at the authentication server.

1.7
2006-02-28 CVE-2006-0920 OI SQL Injection vulnerability in OI Email Marketing System 3.0

Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server's FTP password in cleartext on a Configuration web page, which allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the password.

1.7