Weekly Vulnerabilities Reports > November 13 to 19, 2006

Overview

90 new vulnerabilities reported during this period, including 6 critical vulnerabilities and 52 high severity vulnerabilities. This weekly summary report vulnerabilities in 77 products from 64 vendors including Microsoft, Grisoft, Dynamic Dataworx, Campware ORG, and Superfreaker Studios. Vulnerabilities are notably categorized as "Numeric Errors", "Improper Restriction of Operations within the Bounds of a Memory Buffer", "Improper Input Validation", "Resource Management Errors", and "Permissions, Privileges, and Access Controls".

  • 85 reported vulnerabilities are remotely exploitables.
  • 23 reported vulnerabilities have public exploit available.
  • 1 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 89 reported vulnerabilities are exploitable by an anonymous user.
  • Microsoft has the most reported vulnerabilities, with 7 reported vulnerabilities.
  • Grisoft has the most reported critical vulnerabilities, with 2 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

6 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-11-18 CVE-2006-5972 Netgear Buffer Overflow vulnerability in Netgear Wg111V2 and Wg111V2 Driver

Stack-based buffer overflow in WG111v2.SYS in NetGear WG111v2 wireless adapter (USB) allows remote attackers to execute arbitrary code via a long 802.11 beacon request.

10.0
2006-11-18 CVE-2006-5819 Verity Information Disclosure and Request Proxying vulnerability in Verity Ultraseek

Verity Ultraseek before 5.7 allows remote attackers to use the server as a proxy for web attacks and host scanning via a direct request to the highlight/index.html script.

10.0
2006-11-16 CVE-2006-5940 Grisoft Numeric Errors vulnerability in Grisoft AVG Antivirus

Unspecified vulnerability in Grisoft AVG Anti-Virus before 7.1.407 has unknown impact and remote attack vectors related to "Integer Issues" and parsing of .EXE files.

10.0
2006-11-16 CVE-2006-5938 Grisoft Improper Input Validation vulnerability in Grisoft AVG Antivirus

Grisoft AVG Anti-Virus before 7.1.407 has unknown impact and remote attack vectors involving an uninitialized variable and a crafted CAB file.

10.0
2006-11-15 CVE-2006-5912 Campware ORG Remote Security vulnerability in Campware.Org Campsite 2.6.0/2.6.1

Unspecified vulnerability in Campware Campsite before 2.6.2 has unknown impact and attack vectors, related to a "Security fix for you-know-what," possibly related to encrypted passwords.

10.0
2006-11-14 CVE-2006-4691 Microsoft Remote Code Execution vulnerability in Microsoft Windows 2000 and Windows XP

Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.

10.0

52 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-11-14 CVE-2006-5882 Linksys
Broadcom
Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products

Stack-based buffer overflow in the Broadcom BCMWL5.SYS wireless device driver 3.50.21.10, as used in Cisco Linksys WPC300N Wireless-N Notebook Adapter before 4.100.15.5 and other products, allows remote attackers to execute arbitrary code via an 802.11 response frame containing a long SSID field.

8.3
2006-11-16 CVE-2006-5939 Grisoft Divide BY Zero vulnerability in Grisoft AVG Antivirus

Grisoft AVG Anti-Virus before 7.1.407 allows remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers a divide-by-zero error.

7.8
2006-11-17 CVE-2006-5962 Hpecs Shopping Cart SQL-Injection vulnerability in Hpecs Shopping Cart

Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.

7.5
2006-11-17 CVE-2006-5961 Pegasus Buffer Overflow vulnerability in Pegasus Mercury Mail Transport System 4.0.1B

Buffer overflow in Mercury Mail Transport System 4.01b for Windows has unknown impact and attack vectors, as originally reported in a GLEG VulnDisco pack.

7.5
2006-11-17 CVE-2006-5959 WEB Inhabit Unspecified vulnerability in web Inhabit A+ Store E-Commerce

SQL injection vulnerability in browse.asp in A+ Store E-Commerce allows remote attackers to execute arbitrary SQL commands via the ParentID parameter.

7.5
2006-11-17 CVE-2006-5955 20 20 Applications SQL-Injection vulnerability in 20 20 Datashed

SQL injection vulnerability in listings.asp in 20/20 DataShed (aka Real Estate Listing System) allows remote attackers to execute arbitrary SQL commands via the itemID parameter.

7.5
2006-11-17 CVE-2006-5954 Netvios SQL-Injection vulnerability in Netvios

SQL injection vulnerability in page.asp in NetVIOS 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsID parameter.

7.5
2006-11-17 CVE-2006-5952 ASP Smiley SQL-Injection vulnerability in ASP Smiley ASP Smiley 1.0

SQL injection vulnerability in admin/default.asp in ASP Smiley 1.0 allows remote attackers to execute arbitrary SQL commands via the Username field.

7.5
2006-11-17 CVE-2006-5951 Exophpdesk Remote File Include vulnerability in Exophpdesk 1.2

PHP remote file inclusion vulnerability in pipe.php in Exophpdesk 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter.

7.5
2006-11-17 CVE-2006-5948 Ringsworld Remote File Include vulnerability in Ringsworld PHPpeanuts 1.1

PHP remote file inclusion vulnerability in pntUnit/Inspect.php in phpPeanuts 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the Include parameter.

7.5
2006-11-17 CVE-2006-5943 Website Designs FOR Less Input Validation vulnerability in Inventory Manager

Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote attackers to execute arbitrary SQL commands via the (1) pictable, (2) picfield, or (3) where parameter.

7.5
2006-11-16 CVE-2006-5937 Grisoft Integer Overflow OR Wraparound vulnerability in Grisoft AVG Antivirus

Multiple integer overflows in Grisoft AVG Anti-Virus before 7.1.407 allow remote attackers to execute arbitrary code via crafted (1) CAB or (2) RAR archives that trigger a heap-based buffer overflow.

7.5
2006-11-16 CVE-2006-5936 Sitexpress SQL Injection vulnerability in SiteXpress E-Commerce System Dept.ASP

SQL injection vulnerability in dept.asp in SiteXpress E-Commerce System allows remote attackers to execute arbitrary SQL commands via the id parameter.

7.5
2006-11-16 CVE-2006-5935 Shopsystems SQL Injection vulnerability in Shopsystems 4.0

SQL injection vulnerability in index.php in ShopSystems 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the sessid parameter.

7.5
2006-11-16 CVE-2006-5934 Iexpress SQL Injection vulnerability in Iexpress Estate Agent Manager 1.3

SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the UserName field.

7.5
2006-11-16 CVE-2006-5933 Ultrasite SQL-Injection vulnerability in Ultrasite 1.0

SQL injection vulnerability in update.asp in UltraSite 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

7.5
2006-11-16 CVE-2006-5932 Kahua Authentication Bypass vulnerability in Kahua Shared User Database

Kahua before 0.7, when running multiple applications under a single supervisor, grants application access on the basis of username instead of username and database name, which allows remote authenticated users to obtain unauthorized access if different databases assign the same username to different user accounts.

7.5
2006-11-16 CVE-2006-5930 Aigaion Remote File Include vulnerability in Aigaion 1.2.1

Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) _basicfunctions.php, or (2) pageactionauthor.php.

7.5
2006-11-16 CVE-2006-5929 Phpjobscheduler Remote Security vulnerability in PHPjobscheduler 3.0

PHP remote file inclusion vulnerability in firepjs.php in Phpjobscheduler 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter.

7.5
2006-11-16 CVE-2006-5928 Phpjobscheduler Remote File Include vulnerability in PHPjobscheduler 3.0

Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter to (1) add-modify.php, (2) delete.php, (3) modify.php, and (4) phpjobscheduler.php.

7.5
2006-11-16 CVE-2006-5927 ASP Scripter SQL Injection vulnerability in ASP Scripter Easy Portal and Live Support

SQL injection vulnerability in cpLogin.asp in ASP Scripter Easy Portal 1.4 and Live Support 1.3 allows remote attackers to execute arbitrary SQL commands via the Password parameter.

7.5
2006-11-16 CVE-2006-5926 Vallheru SQL Injection vulnerability in Vallheru 1.0.6

Multiple SQL injection vulnerabilities in mail.php in Vallheru before 1.0.7 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) to parameters.

7.5
2006-11-15 CVE-2006-5925 Elinks
Links
Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.
7.5
2006-11-15 CVE-2006-5923 Chris MAC Remote File Include vulnerability in GimeScripts Shopping Catalog

PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter.

7.5
2006-11-15 CVE-2006-5919 Activecampaign Remote File Include vulnerability in Activecampaign Knowledgebuilder 2.2

PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the visEdit_root parameter, a different vector than CVE-2003-1131.

7.5
2006-11-15 CVE-2006-5918 PHP Rapid Kill Unspecified vulnerability in PHP Rapid Kill PHP Rapid Kill 5.7Pro

Unrestricted file upload vulnerability in RapidKill (aka PHP Rapid Kill) 5.7 Pro, and certain other versions, allows remote attackers to upload and execute arbitrary PHP scripts via the "Link to Download" field.

7.5
2006-11-15 CVE-2006-5914 Samedia Input Validation vulnerability in Samedia LandShop LS.PHP

SQL injection vulnerability in ls.php in SAMEDIA LandShop allows remote attackers to execute arbitrary SQL commands via the infield parameter.

7.5
2006-11-15 CVE-2006-5911 Campware ORG Remote File Include vulnerability in Campware.Org Campsite 2.6.0/2.6.1

Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) Alias.php, (2) Article.php, (3) ArticleAttachment.php, (4) ArticleComment.php, (5) ArticleData.php, (6) ArticleImage.php, (7) ArticleIndex.php, (8) ArticlePublish.php, (9) ArticleTopic.php, (10) ArticleType.php, (11) ArticleTypeField.php, (12) Attachment.php, (13) Country.php, (14) DatabaseObject.php, (15) Event.php, (16) IPAccess.php, (17) Image.php, (18) Issue.php, (19) IssuePublish.php, (20) Language.php, (21) Log.php, (22) LoginAttempts.php, (23) Publication.php, (24) Section.php, (25) ShortURL.php, (26) Subscription.php, (27) SubscriptionDefaultTime.php, (28) SubscriptionSection.php, (29) SystemPref.php, (30) Template.php, (31) TimeUnit.php, (32) Topic.php, (33) UrlType.php, (34) User.php, and (35) UserType.php in implementation/management/classes/; (36) configuration.php and (37) db_connect.php in implementation/management/; and (38) LocalizerConfig.php and (39) LocalizerLanguage.php in implementation/management/priv/localizer/.

7.5
2006-11-15 CVE-2006-5910 Campware ORG Remote File Include vulnerability in Campware.Org Campsite 2.6.0/2.6.1

Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) bugreporter/thankyou.php and (2) feedback/thankyou.php in implementation/management/priv/.

7.5
2006-11-15 CVE-2006-5908 Lucas Rodriguez SAN Pedro SQL Injection vulnerability in Lucas Rodriguez SAN Pedro YET Another News System 0.2B

Multiple SQL injection vulnerabilities in the login_user function in yans.func.php in Lucas Rodriguez San Pedro Yet Another News System (YANS) 0.2b allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.

7.5
2006-11-15 CVE-2006-5907 Jean Christophe Ramos SQL Injection vulnerability in Jean-Christophe Ramos BAN and Pls-Bannieres

SQL injection vulnerability in modules/bannieres/bannieres.php in Jean-Christophe Ramos SCRIPT BANNIERES (aka ban 0.1 and PLS-Bannieres 1.21) allows remote attackers to execute arbitrary SQL commands via the id parameter.

7.5
2006-11-15 CVE-2006-5904 Mwchat PRO Remote Security vulnerability in Mwchat PRO Mwchat PRO 7.0

Multiple PHP remote file inclusion vulnerabilities in MWChat Pro 7.0 allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[MWCHAT_Libs] parameter to (1) about.php, (2) buddy.php, (3) chat.php, (4) dialog.php, (5) head.php, (6) help.php, (7) index.php, and (8) license.php, different vectors than CVE-2005-1869.

7.5
2006-11-15 CVE-2006-5903 Rahul Jonna Remote Security vulnerability in Gspace

Rahul Jonna Gmail File Space (GSpace) allows remote attackers to perform virtual filesystem actions via e-mail messages with certain subject lines, as demonstrated by (1) a GSPACE "2174|1|1|1|gs:/ d$" message, which injects a new file into the filesystem; and (2) a GSPACE "|-135|1|1|0|gs:/ d$" message, which creates a folder.

7.5
2006-11-15 CVE-2006-5902 Viksoe Remote Security vulnerability in Gmail Drive

viksoe GMail Drive shell extension allows remote attackers to perform virtual filesystem actions via e-mail messages with certain subject lines, as demonstrated by (1) a GMAILFS: [13;a;1] message with a new filename and a file attachment, which injects a new file into the filesystem; (2) a GMAILFS: [13;a;1] message with an existing filename and a file attachment, which overwrites existing file content; and (3) a GMAILFS: [14;a;1] message, which creates a folder.

7.5
2006-11-14 CVE-2006-5895 Encapscms Remote File Include vulnerability in Encapscms 0.3.6

PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

7.5
2006-11-14 CVE-2006-5893 Iwonder Designs Remote File Include vulnerability in Iwonder Designs Storystream 0.4.0.0

Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) mysql.php and (2) mysqli.php in include/classes/pear/DB/.

7.5
2006-11-14 CVE-2006-5892 THE NET Guys SQL Injection vulnerability in Aspired2Poll MoreInfo.ASP

SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

7.5
2006-11-14 CVE-2006-5891 Superfreaker Studios SQL-Injection vulnerability in Superfreaker Studios Ustore 1.0

SQL injection vulnerability in detail.asp in Superfreaker Studios UStore 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

7.5
2006-11-14 CVE-2006-5890 Superfreaker Studios SQL-Injection vulnerability in Superfreaker Studios Usupport 1.0

SQL injection vulnerability in detail.asp in Superfreaker Studios USupport 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

7.5
2006-11-14 CVE-2006-5888 Superfreaker Studios SQL-Injection vulnerability in Superfreaker Studios Upublisher 1.0

SQL injection vulnerability in viewarticle.asp in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

7.5
2006-11-14 CVE-2006-5887 Dynamic Dataworx SQL Injection vulnerability in Dynamic Dataworx Nuschool 1.0

SQL injection vulnerability in CampusNewsDetails.asp in Dynamic Dataworx NuSchool 1.0 allows remote attackers to execute arbitrary SQL commands via the NewsID parameter.

7.5
2006-11-14 CVE-2006-5886 Dynamic Dataworx SQL Injection vulnerability in Dynamic Dataworx Nurealestate 1.0

SQL injection vulnerability in propertysdetails.asp in Dynamic Dataworx NuRealestate (NuRems) 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the PropID parameter.

7.5
2006-11-14 CVE-2006-5885 Dynamic Dataworx SQL Injection vulnerability in Dynamic Dataworx Nustore 1.0

SQL injection vulnerability in Products.asp in NuStore 1.0 allows remote attackers to execute arbitrary SQL commands via the SubCatagoryID parameter.

7.5
2006-11-14 CVE-2006-4688 Microsoft Remote Code Execution vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP

Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."

7.5
2006-11-14 CVE-2006-5884 Microsoft Unspecified vulnerability in Microsoft IE and Internet Explorer

Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5.01 through 6 have unknown impact and remote attack vectors, possibly related to (1) Danim.dll and (2) Lmrt.dll, a different set of vulnerabilities than CVE-2006-4446 and CVE-2006-4777.

7.5
2006-11-14 CVE-2006-3445 Microsoft Numeric Errors vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP

Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results in a heap-based buffer overflow.

7.5
2006-11-14 CVE-2006-5881 Dynamic Dataworx SQL Injection vulnerability in Dynamic Dataworx Nucommunity 1.0

SQL injection vulnerability in cl_CatListing.asp in Dynamic Dataworx NuCommunity 1.0 allows remote attackers to execute arbitrary SQL commands via the cl_cat_ID parameter.

7.5
2006-11-14 CVE-2006-5880 Isystems SQL Injection vulnerability in Isystems Munch PRO 1.0

SQL injection vulnerability on the subMenu page in switch.asp in Munch Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

7.5
2006-11-14 CVE-2006-5879 Aspportal SQL Injection vulnerability in Aspportal 3.0.0/3.1.0/3.1.1

SQL injection vulnerability in default1.asp in ASPPortal 4.0.0 beta and earlier allows remote attackers to execute arbitrary SQL commands via the Poll_ID parameter, a different vector than CVE-2006-1353.

7.5
2006-11-14 CVE-2006-5878 Edgewall Software Cross-Site Request Forgery vulnerability in Trac

Cross-site request forgery (CSRF) vulnerability in Edgewall Trac 0.10 and earlier allows remote attackers to perform unauthorized actions as other users via unknown vectors.

7.5
2006-11-14 CVE-2006-4251 Powerdns Remote Denial of Service and Buffer Overflow vulnerability in PowerDNS

Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query that prevents Recursor from properly calculating the TCP DNS query length.

7.5
2006-11-18 CVE-2006-4413 Apple Remote Desktop Insecure Default Package Permission vulnerability in Apple Remote Desktop 2.0/2.1/3.0

Apple Remote Desktop before 3.1 uses insecure permissions for certain built-in packages, which allows local users on an Apple Remote Desktop administration system to modify the packages and gain root privileges on client systems that use the packages.

7.2

28 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-11-17 CVE-2006-5960 WEB Inhabit Unspecified vulnerability in web Inhabit A+ Store E-Commerce

Multiple cross-site scripting (XSS) vulnerabilities in account_login.asp in A+ Store E-Commerce allow remote attackers to inject arbitrary web script or HTML via the (1) username (txtUserName) and (2) password (txtPassword) parameters.

6.8
2006-11-17 CVE-2006-5958 Infinicart Cross-Site Scripting vulnerability in infinicart

Multiple cross-site scripting (XSS) vulnerabilities in INFINICART allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password fields in (a) login.asp, (3) search field in (b) search.asp, and (4) email field in (c) sendpassword.asp.

6.8
2006-11-17 CVE-2006-5942 Website Designs FOR Less Input Validation vulnerability in Inventory Manager

Cross-site scripting (XSS) vulnerability in inventory/display/display_results.asp in Website Designs For Less Inventory Manager allows remote attackers to inject arbitrary web script or HTML via the category parameter.

6.8
2006-11-15 CVE-2006-5915 Samedia Input Validation vulnerability in Samedia LandShop LS.PHP

Multiple cross-site scripting (XSS) vulnerabilities in ls.php in SAMEDIA LandShop allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) CAT_ID, (3) keyword, (4) search_area, (5) search_type, (6) infield, or (7) search_order parameter.

6.8
2006-11-15 CVE-2006-5900 Zend Cross-Site Scripting vulnerability in Zend Framework Preview 0.2.0

Cross-site scripting (XSS) vulnerability in the incubator/tests/Zend/Http/_files/testRedirections.php sample code in Zend Framework Preview 0.2.0 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.

6.8
2006-11-14 CVE-2006-5894 Rama CMS Local File Include vulnerability in Rama CMS Lang Parameter

Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a ..

6.8
2006-11-17 CVE-2006-5966 Panda Resource Management Errors vulnerability in Panda Activescan 5.0/5.53.00

Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to (1) reboot the system using the Reinicializar method in the ActiveScan.1 ActiveX control, or (2) determine arbitrary file existence and size via the ObtenerTamano method in the PAVPZ.SOS.1 ActiveX control.

6.4
2006-11-15 CVE-2006-5913 Microsoft Remote Security vulnerability in Microsoft IE 7.0

Microsoft Internet Explorer 7 allows remote attackers to (1) cause a security certificate from a secure web site to appear invalid via a link to res://ieframe.dll/sslnavcancel.htm with the target site in the anchor identifier, which displays the site's URL in the address bar but causes Internet Explorer to report that the certificate is invalid, or (2) trigger a "The webpage no longer exists" report via a link to res://ieframe.dll/http_410.htm, a variant of CVE-2006-5805.

6.4
2006-11-15 CVE-2006-5905 WEB Directory PRO Remote Security vulnerability in Web Directory Pro

Web Directory Pro allows remote attackers to (1) backup the database and obtain the backup via a direct request to admin/backup_db.php or (2) modify configuration via a direct request to admin/options.php.

6.4
2006-11-15 CVE-2006-5924 Efficientip Cross-Site Scripting vulnerability in Efficientip Ipmanager 2.3

Cross-site scripting (XSS) vulnerability in index.php in Efficient IP iPmanager (IPm) 2.3 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.

5.8
2006-11-15 CVE-2006-5921 Wheatblog HTML Injection vulnerability in WheatBlog

Multiple cross-site scripting (XSS) vulnerabilities in add_comment.php in Wheatblog (wB) allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) WWW, and (3) Comment fields.

5.8
2006-11-17 CVE-2006-5967 Panda Remote vulnerability in Panda ActiveScan ActiveX Controls

Race condition in Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to cause memory corruption and execute arbitrary code via unknown vectors related to multiple invocations of the Analizar method in the ActiveScan.1 ActiveX control, which is not thread safe.

5.1
2006-11-16 CVE-2006-5931 Aigaion Remote Security vulnerability in Aigaion 1.2.1

Multiple PHP remote file inclusion vulnerabilities in Aigaion Web based bibliography management system 1.2.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to certain PHP scripts in (1) lib/actions/, (2) lib/displays/, (3) lib/editforms/, (4) lib/functions/, (5) scheme/, and (6) the root directory.

5.1
2006-11-14 CVE-2006-4687 Microsoft Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft IE and Internet Explorer

Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via crafted layout combinations involving DIV tags and HTML CSS float properties that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."

5.1
2006-11-18 CVE-2006-5971 Verity Directory Traversal vulnerability in Ultraseek

Absolute path traversal vulnerability in admin/logfile.txt in Verity Ultraseek before 5.6.2 allows remote attackers to read arbitrary files via the name variable.

5.0
2006-11-18 CVE-2006-5970 Verity Information Disclosure vulnerability in Ultraseek

Verity Ultraseek before 5.7 allows remote attackers to obtain sensitive information via direct requests with (1) a null ("%00") terminated url parameter to help/urlstatusgo.html; or missing parameters to (2) help/header.html, (3) help/footer.html, (4) spell.html, (5) coreforma.html, (6) daterange.html, (7) hits.html, (8) hitsnavbottom.html, (9) indexform.html, (10) indexforma.html, (11) languages.html, (12) nohits.html, (13) onehit1.html, (14) onehit2.html, (15) query.html, (16) queryform0.html, (17) queryform0a.html, (18) queryform1.html, (19) queryform1a.html, (20) queryform2.html, (21) queryform2a.html, (22) quicklinks.html, (23) relatedtopics.html, (24) signin.html, (25) subtopics.html, (26) thesaurus.html, (27) topics.html, (28) hitspagebar.html, (29) highlight/highlight.html, (30) highlight/highlight_one.html, and (31) highlight/topnav.html, which leaks the installation path in the resulting error message.

5.0
2006-11-17 CVE-2006-5950 Altools Unspecified vulnerability in Altools Alftp FTP Server 4.1Beta1

Unspecified vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote authenticated users to obtain the installation path via unknown vectors related to the REN command, probably due to response messages.

5.0
2006-11-17 CVE-2006-5949 Altools Unspecified vulnerability in Altools Alftp FTP Server 4.1Beta1

Directory traversal vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote attackers to create arbitrary directories via directory traversal sequences in a MKD request.

5.0
2006-11-17 CVE-2006-5947 Conxint Directory Traversal vulnerability in Conxint FTP Server 2.2.0603

Multiple directory traversal vulnerabilities in Conxint FTP Server 2.2.0603, and possibly earlier, allow remote attackers to read arbitrary files and list arbitrary directories via directory traversal sequences in (1) DIR (LIST or NLST) and (2) GET (RETR) commands.

5.0
2006-11-15 CVE-2006-5922 Wheatblog Information Disclosure vulnerability in Wheatblog

index.php in Wheatblog (wB) allows remote attackers to obtain sensitive information via certain values of the postPtr[] and next parameters, which reveals the path in an error message.

5.0
2006-11-15 CVE-2006-5909 Paul Tarjan Permissions, Privileges, and Access Controls vulnerability in Paul Tarjan Stanford Conference and Research Forum Beta

generaloptions.php in Paul Tarjan Stanford Conference And Research Forum (SCARF) before 20070227 does not require the admin privilege, which allows remote attackers to reconfigure the application or its user accounts.

5.0
2006-11-15 CVE-2006-5901 Hawking Technology Denial-Of-Service vulnerability in Wr254-Ca Wireless Router

Hawking Technology wireless router WR254-CA uses a hardcoded IP address among the set of DNS server IP addresses, which could allow remote attackers to cause a denial of service or hijack the router by attacking or spoofing the server at the hardcoded address.

5.0
2006-11-15 CVE-2006-5898 Phpheaven Directory Traversal vulnerability in phpMyChat

Directory traversal vulnerability in localization/languages.lib.php3 in PhpMyChat 0.14.5 and earlier allows remote attackers to read arbitrary files via a ..

5.0
2006-11-15 CVE-2006-5897 Phpheaven Path Traversal vulnerability in PHPheaven PHPmychat Plus

Multiple directory traversal vulnerabilities in PhpMyChat Plus 1.9 and earlier allow remote attackers to read arbitrary files via a ..

5.0
2006-11-14 CVE-2006-4689 Microsoft Denial-Of-Service vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP

Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability."

5.0
2006-11-14 CVE-2006-4252 Powerdns Remote Denial of Service and Buffer Overflow vulnerability in PowerDNS

PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.

5.0
2006-11-17 CVE-2006-5968 ALT N Local Security vulnerability in Mdaemon

MDaemon 9.0.5, 9.0.6, 9.51, and 9.53, and possibly other versions, installs the MDaemon application folder with insecure permissions (Users create files/directories), which allows local users to execute arbitrary code by creating malicious RASAPI32.DLL or MPRAPI.DLL libraries in the MDaemon\APP folder, which is an untrusted search path element due to insecure permissions.

4.6
2006-11-14 CVE-2006-5198 Winzip Remote Code Execution vulnerability in Winzip 10.0

The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "unsafe methods."

4.0

4 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2006-11-14 CVE-2006-5883 Cpanel Cross-Site Scripting vulnerability in Cpanel 10

Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) dir parameter in (a) seldir.html, and the (2) user and (3) dir parameters in (b) newuser.html.

3.5
2006-11-17 CVE-2006-5793 Greg Roelofs Improper Input Validation vulnerability in Greg Roelofs Libpng

The sPLT chunk handling code (png_set_sPLT function in pngset.c) in libpng 1.0.6 through 1.2.12 uses a sizeof operator on the wrong data type, which allows context-dependent attackers to cause a denial of service (crash) via malformed sPLT chunks that trigger an out-of-bounds read.

2.6
2006-11-17 CVE-2006-5956 Xlinesoft Local Information Disclosure vulnerability in Xlinesoft PHPrunner 3.1

XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users to obtain sensitive information by reading the file.

2.1
2006-11-14 CVE-2006-5461 Avahi Unspecified vulnerability in Avahi

Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi.

2.1