Weekly Vulnerabilities Reports > March 27 to April 2, 2006

Overview

127 new vulnerabilities reported during this period, including 4 critical vulnerabilities and 31 high severity vulnerabilities. This weekly summary report vulnerabilities in 110 products from 92 vendors including Vscripts, Microsoft, Fusionzone, Debian, and Veritas. Vulnerabilities are notably categorized as "SQL Injection", "Code Injection", "Numeric Errors", "Improper Restriction of Operations within the Bounds of a Memory Buffer", and "Cross-site Scripting".

  • 117 reported vulnerabilities are remotely exploitables.
  • 7 reported vulnerabilities have public exploit available.
  • 4 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 120 reported vulnerabilities are exploitable by an anonymous user.
  • Vscripts has the most reported vulnerabilities, with 6 reported vulnerabilities.
  • Veritas has the most reported critical vulnerabilities, with 2 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

4 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-03-30 CVE-2006-1540 Microsoft Code Injection vulnerability in Microsoft Office

MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an Excel .xlw document, which triggers an access violation in excel.exe; (3) a Word document, which triggers an access violation in mso.dll in winword.exe; and (4) a PowerPoint document, which triggers an access violation in powerpnt.txt.

9.3
2006-03-30 CVE-2006-1545 Vscripts Remote Security vulnerability in Vscripts Vnews 1.2

Direct static code injection vulnerability in admin/config.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allows remote authenticated administrators to execute code by inserting the code into variables that are stored in admin/config.php.

9.0
2006-03-28 CVE-2006-0990 Veritas Remote Buffer Overflow vulnerability in VERITAS NetBackup

Stack-based buffer overflow in the NetBackup Catalog daemon (bpdbm) in Veritas NetBackup Enterprise Server 5.0 through 6.0 and DataCenter and BusinesServer 4.5FP and 4.5MP allows attackers to execute arbitrary code via unknown vectors.

9.0
2006-03-28 CVE-2006-0989 Veritas Remote Buffer Overflow vulnerability in VERITAS NetBackup

Stack-based buffer overflow in the volume manager daemon (vmd) in Veritas NetBackup Enterprise Server 5.0 through 6.0 and DataCenter and BusinesServer 4.5FP and 4.5MP allows attackers to execute arbitrary code via unknown vectors.

9.0

31 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-03-30 CVE-2006-1547 Apache Remote vulnerability in Apache Struts

ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.

7.8
2006-03-30 CVE-2006-1541 Ezaspsite SQL Injection vulnerability in EzASPSite Default.ASP

SQL injection vulnerability in Default.asp in EzASPSite 2.0 RC3 and earlier allows remote attackers to execute arbitrary SQL commands and obtain the SHA1 hash of the admin password via the Scheme parameter.

7.8
2006-03-28 CVE-2006-1403 Csdoom Buffer Overflow and Format String vulnerability in Csdoom 2005 0.7

Format string vulnerability in the PrintString function in c_console.cpp in client/server Doom (csDoom) 0.7 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via format string specifiers in strings passed to the console.

7.8
2006-03-31 CVE-2006-1563 Vscripts Remote Security vulnerability in Vscripts Vbook 2.0

Direct static code injection vulnerability in config.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allows remote administrators to execute arbitrary PHP code into the config file, which is included other [V]Book scripts.

7.6
2006-03-30 CVE-2006-1550 DIA Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in DIA

Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later before 0.95-pre6 allow user-assisted attackers to have an unknown impact via a crafted xfig file, possibly involving an invalid (1) color index, (2) number of points, or (3) depth.

7.6
2006-04-02 CVE-2006-1586 Internet Solutions Professionals SQL Injection vulnerability in ISP Site Man Admin_Login.ASP

SQL injection vulnerability in admin_login.asp in ISP of Egypt SiteMan allows remote attackers to execute arbitrary SQL commands via the pass parameter.

7.5
2006-04-02 CVE-2006-1579 Dbbs SQL Injection vulnerability in DbbS Topics.PHP

SQL injection vulnerability in topics.php in Dynamic Bulletin Board System (DbbS) 2.0-alpha and earlier allows remote attackers to execute arbitrary SQL commands via the limite parameter.

7.5
2006-04-02 CVE-2006-1576 Vscripts PL Input Validation vulnerability in Vscripts.Pl Qlnews 1.2

Direct static code injection vulnerability in QLnews 1.2 allows remote authenticated administrators to execute arbitrary PHP code by modifying config.php.

7.5
2006-04-01 CVE-2006-1573 Mediaslash COM Remote File Include vulnerability in Mediaslash.Com Mediaslash Gallery 0

PHP remote file inclusion vulnerability in index.php in MediaSlash Gallery allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter (part of the $page_menu variable).

7.5
2006-03-31 CVE-2006-1560 Skintech SQL Injection vulnerability in Skintech PHPnewsmanager 1.48

Multiple SQL injection vulnerabilities in SkinTech phpNewsManager 1.48 allow remote attackers to execute arbitrary SQL commands via unspecified parameters, possibly (1) id and (2) topicid, in (a) browse.php, (b) category.php, (c) gallery.php, (d) poll.php, and (e) possibly other unspecified scripts.

7.5
2006-03-31 CVE-2006-1559 PHP SQL-Injection vulnerability in PHP Script Index

SQL injection vulnerability in PHP Script Index allows remote attackers to execute arbitrary SQL commands via the search parameter.

7.5
2006-03-31 CVE-2006-1557 Skintech SQL Injection vulnerability in Skintech X-Changer 0.20

Multiple SQL injection vulnerabilities in X-Changer 0.2 allow remote attackers to execute arbitrary SQL commands via the (1) from and (2) into parameters in a calculate action, and the (3) id parameter in an edit action to index.php.

7.5
2006-03-31 CVE-2006-1555 Tachyon Authentication Bypass vulnerability in Tachyon Vsns Lemon 3.2.0

VSNS Lemon 3.2.0 allows remote attackers to bypass authentication and access password-protected articles by setting the vsns[topic_id] cookie to the targeted topic.

7.5
2006-03-30 CVE-2006-1543 Vscripts SQL Injection vulnerability in Vscripts Vnews 1.2

Multiple SQL injection vulnerabilities in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) loginvar parameter in (a) admin/admin.php, and the (2) news and (3) nom parameters in (b) news.php.

7.5
2006-03-30 CVE-2006-1539 BSD Games Local Privilege Escalation vulnerability in Bsd-Games Tetris-Bsd Gold

Multiple buffer overflows in the checkscores function in scores.c in tetris-bsd in bsd-games before 2.17-r1 in Gentoo Linux might allow local users with games group membership to gain privileges by modifying tetris-bsd.scores to contain crafted executable content, which is executed when another user launches tetris-bsd.

7.5
2006-03-30 CVE-2006-1536 Phoetux NET SQL Injection vulnerability in Phxcontacts 0.93/0.93.1

Multiple SQL injection vulnerabilities in Phoetux.net PhxContacts 0.93.1 beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) motclef and (2) nbr_line_view parameters in (a) carnet.php, and the (3) id_contact parameter in (b) contact_view.php.

7.5
2006-03-30 CVE-2006-1534 Null News SQL Injection vulnerability in Null News

Multiple SQL injection vulnerabilities in Null news allow remote attackers to execute arbitrary SQL commands via (1) the user_email parameter in (a) lostpass.php, and the (2) user_email and (3) user_username parameters in (b) sub.php and (c) unsub.php.

7.5
2006-03-30 CVE-2006-1533 Sourceworkshop SQL Injection vulnerability in Sourceworkshop Newsletter 1.0

SQL injection vulnerability in newsletter.php in Sourceworkshop newsletter 1.0 allows remote attackers to execute arbitrary SQL commands via the newsletteremail parameter.

7.5
2006-03-30 CVE-2006-1501 Oneorzero SQL Injection vulnerability in Oneorzero 1.6.3.0

SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in the kans action.

7.5
2006-03-30 CVE-2006-1500 Tilde SQL Injection vulnerability in Tilde CMS 3.0

SQL injection vulnerability in index.php in Tilde CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

7.5
2006-03-30 CVE-2006-1499 Source Workshop SQL Injection vulnerability in Source Workshop Vcounter 1.0

SQL injection vulnerability in vCounter.php in vCounter 1.0 allows remote attackers to execute arbitrary SQL commands via the URI (_SERVER[REQUEST_URI] variable).

7.5
2006-03-30 CVE-2006-1495 Netoffice
Phpcollab
SQL Injection vulnerability in PhpCollab Sendpassword.PHP

SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the "forgotten password" option.

7.5
2006-03-29 CVE-2006-1491 Horde Code Injection vulnerability in Horde Application Framework

Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.

7.5
2006-03-29 CVE-2006-1489 Fusionzone SQL Injection vulnerability in Fusionzone Couponzone 4.2

Multiple SQL injection vulnerabilities in FusionZONE CouponZONE local.cfm in 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) companyid, (2) scat, and (3) coid parameters.

7.5
2006-03-29 CVE-2006-1478 Turnkey WEB Tools File-Upload vulnerability in Turnkey web Tools PHP Live Helper 1.8

Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie, as demonstrated by uploading PHP code in a gl_session cookie to users.php, which causes the code to be stored in error.log, which is then included by initiate.php.

7.5
2006-03-29 CVE-2006-1477 Turnkey WEB Tools Remote File Include vulnerability in Turnkey web Tools PHP Live Helper 1.8

Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php, and (7) blank.php.

7.5
2006-03-28 CVE-2006-1426 Pixel Motion SQL Injection vulnerability in Pixel Motion

Multiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in index.php or bypass authentication via the (2) password parameter in admin/index.php.

7.5
2006-03-28 CVE-2006-1402 Csdoom Buffer Overflow and Format String vulnerability in Csdoom 20050.7

Buffer overflow in client/server Doom (csDoom) 0.7 and earlier allows remote attackers to (1) cause a denial of service via a long nickname or teamname to the SV_SetupUserInfo function or (2) execute arbitrary code via a long string sent when joining a match or a long chat message to the SV_BroadcastPrintf function.

7.5
2006-03-30 CVE-2006-1506 SUN Local Security vulnerability in Grid Engine

Unspecified vulnerability in rsh in Sun Microsystems Sun Grid Engine 5.3 before 20060327 and N1 Grid Engine 6.0 before 20060327 allows local users to gain root privileges.

7.2
2006-03-29 CVE-2006-1484 KYE Local Privilege Escalation vulnerability in Genius VideoCAM NB

Genius VideoCAM NB Driver does not drop privileges when saving files, which allows local users to gain privileges by opening arbitrary files via the "save as" dialog.

7.2
2006-03-28 CVE-2006-0991 Veritas Remote Buffer Overflow vulnerability in VERITAS NetBackup

Buffer overflow in the NetBackup Sharepoint Services server daemon (bpspsserver) on NetBackup 6.0 for Windows allows remote attackers to execute arbitrary code via crafted "Request Service" packets to the vnetd service (TCP port 13724).

7.1

86 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-04-02 CVE-2006-1577 Mantis Cross-Site Scripting vulnerability in Mantis View_All_Set.PHP

Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) start_day, (2) start_year, and (3) start_month parameters.

6.8
2006-04-02 CVE-2006-1575 Vscripts PL Input Validation vulnerability in Vscripts.Pl Qlnews 1.2

Multiple cross-site scripting (XSS) vulnerabilities in news.php in QLnews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorx and (2) newsx parameters.

6.8
2006-03-31 CVE-2006-1562 Vscripts Cross-Site Scripting vulnerability in Vscripts Vbook 2.0

Multiple cross-site scripting (XSS) vulnerabilities in index.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) autor, (2) www, (3) temat, and (4) tresc parameters.

6.8
2006-03-31 CVE-2006-1558 PHP Cross-Site Scripting vulnerability in PHP Script Index Search Parameter

Cross-site scripting (XSS) vulnerability in search.php in PHP Script Index allows remote attackers to inject arbitrary web script or HTML via the search parameter.

6.8
2006-03-31 CVE-2006-1556 AL Caricatier Cross-Site Scripting vulnerability in Al-Caricatier 2.5

Multiple cross-site scripting (XSS) vulnerabilities in view_caricatier.php in AL-Caricatier 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) CatName, (2) CaricatierID, or (3) CatID parameter.

6.8
2006-03-30 CVE-2006-1507 Phpkit Cross-Site Scripting vulnerability in PHPkit 1.6.03

Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error parameter to include.php, possibly due to a problem in login/login.php.

6.8
2006-03-29 CVE-2006-1485 Greymatter Unspecified vulnerability in Greymatter

gm-upload.cgi in Greymatter 1.3.1 allows remote authenticated users with upload privileges to execute arbitrary programs by uploading files to locations within the web root.

6.5
2006-03-29 CVE-2006-1481 PHP Ticket SQL Injection vulnerability in PHP Ticket PHP Ticket 0.5/0.6

SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL commands and obtain usernames and passwords via the frm_search_in parameter.

6.5
2006-04-02 CVE-2006-1584 Juliusz Julas Gonera Remote File Include vulnerability in Juliusz Julas Gonera Warcraft III Replay Parser PHP 1.8C

Unspecified vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to fopen function calls or file uploads.

6.4
2006-04-02 CVE-2006-1581 Blanknberg Directory Traversal vulnerability in Blanknberg 0.2

Directory traversal vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to read arbitrary files via a ..

6.4
2006-04-02 CVE-2006-1578 Index Data APS SQL-Injection vulnerability in Keystone Digital Library Suite

Multiple SQL injection vulnerabilities in Keystone Digital Library Suite (DLS) 1.5.4 and earlier allow remote attackers to execute arbitrary SQL commands via the subject_type_id parameter in (1) the index page and (2) the search module.

6.4
2006-04-02 CVE-2006-1583 Juliusz Julas Gonera Remote File Include vulnerability in Juliusz Julas Gonera Warcraft III Replay Parser PHP 1.8C

Cross-site scripting (XSS) vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via the page parameter.

5.8
2006-04-02 CVE-2006-1582 Blanknberg Cross-Site Scripting vulnerability in Blanknberg 0.2

Cross-site scripting (XSS) vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to inject arbitrary web script or HTML via the _path parameter.

5.8
2006-04-02 CVE-2006-1580 Websina Cross-Site Scripting vulnerability in Bugzero

Multiple cross-site scripting (XSS) vulnerabilities in Bugzero 4.3.1 and other versions allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in query.jsp and (2) entryId parameter in edit.jsp.

5.8
2006-04-01 CVE-2006-1574 Hitachi Cross-Site Scripting vulnerability in Hitachi Groupmax World Wide Web

Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web, World Wide Web Desktop, World Wide Web for Scheduler, and Desktop for Scheduler, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

5.8
2006-03-28 CVE-2006-1407 Webhost Automation Cross-Site Scripting vulnerability in Web Host Automation Ltd. Helm

Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp.

5.8
2006-03-28 CVE-2006-1405 Sheer Vision Technologies Cross-Site Scripting vulnerability in SweetSuite.NET Content Management System Search.ASPX

Cross-site scripting (XSS) vulnerability in search.aspx in SweetSuite.NET Content Management System (ssCMS) 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

5.8
2006-03-28 CVE-2006-1404 Industrial Imagination Cross-Site Scripting vulnerability in BlankOL Bol.CGI

Multiple cross-site scripting (XSS) vulnerabilities in bol.cgi in BlankOL 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) file or (2) function parameter.

5.8
2006-04-01 CVE-2006-1571 R2Xdesign SQL Injection vulnerability in R2Xdesign Qlitenews 20050701

Multiple SQL injection vulnerabilities in loginprocess.php in qliteNews 2005.07.01 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.

5.1
2006-04-01 CVE-2006-1569 Redcms Input Validation vulnerability in Redcms 0.1

Multiple SQL injection vulnerabilities in RedCMS 0.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters to (a) login.php or (b) register.php; or (3) u parameter to (c) profile.php.

5.1
2006-04-01 CVE-2006-1568 Redcms Input Validation vulnerability in Redcms 0.1

Multiple cross-site scripting (XSS) vulnerabilities in register.php in RedCMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) email, (2) location, or (3) website parameters.

5.1
2006-03-31 CVE-2006-1561 Vscripts SQL Injection vulnerability in Vscripts Vbook 2.0

SQL injection vulnerability in index.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allows remote attackers to execute arbitrary SQL commands via the x parameter.

5.1
2006-03-31 CVE-2006-1553 Tachyon SQL Injection vulnerability in Tachyon Vsns Lemon 3.2.0

SQL injection vulnerability in functions/final_functions.php in VSNS Lemon 3.2.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

5.1
2006-03-30 CVE-2006-1511 Microsoft Buffer Overflow vulnerability in Microsoft .NET Framework SDK MSIL Tools

Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.

5.1
2006-03-30 CVE-2006-1504 Arab Portal Cross-Site Scripting vulnerability in Arab Portal Arab Portal 2.0

Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the title parameter in (1) online.php and (2) download.php.

5.1
2006-03-30 CVE-2006-1503 Vwar Code Injection vulnerability in Vwar Virtual WAR

PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attackers to include and execute arbitrary PHP code via a URL in the vwar_root parameter.

5.1
2006-03-30 CVE-2006-1502 Mplayer Integer Overflow vulnerability in MPlayer

Multiple integer overflows in MPlayer 1.0pre7try2 allow remote attackers to cause a denial of service and trigger heap-based buffer overflows via (1) a certain ASF file handled by asfheader.c that causes the asf_descrambling function to be passed a negative integer after the conversion from a char to an int or (2) an AVI file with a crafted wLongsPerEntry or nEntriesInUse value in the indx chunk, which is handled in aviheader.c.

5.1
2006-03-29 CVE-2006-1480 Duda Remote Command Execution vulnerability in WEBalbum

Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and execute commands by (1) injecting code into local log files via GET commands, then (2) accessing that log via a ..

5.1
2006-03-28 CVE-2006-1421 Arthur Konze Webdesign SQL Injection vulnerability in Arthur Konze Webdesign Akocomment 2.0

Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acname or (2) contentid parameter.

5.1
2006-04-01 CVE-2006-1572 O2Php COM SQL Injection vulnerability in O2PHP Oxygen Post.PHP

SQL injection vulnerability in post.php in Oxygen 1.1.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a newthread action.

5.0
2006-03-31 CVE-2006-1552 Apple Numeric Errors vulnerability in Apple products

Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".

5.0
2006-03-31 CVE-2006-0052 GNU Denial Of Service vulnerability in GNU Mailman Attachment Scrubber Malformed MIME Message

The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a denial of service (mailing list delivery failure) via a multipart MIME message with a single part that has two blank lines between the first boundary and the end boundary.

5.0
2006-03-30 CVE-2006-1537 Webcalendar Information Disclosure vulnerability in Webcalendar 1.1.0

Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, (2) tests/add_duration_test.php, (3) tests/all_tests.php, (4) groups.php, (5) nonusers.php, (6) includes/settings.php, (7) includes/init.php, (8) includes/settings.php.orig, (9) includes/js/admin.php, (10) includes/js/edit_entry.php, (11) includes/js/edit_layer.php, (12) includes/js/export_import.php, (13) includes/js/popups.php, (14) includes/js/pref.php, or (15) includes/menu/index.php, which reveal the path in various error messages.

5.0
2006-03-30 CVE-2006-1505 Basic Analysis AND Security Engine Authentication Bypass vulnerability in Basic Analysis and Security Engine Base_maintenance.PHP

base_maintenance.php in Basic Analysis and Security Engine (BASE) before 1.2.4 (melissa), when running in standalone mode, allows remote attackers to bypass authentication, possibly by setting the standalone parameter to "yes".

5.0
2006-03-30 CVE-2006-1497 Vihor Cross-Site Scripting vulnerability in Vihor Vihordesign 1.0.6

Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter.

5.0
2006-03-29 CVE-2006-1492 Nikolay Avrionov Input Validation vulnerability in Explorer XP

Directory traversal vulnerability in dir.php in Explorer XP allows remote attackers to read arbitrary files via the chemin parameter.

5.0
2006-03-29 CVE-2006-1488 Activecampaign Remote Security vulnerability in Activecampaign Supporttrio 2.50.2

ActiveCampaign SupportTrio 2.5 allows remote attackers to obtain the full path of the server via invalid (1) article or (2) print parameters in a kb action to index.php, or (3) an invalid category parameter to modules/KB/pdf.php, which leaks the path in an error message.

5.0
2006-03-29 CVE-2006-1483 Desiderata Software Unspecified vulnerability in Desiderata Software Blazix web Server

Blazix Web Server before 1.2.6, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) .

5.0
2006-03-28 CVE-2006-1432 Fusionzone Information Disclosure vulnerability in Fusionzone Couponzone 4.2

fusionZONE couponZONE 4.2 allows remote attackers to obtain the full path of the web server, and other sensitive information, via invalid values, as demonstrated using manipulations associated with SQL.

5.0
2006-03-28 CVE-2006-1423 Ubbcentral SQL Injection vulnerability in Ubbcentral Ubb.Threads

SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands via the Number parameter.

5.0
2006-03-28 CVE-2006-1422 Jjwwebdesign SQL Injection vulnerability in Jjwwebdesign PHPbookingcalendar 1.0C

SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to execute arbitrary SQL commands via the event_id parameter.

5.0
2006-03-28 CVE-2006-1420 Arabless SQL Injection vulnerability in Arabless Saphplesson 2.0

SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands via the lessid parameter.

5.0
2006-03-28 CVE-2006-1419 Nuked Klan SQL Injection vulnerability in Nuked-Klan

SQL injection vulnerability in the Calendar module in nuked-klan 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php.

5.0
2006-03-28 CVE-2006-1412 TFT Gallery Information Disclosure vulnerability in TFT Gallery TFT Gallery 0.10

TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd.

5.0
2006-03-28 CVE-2006-1409 Vavoom Denial of Service vulnerability in Vavoom

Buffer overflow in Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (application crash) via an invalid comprLength value in a compressed packet.

5.0
2006-03-28 CVE-2006-1408 Vavoom Denial of Service vulnerability in Vavoom

Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via (1) a packet with no data or (2) a large packet, which prevents Vavoom from discarding the packet from the socket.

5.0
2006-03-30 CVE-2006-1538 Enova Local Security vulnerability in X-Wall Asic

The Enova X-Wall ASIC encrypts with a key obtained via Microwire from a serial EEPROM that stores the key in cleartext, which allows local users with physical access to obtain the key by reading and duplicating an EEPROM that is located on a hardware token, or by sniffing the Microwire bus.

4.9
2006-03-30 CVE-2006-1509 HP Local Denial of Service vulnerability in HP Hp-Ux 11.00/11.11/11.23

/sbin/passwd in HP-UX B.11.00, B.11.11, and B.11.23 before 20060326 "does not recover gracefully from some error conditions," which allows local users to cause a denial of service.

4.9
2006-03-31 CVE-2006-1566 Debian Packages Insecure RUNPATH vulnerability in Debian Linux 3.1

Untrusted search path vulnerability in libtunepimp-perl 0.4.2-1 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the tunepimp.so module, which might allow local users to gain privileges by installing malicious libraries in that directory.

4.6
2006-03-31 CVE-2006-1565 Debian Packages Insecure RUNPATH vulnerability in Debian Linux 3.1

Untrusted search path vulnerability in libgpib-perl 3.2.06-2 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the LinuxGpib.so module, which might allow local users to gain privileges by installing malicious libraries in that directory.

4.6
2006-03-31 CVE-2006-1564 Debian Packages Insecure RUNPATH vulnerability in Debian Linux 3.1

Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux includes RPATH values under the /tmp/svn directory for the (1) mod_authz_svn.so and (2) mod_dav_svn.so modules, which might allow local users to gain privileges by installing malicious libraries in that directory.

4.6
2006-04-01 CVE-2006-1570 Esqlanelapse Cross-Site Scripting vulnerability in Esqlanelapse 2.0/2.2

Cross-site scripting (XSS) vulnerability in Esqlanelapse 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

4.3
2006-04-01 CVE-2006-1567 Sitesearch Cross-Site Scripting vulnerability in SiteSearch Indexer Searchresults.ASP

Cross-site scripting (XSS) vulnerability in searchresults.asp in SiteSearch Indexer 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchField parameter.

4.3
2006-03-30 CVE-2006-1548 Apache Remote vulnerability in Apache Struts

Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via the parameter name, which is not filtered in the resulting error message.

4.3
2006-03-30 CVE-2006-1544 Vscripts Cross-Site Scripting vulnerability in Vscripts Vnews 1.2

Multiple cross-site scripting (XSS) vulnerabilities in news.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorkomentarza and (2) tresckomentarza parameters.

4.3
2006-03-30 CVE-2006-1535 Phoetux NET Cross-Site Scripting vulnerability in Phxcontacts 0.93/0.93.1

Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net PhxContacts 0.93.1 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter.

4.3
2006-03-30 CVE-2006-1532 Deltascripts Cross-Site Scripting vulnerability in Deltascripts PHP Classifieds 6.18/6.20

Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword parameter.

4.3
2006-03-30 CVE-2006-1508 MH Software Cross-Site Scripting vulnerability in MH Software Connect Daily 3.2.8

Multiple cross-site scripting (XSS) vulnerabilities in MH Software Connect Daily Web Calendar Software 3.2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) calendar_id, (2) style_sheet, and (3) start parameters in (a) ViewDay.html; the (4) txtSearch and (5) opgSearch parameters in (b) ViewSearch.html; the (6) calendar_id and (7) approved parameters in (c) ViewYear.html; the (8) item_type_id parameter in (d) ViewCal.html; and the (9) week parameter in (e) ViewWeek.html.

4.3
2006-03-30 CVE-2006-1498 Mediawiki HTML Injection vulnerability in MediaWiki Encoded Page Link

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.5.8 and 1.4.15 allows remote attackers to inject arbitrary web script or HTML via crafted encoded links.

4.3
2006-03-30 CVE-2006-1496 Vihor Cross-Site Scripting vulnerability in VihorDesign

Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error message for the failed fopen call.

4.3
2006-03-29 CVE-2006-1493 Nikolay Avrionov Input Validation vulnerability in Explorer XP

Cross-site scripting (XSS) vulnerability in dir.php in Explorer XP allows remote attackers to inject arbitrary web script or HTML via the chemin parameter.

4.3
2006-03-29 CVE-2006-1487 Activecampaign Cross-Site Scripting vulnerability in Activecampaign Supporttrio 2.50.2

Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the KnowledgeBase search module.

4.3
2006-03-29 CVE-2006-1486 Fusionzone Cross-Site Scripting vulnerability in RealestateZONE

Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) state parameters.

4.3
2006-03-29 CVE-2006-1482 Conftool Cross-Site Scripting vulnerability in Conftool 1.1

Cross-site scripting (XSS) vulnerability in index.php in ConfTool 1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

4.3
2006-03-29 CVE-2006-1479 Serge REY Input Validation vulnerability in Serge REY Gtd-PHP 0.5

Multiple cross-site scripting (XSS) vulnerabilities in Serge Rey gtd-php (aka Getting Things Done) 0.5 allow remote attackers to inject arbitrary web script or HTML via the Description field in (1) newProject.php, (2) newList.php, and (3) newWaitingOn.php; the Title field in (4) newProject.php, (5) newList.php, (6) newWaitingOn.php, (7) newChecklist.php, (8) newContext.php, and (9) newGoal.php; the (10) Category Name field in newCategory.php; the (11) listTitle field in listReport.php; the (12) projectName field in projectReport.php; and the (13) checklistTitle field in checklistReport.php.

4.3
2006-03-29 CVE-2006-1474 Raindance Cross-Site Scripting vulnerability in Web Conferencing Pro

Cross-site scripting (XSS) vulnerability in the "failed" functionality in Raindance Web Conferencing Pro allows remote attackers to inject arbitrary web script or HTML via the browser parameter.

4.3
2006-03-28 CVE-2006-1431 Fusionzone Cross-Site Scripting vulnerability in Fusionzone Couponzone 4.2

Cross-site scripting (XSS) vulnerability in local.cfm in fusionZONE couponZONE 4.2 allows remote attackers to inject arbitrary web script or HTML via URL-encoded (1) srchfor and (2) srchby parameters.

4.3
2006-03-28 CVE-2006-1430 Controlzx Cross-Site Scripting vulnerability in CONTROLzx HMS

Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS (formerly DRZES) 3.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dedicatedPlanID parameter to dedicated_order.php, (2) sharedPlanID parameter to shared_order.php, (3) plan_id parameter to customers/server_management.php, and (4) email field to customers/forgotpass.php.

4.3
2006-03-28 CVE-2006-1429 Fusionzone Cross-Site Scripting vulnerability in ClassifiedZONE Accountlogon.CFM

Cross-site scripting (XSS) vulnerability in accountlogon.cfm in classifiedZONE 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rtn parameter.

4.3
2006-03-28 CVE-2006-1428 Coinsoft Technologies Cross-Site Scripting vulnerability in phpCOIN

Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php.

4.3
2006-03-28 CVE-2006-1427 WEB APP ORG Cross-Site Scripting vulnerability in Web-App.Org and Web-App.Net

Multiple cross-site scripting (XSS) vulnerabilities in WebAPP 0.9.9.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) id, (3) num, (4) board, (5) cat, (6) real, (7) viewcat, (8) img, or (9) curcatname parameter in cgi-bin/index.cgi, or (10) vsSD parameter in /mods/calendar/index.cgi.

4.3
2006-03-28 CVE-2006-1425 Phpmyfamily Cross-Site Scripting vulnerability in PHPmyfamily 1.4.1

Cross-site scripting (XSS) vulnerability in track.php in phpmyfamily 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

4.3
2006-03-28 CVE-2006-1417 Caloris Planitia Technologies Cross-Site Scripting vulnerability in Caloris Planitia Technologies web Quiz PRO 1.0

Multiple cross-site scripting (XSS) vulnerabilities in Caloris Planitia Online Quiz System (aka Web Quiz pro), possibly 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) exam parameter in prequiz.asp or (2) msg parameter in student.asp.

4.3
2006-03-28 CVE-2006-1416 Xigla Cross-Site Scripting vulnerability in Absolute FAQ Manager

Cross-site scripting (XSS) vulnerability in afmsearch.aspx in Absolute FAQ Manager .NET 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the question parameter.

4.3
2006-03-28 CVE-2006-1415 Dotnetbb Cross-Site Scripting vulnerability in dotNetBB Forums dotNetBB

Cross-site scripting (XSS) vulnerability in iforget.aspx in dotNetBB 2.42EC SP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the em parameter.

4.3
2006-03-28 CVE-2006-1414 Toast Forums Cross-Site Scripting vulnerability in Toast Forums Toast Forums 1.6

Multiple cross-site scripting (XSS) vulnerabilities in toast.asp in Toast Forums 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) author, (2) subject, (3) message, or (4) dayprune parameter.

4.3
2006-03-28 CVE-2006-1413 Htmljunction Cross-Site Scripting vulnerability in EZHomePagePro

Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) adid or (2) aname parameter in (a) common/email.asp, (b) users/users_search.asp, or (c) users/users_profiles.asp; (3) page parameter in (d) users/users_calendar.asp; (4) usid parameter in (e) users/users_mgallery.asp; or (5) m parameter in (f) users/users_search.asp.

4.3
2006-03-28 CVE-2006-1411 Xigla Cross-Site Scripting vulnerability in Absolute Image Gallery XE

Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the shownew parameter in gallery.asp and (2) unspecified search module parameters.

4.3
2006-03-28 CVE-2006-1410 Xigla HTML Injection vulnerability in Xigla Absolute Live Support XE 2.0

Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute Live Support XE 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Screen name or (2) Session Topic field.

4.3
2006-03-28 CVE-2006-1406 Uniforum Cross-Site Scripting vulnerability in uniForum

Multiple cross-site scripting (XSS) vulnerabilities in wbadmlog.aspx in uniForum 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtuser or (2) txtpassword parameters.

4.3
2006-03-28 CVE-2006-1401 PHP Lite Cross-Site Scripting vulnerability in PHP Lite Calendar Express 2.2

Multiple cross-site scripting (XSS) vulnerabilities in search.php in Calendar Express 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) allwords or (2) oneword parameter.

4.3
2006-03-28 CVE-2006-1400 Metisware Cross-Site Scripting vulnerability in Metisware Instructor PersonalTaskEdit.ASP

Cross-site scripting (XSS) vulnerability in MyTasks/PersonalTaskEdit.asp in Metisware Instructor 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the Task parameter.

4.3
2006-03-28 CVE-2006-1399 PHP Lite Cross-Site Scripting vulnerability in PHP Lite Meeting Reserve 1.0Beta

Cross-site scripting (XSS) vulnerability in searchresult.php in Meeting Reserve 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the search_term parameter.

4.3
2006-03-28 CVE-2006-1398 Sixal HTML Injection vulnerability in Sixal G-Book 1.0

Cross-site scripting (XSS) vulnerability in guestbook.php in G-Book 1.0 allows remote attackers to inject arbitrary web script or HTML via the g_message parameter.

4.3
2006-03-28 CVE-2006-1397 Phpadsnew
Phppgads
Input Validation vulnerability in PHPAdsNew and PHPPGAds

Multiple cross-site scripting (XSS) vulnerabilities in (a) phpAdsNew and (b) phpPgAds before 2.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) certain parameters to the banner delivery module, which is not properly handled in the administrator interface, or (2) certain parameters to the login form.

4.3
2006-03-30 CVE-2006-1510 Microsoft Buffer Overflow vulnerability in Microsoft .NET Framework SDK MSIL Tools

Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method.

4.0

6 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-03-31 CVE-2006-1554 Tachyon HTML Injection vulnerability in Tachyon Vsns Lemon 3.2.0

Cross-site scripting (XSS) vulnerability in VSNS Lemon 3.2.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter while adding a comment.

2.6
2006-03-29 CVE-2006-1476 Microsoft Remote Security vulnerability in Windows XP Tablet PC Edition

Windows Firewall in Microsoft Windows XP SP2 produces incorrect application block alerts when the application filename is ".exe" (with no characters before the "."), which might allow local user-assisted users to trick a user into unblocking a Trojan horse program, as demonstrated by a malicious ".exe" program in a folder named "Internet Explorer," which triggers a question about whether to unblock the "Internet Explorer" program.

2.6
2006-03-28 CVE-2006-1418 Caloris Planitia Technologies Cross-Site Scripting vulnerability in Caloris Planitia Technologies School Management System

Cross-site scripting (XSS) vulnerability in default.asp in Caloris Planitia E-School Management System 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

2.6
2006-03-29 CVE-2006-1475 Microsoft Local Security vulnerability in Windows XP Tablet PC Edition

Windows Firewall in Microsoft Windows XP SP2 does not produce application alerts when an application is executed using the NTFS Alternate Data Streams (ADS) filename:stream syntax, which might allow local users to launch a Trojan horse attack in which the victim does not obtain the alert that Windows Firewall would have produced for a non-ADS file.

2.1
2006-03-30 CVE-2006-1059 Samba Local Information Disclosure vulnerability in Samba Machine Trust Account

The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain.

1.2
2006-03-27 CVE-2006-1066 Linux Local Denial Of Service vulnerability in Linux Kernel Get_Compat_Timespec and PTrace

Linux kernel 2.6.16-rc2 and earlier, when running on x86_64 systems with preemption enabled, allows local users to cause a denial of service (oops) via multiple ptrace tasks that perform single steps, which can cause corruption of the DEBUG_STACK stack during the do_debug function call.

1.2