Skip to content

customize
National Cyber Alert System
Cyber Security Bulletin SB07-267 archive

Vulnerability Summary for the Week of September 17, 2007

The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the NVD, which contains historical vulnerability information.

The vulnerabilities are based on the CVE vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:

  • High - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0

  • Medium - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9

  • Low - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9

Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.


High Vulnerabilities
Primary
Vendor -- Product
Description
Discovered
Published
CVSS ScoreSource & Patch Info
ajax -- file browser
PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP code via a URL in the approot parameter.
unknown
2007-09-17
7.5CVE-2007-4921
MILW0RM
XF
Alcatel -- OmniPCX Enterprise
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
unknown
2007-09-18
10.0CVE-2007-3010
FULLDISC
OTHER-REF
OTHER-REF
SECUNIA
auraCMS -- AuraCMS
Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute arbitrary PHP files via the image parameter, which places a file under files/.
unknown
2007-09-17
7.5CVE-2007-4905
MILW0RM
BID
auraCMS -- AuraCMS
Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pilih parameter.
unknown
2007-09-17
7.5CVE-2007-4908
MILW0RM
OTHER-REF
BID
Automated Solutions -- Modbus Slave ActiveX Control
Unspecified vulnerability in the Modbus/TCP Diagnostic function in MiniHMI.exe for the Automated Solutions Modbus Slave ActiveX Control before 1.5 allows remote attackers to corrupt the heap and possibly execute arbitrary code via malformed Modbus requests to TCP port 502.
unknown
2007-09-19
7.5CVE-2007-4827
OTHER-REF
OTHER-REF
BID
Avaya -- IP Softphone
Multiple buffer overflows in unspecified ActiveX controls in COM objects in Avaya IP Softphone R5.2 before SP3, and R6.0, allow remote attackers to execute arbitrary code via unspecified vectors.
unknown
2007-09-19
9.3CVE-2007-3286
OTHER-REF
BID
Axis -- 207W Camera
The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensitive information by sniffing the wireless network or by leveraging unspecified other vectors.
unknown
2007-09-18
9.3CVE-2007-4926
BUGTRAQ
OTHER-REF
OTHER-REF
BaoFeng -- Storm
Multiple buffer overflows in a certain ActiveX control in sparser.dll in Baofeng Storm 2.8 and earlier allow remote attackers to execute arbitrary code via malformed input in an unknown set of arguments or property values, a different DLL than CVE-2007-4816. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
unknown
2007-09-18
9.3CVE-2007-4943
FRSIRT
Boa -- Boa Webserver
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memory locations used for string constants, which allows remote attackers to change the admin password stored in memory via a long username in an HTTP Basic Authentication request.
unknown
2007-09-17
10.0CVE-2007-4915
BUGTRAQ
OTHER-REF
Chupix -- Chupix CMS
Multiple directory traversal vulnerabilities in download.php in Chupix CMS 0.2.3 allow remote attackers to read or overwrite arbitrary files via a .. (dot dot) in the (1) fichier or (2) repertoire parameter, or create arbitrary directories via a .. (dot dot) in the (3) repertoire parameter.
unknown
2007-09-18
7.5CVE-2007-4957
MILW0RM
BID
ComScripts -- CS Guestbook
CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin name and MD5 password hash via a direct request for base/usr/0.php.
unknown
2007-09-18
7.8CVE-2007-4937
BUGTRAQ
BID
COWON America -- jetAudio
Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic and 7.0.3.3016 allows remote attackers to create or overwrite arbitrary local files via a ..\ (dot dot backslash) in the second argument to the DownloadFromMusicStore method. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for code execution by overwriting JetAudio.exe, which is launched by the control after completion of the method call.
unknown
2007-09-19
10.0CVE-2007-4983
MILW0RM
SECUNIA
David Harris -- Mercury_32
Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211.
unknown
2007-09-20
9.0CVE-2007-5018
MILW0RM
BID
Derek Leung -- pSlash
Multiple PHP remote file inclusion vulnerabilities in pSlash 0.70 allow remote attackers to execute arbitrary PHP code via a URL in (1) the lvc_admin_dir parameter to modules/visitors2/admin/view-archiver.inc.php or (2) the lvc_include_dir parameter to modules/visitors2/include/menus.inc.php. NOTE: the modules/visitors2/include/config.inc.php vector is already covered by CVE-2006-4373. NOTE: vector 1 is disputed by CVE because PHP encounters a fatal instantiation error on a direct request for the file, before reaching the include statement.
unknown
2007-09-20
7.5CVE-2007-5014
OTHER-REF
eWire -- Payment Client
The ewirePC_Decrypt function in ewirepcfunctions.php in eWire Payment Client (ePC) 1.60 and 1.70 allows remote attackers to execute arbitrary commands via shell metacharacters in the paymentinfo parameter to simplePHPLinux/3payment_receive.php.
unknown
2007-09-18
7.5CVE-2007-4925
OTHER-REF
SECUNIA
Focus_SIS -- Focus_SIS
PHP remote file inclusion vulnerability in modules/Discipline/StudentFieldBreakdown.php in Focus/SIS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the FocusPath parameter, a different vector than CVE-2007-4806. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
unknown
2007-09-18
7.5CVE-2007-4942
VIM
FRSIRT
SECUNIA
gelatocms -- gelatocms
SQL injection vulnerability in index.php in Gelato allows remote attackers to execute arbitrary SQL commands via the post parameter.
unknown
2007-09-17
7.5CVE-2007-4918
BUGTRAQ
MILW0RM
BID
Gentoo -- libsndfile
Heap-based buffer overflow in libsndfile 1.0.17 and earlier might allow remote attackers to execute arbitrary code via a FLAC file with crafted PCM data containing a block with a size that exceeds the previous block size.
unknown
2007-09-19
7.5CVE-2007-4974
OTHER-REF
GForge -- GForge
SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter.
unknown
2007-09-18
7.5CVE-2007-4966
MILW0RM
OTHER-REF
SECUNIA
HP -- photo & imaging gallery
HP -- all-in-on printer
Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.
unknown
2007-09-17
10.0CVE-2007-4916
BUGTRAQ
BUGTRAQ
OTHER-REF
OTHER-REF
HP -- HP-UX
The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly reports password status, which allows remote attackers to obtain privileges when certain "password issues" are not detected.
unknown
2007-09-20
9.0CVE-2007-5008
HP
BID
SECTRACK
SECUNIA
Insane Visions -- OneCMS
SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands via the abc parameter.
unknown
2007-09-20
7.5CVE-2007-5016
MILW0RM
BID
Invision Power Services -- Invision Power Board
ips_kernel/class_upload.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to upload arbitrary script files with crafted image filenames to uploads/, where they are saved with a .txt extension and are not executable. NOTE: there are limited usage scenarios under which this would be a vulnerability, but it is being tracked by CVE since the vendor has stated it is security-relevant.
unknown
2007-09-17
7.5CVE-2007-4913
OTHER-REF
OTHER-REF
JBlog -- JBlog
Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the id parameter to index.php, and allow (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter to admin/modifpost.php.
unknown
2007-09-17
7.5CVE-2007-4919
MILW0RM
BID
XF
Joomla -- joom12Pic component
PHP remote file inclusion vulnerability in admin.joom12pic.php in the joom12Pic (com_joom12pic) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.
unknown
2007-09-18
7.5CVE-2007-4954
MILW0RM
Joomla -- Flash Fun component
PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun! (com_joomlaflashfun) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.
unknown
2007-09-18
7.5CVE-2007-4955
MILW0RM
BID
KDE -- KMPlayer
KMPlayer 2.9.3.1210 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a .avi file with certain large "indx truck size" and nEntriesInuse values.
unknown
2007-09-18
7.1CVE-2007-4941
BUGTRAQ
OTHER-REF
BID
XF
Ktauber -- StylesDemo
phpBB -- phpBB
SQL injection vulnerability in index.php in the Ktauber.com StylesDemo 0.9.9 mod for phpBB 2.0.xx allows remote attackers to execute arbitrary SQL commands via the s parameter.
unknown
2007-09-19
7.5CVE-2007-4984
MILW0RM
BID
KwsPHP -- kwsphp
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.php, (2) the id parameter to index.php in a carnet editer action in the Member_Space (espace_membre) module, or (3) the typenav parameter to index.php in a browser aff action in the stats module.
unknown
2007-09-18
7.5CVE-2007-4956
MILW0RM
MILW0RM
MILW0RM
BID
KwsPHP -- kwsphp
SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a results action, a different module than CVE-2007-4956.2.
unknown
2007-09-19
7.5CVE-2007-4979
MILW0RM
MPlayer -- MPlayer
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values, and a certain wLongsPerEntry value.
unknown
2007-09-18
9.3CVE-2007-4938
BUGTRAQ
OTHER-REF
BID
XF
MW6 Technologies -- QRCode ActiveX
Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Technologies QRCode ActiveX 3.0.0.1 and earlier allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveAsBMP or (2) SaveAsWMF method. NOTE: some of these details are obtained from third party information.
unknown
2007-09-19
10.0CVE-2007-4982
MILW0RM
OTHER-REF
SECUNIA
mympc -- CD-Storm
VeryCD -- StormPlayer
guliverkli -- Media Player Classic
Heap-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with an "indx truck size" of 0xffffffff, and certain wLongsPerEntry and nEntriesInuse values.
unknown
2007-09-18
9.3CVE-2007-4939
BUGTRAQ
OTHER-REF
BID
SECUNIA
SECUNIA
SECUNIA
XF
mympc -- CD-Storm
VeryCD -- StormPlayer
guliverkli -- Media Player Classic
Multiple integer overflows in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain large "indx truck size" and nEntriesInuse values.
unknown
2007-09-18
9.3CVE-2007-4940
BUGTRAQ
OTHER-REF
BID
XF
myphpPagetool -- myphpPagetool
Multiple PHP remote file inclusion vulnerabilities in myphpPagetool 0.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the ptinclude parameter to (1) help1.php, (2) help2.php, (3) help3.php, (4) help4.php, (5) help5.php, (6) help6.php, (7) help7.php, (7) help8.php, (8) help9.php, or (10) index.php in doc/admin/.
unknown
2007-09-18
7.5CVE-2007-4947
OTHER-REF
netinvoicing -- netinvoicing
Unspecified vulnerability in netInvoicing before 2.7.3 has unknown impact and attack vectors, related to "security check soap".
unknown
2007-09-17
7.5CVE-2007-4910
OTHER-REF
BID
SECUNIA
Office Efficiencies -- SafeSquid
Unspecified vulnerability in Office Efficiencies SafeSquid 4.1.x has unknown impact and attack vectors, related to a "serious security flaw," possibly specific to Linux.
unknown
2007-09-18
7.5CVE-2007-4936
OTHER-REF
BID
Omnistar Interactive -- OmniStar Article Manager
SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL commands via the page_id parameter in a favorite op action, a different vector than CVE-2006-5917.
unknown
2007-09-18
7.5CVE-2007-4952
MILW0RM
photochannel -- pni digital media upload plugin activex control
Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors.
unknown
2007-09-18
10.0CVE-2007-0326
CERT-VN
php webquest -- php webquest
SQL injection vulnerability in soporte_derecha_w.php in PHP Webquest 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter.
unknown
2007-09-17
7.5CVE-2007-4920
MILW0RM
BID
phpBB2 -- phpBB2 Plus
phpBB2 -- phpBB2 Plus German Language Pack
phpBB Group -- PhpBB
PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
unknown
2007-09-20
7.5CVE-2007-5009
BUGTRAQ
MILW0RM
BID
phpFFL -- phpFFL
Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code via a URL in the PHPFFL_FILE_ROOT parameter to (1) program_files/livedraft/livedraft.php or (2) program_files/livedraft/admin.php.
unknown
2007-09-18
7.5CVE-2007-4934
MILW0RM
OTHER-REF
BID
phpFFL -- phpFFL
Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code via a URL in the PHPFFL_FILE_ROOT parameter to (1) admin.php, (2) custom_pages.php, (3) draft.php, (4) faq.php, (5) leagues.php, (6) livedraft.php, (7) login.php, (8) my_team.php, (9) profile.php, (10) signup.php, (11) statistics.php, (12) transactions.php, (13) program_files/admin/custom_pages.php, or (14) program_files/common.php. NOTE: the program_files/livedraft/admin.php and program_files/livedraft/livedraft.php vectors are covered by CVE-2007-4934.
unknown
2007-09-18
7.5CVE-2007-4935
OTHER-REF
phportal -- phportal
** DISPUTED ** PHP remote file inclusion vulnerability in form/db_form/employee.php in PHPortal 0.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. NOTE: this issue is disputed by CVE, since DOCUMENT_ROOT cannot be modified by an attacker.
unknown
2007-09-18
7.5CVE-2007-4950
OTHER-REF
phpReactor -- phpReactor
** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in php(Reactor) 1.2.7pl1 allow remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter to (1) ekilat.com-int.tpl.php, (2) phpreactor.org-top.tpl.php, or (3) ekilat.com-top.tpl.php in examples/. NOTE: this issue has been disputed by CVE, since the vulnerability is present only when the product is incorrectly installed by placing examples/ under the web root.
unknown
2007-09-18
7.5CVE-2007-4949
OTHER-REF
phpSyncML -- phpSyncML
Multiple PHP remote file inclusion vulnerabilities in phpSyncML 0.1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) Decoder.php and (2) Encoder.php in WBXML/.
unknown
2007-09-19
7.5CVE-2007-4978
MILW0RM
Qualiteam -- X-Cart
Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dir parameter to (1) config.php, (2) prepare.php, (3) smarty.php, (4) customer/product.php, (5) provider/auth.php, and admin/auth.php.
unknown
2007-09-17
7.5CVE-2007-4907
MILW0RM
BID
Shop-Script -- Shop-Script
admin.php in Shop-Script FREE 2.0 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to access the admin panel.
unknown
2007-09-18
7.5CVE-2007-4932
MILW0RM
Shop-Script -- Shop-Script
Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier allows remote attackers to inject arbitrary PHP code into cfg/appearence.inc.php via a save_appearence action in admin.php, as demonstrated with the (1) productscount, (2) colscount, and (3) darkcolor parameters.
unknown
2007-09-18
7.5CVE-2007-4933
MILW0RM
SimpCMS -- SimpCMS
SQL injection vulnerability in index.php in SimpCMS allows remote attackers to execute arbitrary SQL commands via the keyword parameter in a search site action.
unknown
2007-09-18
7.5CVE-2007-4953
MILW0RM
Sun -- JRE
Sun -- Java Web Start
Sun -- SDK
Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact via a long argument to the dnsResolve (isInstalled.dnsResolve) method.
unknown
2007-09-20
10.0CVE-2007-5019
MILW0RM
BID
Trolltech -- Qt
Off-by-one error in the QUtf8Decoder::toUnicode function in Trolltech Qt 3 allows context-dependent attackers to cause a denial of service (crash) via a crafted Unicode string that triggers a heap-based buffer overflow. NOTE: Qt 4 has the same error in the QUtf8Codec::convertToUnicode function, but it is not exploitable.
unknown
2007-09-18
7.5CVE-2007-4137
OTHER-REF
OTHER-REF
OTHER-REF
OTHER-REF
MANDRIVA
REDHAT
BID
FRSIRT
SECUNIA
SECUNIA
SECUNIA
Ultra Shareware -- Ultra Crypto Component
Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allow remote attackers to execute arbitrary code via (1) a long string in the first argument to the AcquireContext method or (2) an unspecified vector to the DeleteContext method.
unknown
2007-09-17
7.5CVE-2007-4903
MILW0RM
BID
XF
WinImage -- WinImage
Directory traversal vulnerability in WinImage 8.10 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a filename within a (1) .IMG or (2) .ISO file. NOTE: this can be leveraged for code execution by writing to a Startup folder.
unknown
2007-09-18
9.3CVE-2007-4962
BUGTRAQ
BID
SECUNIA
WinImage -- WinImage
Visual truncation vulnerability in WinImage 8.10 and earlier allows remote attackers to spoof a destination filename via a long sequence of space characters in a filename within a (1) .IMG or (2) .ISO file. NOTE: this can be leveraged with a separate directory traversal vulnerability to trick a careful user into overwriting arbitrary files.
unknown
2007-09-18
9.3CVE-2007-4963
BUGTRAQ
WinSCP -- WinSCP
Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote server via file-transfer commands in the final portion of a (1) scp, and possibly a (2) sftp or (3) ftp, URL, as demonstrated by a URL specifying login to the remote server with a username of scp, which is interpreted as an HTTP scheme name by the protocol handler in a web browser, but is interpreted as a username by WinSCP. NOTE: this is related to an incomplete fix for CVE-2006-3015.
unknown
2007-09-17
7.5CVE-2007-4909
BUGTRAQ
OTHER-REF
OTHER-REF
BID
SECUNIA
XF
Yahoo -- Messenger
Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attackers to force a download, and create or overwrite arbitrary files via a full pathname in the second argument to the GetFile method.
unknown
2007-09-20
9.3CVE-2007-5017
MILW0RM
BID
YaPiG -- YaPiG
** DISPUTED ** PHP remote file inclusion vulnerability in sample.php in YaPiG 0.95b allows remote attackers to execute arbitrary PHP code via a URL in the YAPIG_PATH parameter. NOTE: this issue has been disputed by CVE, since YAPIG_PATH is defined before use.
unknown
2007-09-18
7.5CVE-2007-4951
OTHER-REF
Back to top

Medium Vulnerabilities
Primary
Vendor -- Product
Description
Discovered
Published
CVSS ScoreSource & Patch Info
Axis Communications -- AXIS 207W Network Camera
axis-cgi/buffer/command.cgi on the AXIS 207W camera allows remote authenticated users to cause a denial of service (reboot) via many requests with unique buffer names in the buffername parameter in a start action.
unknown
2007-09-18
4.0CVE-2007-4927
BUGTRAQ
OTHER-REF
OTHER-REF
BID
Axis Communications -- AXIS 207W Network Camera
The AXIS 207W camera stores a WEP or WPA key in cleartext in the configuration file, which might allow local users to obtain sensitive information.
unknown
2007-09-18
4.9CVE-2007-4928
BUGTRAQ
OTHER-REF
OTHER-REF
Axis Communications -- AXIS 207W Network Camera
Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 207W camera allow remote attackers to inject arbitrary web script or HTML via the camNo parameter to incl/image_incl.shtml, and other unspecified vectors.
unknown
2007-09-18
4.3CVE-2007-4929
BUGTRAQ
OTHER-REF
OTHER-REF
BID
Axis Communications -- AXIS 207W Network Camera
Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 207W camera allow remote attackers to perform certain actions as administrators via (1) axis-cgi/admin/restart.cgi, (2) the user and sgrp parameters to axis-cgi/admin/pwdgrp.cgi in an add action, or (3) the server parameter to admin/restartMessage.shtml.
unknown
2007-09-18
4.3CVE-2007-4930
BUGTRAQ
OTHER-REF
OTHER-REF
BID
B1G -- b1gmail
Cross-site scripting (XSS) vulnerability in hilfe.php in b1gMail 6.3.1 allows remote attackers to inject arbitrary web script or HTML via the chapter parameter.
unknown
2007-09-19
4.3CVE-2007-4975
BUGTRAQ
BID
SECUNIA
Coppermine -- Coppermine Photo Gallery
Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the log parameter.
unknown
2007-09-19
6.5CVE-2007-4976
BUGTRAQ
OTHER-REF
BID
SECUNIA
COWON America -- jetcast server
JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a long .mp3 URI to TCP port 8000. NOTE: some of these details are obtained from third party information.
unknown
2007-09-17
5.0CVE-2007-4911
MILW0RM
BID
SECUNIA
Data-Vision -- RemoteDocs R-Viewer
Unspecified vulnerability in RemoteDocs R-Viewer before 1.6.3768 allows user-assisted remote attackers to execute arbitrary code via a crafted RDZ archive in which the first file has an executable extension.
unknown
2007-09-18
6.8CVE-2007-4750
BUGTRAQ
OTHER-REF
BID
Data-Vision -- RemoteDocs R-Viewer
RemoteDocs R-Viewer before 1.6.3768 stores encrypted RDZ file data in unencrypted temporary files, which allows local users to obtain sensitive information by reading the temporary files.
unknown
2007-09-18
5.0CVE-2007-4751
BUGTRAQ
OTHER-REF
BID
DiamondCS -- ProcessGuard
ProcessGuard 3.410 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for Windows Native API functions including (1) NtCreateFile, (2) NtCreateKey, (3) NtDeleteValueKey, (4) NtOpenFile, (5) NtOpenKey, and (6) NtSetValueKey.
unknown
2007-09-18
4.6CVE-2007-4970
BUGTRAQ
OTHER-REF
OTHER-REF
GCALDaemon -- GCALDaemon
The readRequest method in org/gcaldaemon/core/http/HTTPListener.java in GCALDaemon 1.0-beta13 allows remote attackers to cause a denial of service via a large integer value in the Content-Length HTTP header, which triggers a fatal Java OutOfMemoryError.
unknown
2007-09-19
5.0CVE-2007-4980
BUGTRAQ
Invision Power Services -- Invision Power Board
Cross-site scripting (XSS) vulnerability in ips_kernel/class_ajax.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to inject arbitrary web script or HTML into user profile fields via unspecified vectors related to character sets other than iso-8859-1 or utf-8.
unknown
2007-09-17
4.3CVE-2007-4912
OTHER-REF
OTHER-REF
BID
SECUNIA
XF
Invision Power Services -- Invision Power Board
Unspecified vulnerability in the subscriptions manager in Invision Power Board (IPB or IP.Board) 2.3.1 before 20070912 allows remote authenticated users to change the member ID and reduce the privilege level of arbitrary users via a crafted payment form, related to (1) class_gw_2checkout.php, (2) class_gw_authorizenet.php, (3) class_gw_nochex.php, (4) class_gw_paypal.php, and (5) class_gw_safshop.php in sources/classes/paymentgateways/.
unknown
2007-09-17
6.5CVE-2007-4914
OTHER-REF
OTHER-REF
BID
SECUNIA
XF
ISecSoft -- ProSecurity
ProSecurity 1.40 Beta 2 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for Windows Native API functions including (1) NtCreateKey, (2) NtDeleteFile, (3) NtLoadDriver, (4) NtOpenSection, and (5) NtSetSystemTime.
unknown
2007-09-18
4.6CVE-2007-4971
BUGTRAQ
OTHER-REF
OTHER-REF
Jelsoft -- osCMax
Cross-site scripting (XSS) vulnerability in catalog_products_with_images.php in osCMax 2.0.0-RC3-0-1 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
unknown
2007-09-18
4.3CVE-2007-4959
SECUNIA
Joomla -- joomla_radio
PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.
unknown
2007-09-17
6.8CVE-2007-4923
MILW0RM
BID
SECUNIA
XF
KwsPHP -- kwsphp
jeuxflash -- jeuxflash module
SQL injection vulnerability in index.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a play ac action.
unknown
2007-09-17
6.5CVE-2007-4922
MILW0RM
BID
XF
LetterGrade -- LetterGrade
Multiple cross-site scripting (XSS) vulnerabilities in LetterGrade allow remote attackers to inject arbitrary web script or HTML via (1) a student's email address, (2) the year parameter to genbrws/Student/cal_month.php3, and other unspecified vectors related to the calendar. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
unknown
2007-09-18
4.3CVE-2007-4945
BID
BID
SECUNIA
LetterGrade -- LetterGrade
LetterGrade allows remote attackers to obtain sensitive information (installation path or account existence) via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
unknown
2007-09-18
5.0CVE-2007-4946
SECUNIA
Linden Lab -- Second Life
Argument injection vulnerability in the Linden Lab Second Life secondlife:// protocol handler, as used in Internet Explorer and possibly Firefox, allows remote attackers to obtain sensitive information via a '" ' (double-quote space) sequence followed by the -autologin and -loginuri arguments, which cause the handler to post login credentials and software installation details to an arbitrary URL.
unknown
2007-09-18
5.0CVE-2007-4960
BUGTRAQ
OTHER-REF
FRSIRT
SECUNIA
Linden Lab -- Second Life
The login_to_simulator method in Linden Lab Second Life, as used by the secondlife:// protocol handler and possibly other Second Life login mechanisms, sends an MD5 hash in cleartext in the passwd field, which allows remote attackers to login to an account by sniffing the network and then sending this hash to a Second Life authentication server.
unknown
2007-09-18
4.3CVE-2007-4961
OTHER-REF
Linux -- Kernel
Race condition in the tee (sys_tee) system call in the Linux kernel 2.6.17 through 2.6.17.6 might allow local users to cause a denial of service (system crash), obtain sensitive information (kernel memory contents), or gain privileges via unspecified vectors related to a potentially dropped ipipe lock during a race between two pipe readers.
unknown
2007-09-18
6.9CVE-2007-0997
MLIST
OTHER-REF
NuclearBB -- NuclearBB
PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.
unknown
2007-09-17
6.8CVE-2007-4906
BUGTRAQ
MILW0RM
oblius -- Obedit
Cross-site scripting (XSS) vulnerability in the save function in Obedit 3.03 allows user-assisted remote attackers to inject arbitrary web script or HTML via unknown vectors, as demonstrated by a SCRIPT element in an unspecified context when saving a document. NOTE: because the details of the attack are uncertain, it is unclear whether this crosses privilege boundaries.
unknown
2007-09-19
4.3CVE-2007-4981
BUGTRAQ
Online Armor -- personal firewall
Online Armor Personal Firewall 2.0.1.215 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via unspecified kernel SSDT hooks for Windows Native API functions including (1) NtAllocateVirtualMemory, (2) NtConnectPort, (3) NtCreateFile, (4) NtCreateKey, (5) NtCreatePort, (6) NtDeleteFile, (7) NtDeleteValueKey, (8) NtLoadKey, (9) NtOpenFile, (10) NtOpenProcess, (11) NtOpenThread, (12) NtResumeThread, (13) NtSetContextThread, (14) NtSetValueKey, (15) NtSuspendProcess, (16) NtSuspendThread, and (17) NtTerminateThread.
unknown
2007-09-18
4.6CVE-2007-4967
BUGTRAQ
OTHER-REF
OTHER-REF
Opera Software -- Opera
The canvas.createPattern function in Opera 9.x before 9.22 for Linux, FreeBSD, and Solaris does not clear memory before using it to process a new pattern, which allows remote attackers to obtain sensitive information (memory contents) via JavaScript.
unknown
2007-09-18
5.0CVE-2007-4944
OTHER-REF
OTHER-REF
OTHER-REF
OTHER-REF
GENTOO
Phormer -- Phormer
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Phormer 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) u, (2) p, (3) c, and (4) s parameters, and other unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
unknown
2007-09-20
4.3CVE-2007-5013
BID
SECUNIA
PHP-Stats -- PHP-Stats
Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the ip parameter in an online action, a different vector than CVE-2007-4334.
unknown
2007-09-17
4.3CVE-2007-4917
BUGTRAQ
BID
PhpWebGallery -- PhpWebGallery
Cross-site scripting (XSS) vulnerability in picture.php in PhpWebGallery 1.7.0, when Comments for all is enabled, allows remote attackers to inject arbitrary web script or HTML via the author parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
unknown
2007-09-20
4.3CVE-2007-5012
BID
SECUNIA
Privacyware -- Privatefirewall
Privatefirewall 5.0.14.2 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for (1) NtOpenProcess and (2) NtOpenThread.
unknown
2007-09-18
4.6CVE-2007-4968
BUGTRAQ
OTHER-REF
OTHER-REF
Python Software Foundation -- Python
Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.
unknown
2007-09-18
5.8CVE-2007-4965
FULLDISC
BID
RealNetworks -- RealPlayer
RealNetworks -- Helix Player
RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) and possibly other platforms, allow user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.
unknown
2007-09-17
4.3CVE-2007-4904
FULLDISC
BID
redhat -- enterprise_linux
OpenOffice -- OpenOffice
redhat -- fedora_core
redhat -- linux
Debian -- Debian Linux
Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3 allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.
unknown
2007-09-18
6.8CVE-2007-2834
IDEFENSE
OTHER-REF
DEBIAN
BID
Streamline -- Streamline
Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to execute arbitrary PHP code via a URL in the sl_theme_unix_path parameter to (1) admin_footer.php, (2) info_footer.php, (3) theme_footer.php, (4) browse_footer.php, (5) account_footer.php, or (6) search_footer.php in core/theme/includes/. NOTE: the vulnerability is present only when the administrator does not follow installation instructions about the requirement for .htaccess Limit support.
unknown
2007-09-20
6.8CVE-2007-5015
MILW0RM
OTHER-REF
BID
Sysinternals -- Process Monitor
Process Monitor 1.22 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via unspecified kernel SSDT hooks for Windows Native API functions including (1) NtCreateKey, (2) NtDeleteValueKey, (3) NtLoadKey, (4) NtOpenKey, (5) NtQueryValueKey, (6) NtSetValueKey, and (7) NtUnloadKey.
unknown
2007-09-18
4.6CVE-2007-4969
BUGTRAQ
OTHER-REF
OTHER-REF
TinyWebGallery -- TinyWebGallery
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) 1.6.3.4 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) index.php, (2) i_frames/i_login.php, and (3) i_frames/i_top_tags.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
unknown
2007-09-18
4.3CVE-2007-4958
SECUNIA
Ultra Shareware -- Ultra Crypto Component
Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allows remote attackers to write to arbitrary files via a full pathname in the argument to the SaveToFile method.
unknown
2007-09-17
6.4CVE-2007-4902
MILW0RM
BID
XF
Webmedia Explorer -- Webmedia Explorer
Multiple PHP remote file inclusion vulnerabilities in Webmedia Explorer (webmex) 3.2.2 allow remote attackers to execute arbitrary PHP code via (1) a URL in the path_include parameter to includes/rss.class.php, (2) a URL in the path_template parameter to (a) templates/main.tpl.php or (b) templates/folder_messages_link_message_name.tpl.php, or (4) a URL in the path_templates parameter to templates/sidebar.tpl.php. NOTE: the vulnerability is present only when the administrator does not follow installation instructions about the requirement for .htaccess support. NOTE: the includes/core.lib.php vector is already covered by CVE-2006-5252.
unknown
2007-09-18
5.1CVE-2007-4948
OTHER-REF
Wilson WindowWare -- WebBatch
Cross-site scripting (XSS) vulnerability in WebBatch allows remote attackers to inject arbitrary web script or HTML via the URL to webbatch.exe. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
unknown
2007-09-20
4.3CVE-2007-5010
SECUNIA
Wilson WindowWare -- WebBatch
webbatch.exe in WebBatch allows remote attackers to obtain sensitive information via the dumpinputdata parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
unknown
2007-09-20
5.0CVE-2007-5011
SECUNIA
WinImage -- WinImage
WinImage 8.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via an invalid BPB_BytsPerSec field in the header of a .IMG file.
unknown
2007-09-18
5.0CVE-2007-4964
BUGTRAQ
BID
Back to top

Low Vulnerabilities
Primary
Vendor -- Product
Description
Discovered
Published
CVSS ScoreSource & Patch Info
Coppermine -- Coppermine Photo Gallery
Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the referer parameter.
unknown
2007-09-19
3.5CVE-2007-4977
BUGTRAQ
OTHER-REF
BID
SECUNIA
HP -- System Management Homepage
HP System Management Homepage (SMH) for Windows, when used in conjunction with HP Version Control Agent or Version Control Repository Manager, leaves old OpenSSL software active after an OpenSSL update, which has unknown impact and attack vectors, probably related to previous vulnerabilities for OpenSSL.
unknown
2007-09-18
2.1CVE-2007-4931
HP
BID
SECTRACK
Linux -- Kernel
The Linux kernel 2.6.20 and 2.6.21 does not properly handle an invalid LDT segment selector in %cs (the xcs field) during ptrace single-step operations, which allows local users to cause a denial of service (NULL dereference and OOPS) via certain code that makes ptrace PTRACE_SETREGS and PTRACE_SINGLESTEP requests, related to the TRACE_IRQS_ON function, and possibly related to the arch_ptrace function.
unknown
2007-09-17
2.1CVE-2007-3731
OTHER-REF
OTHER-REF
OTHER-REF
OTHER-REF
NetBSD -- NetBSD
The display driver allocattr functions in NetBSD 3.0 through 4.0_BETA2, and NetBSD-current before 20070728, allow local users to cause a denial of service (panic) via a (1) negative or (2) large value in an ioctl call, as demonstrated by the vga_allocattr function.
unknown
2007-09-17
2.1CVE-2007-3654
NETBSD
XF
redhat -- enterprise_linux
The NFS client implementation in the kernel in Red Hat Enterprise Linux (RHEL) 3, when a filesystem is mounted with the noacl option, checks permissions for the open system call via vfs_permission (mode bits) data rather than an NFS ACCESS call to the server, which allows local client processes to obtain a false success status from open calls that the server would deny, and possibly obtain sensitive information about file permissions on the server, as demonstrated in a root_squash environment. NOTE: it is uncertain whether any scenarios involving this issue cross privilege boundaries.
unknown
2007-09-18
1.9CVE-2007-0004
OTHER-REF
redhat -- enterprise_linux
** DISPUTED ** The ipv6_getsockopt_sticky function in the kernel in Red Hat Enterprise Linux (RHEL) Beta 5.1.0 allows local users to obtain sensitive information (kernel memory contents) via a negative value of the len parameter. NOTE: this issue has been disputed in a bug comment, stating that "len is ignored when copying header info to the user's buffer."
unknown
2007-09-18
2.1CVE-2007-1865
OTHER-REF
redhat -- enterprise_linux
redhat -- linux
Unspecified vulnerability in the kernel in Red Hat Enterprise Linux (RHEL) 4 on the x86_64 platform allows local users to cause a denial of service (OOPS) via unspecified vectors related to the get_gate_vma function and the fuser command.
unknown
2007-09-17
2.1CVE-2007-3379
OTHER-REF
REDHAT
Sysinternals -- Regmon
RegMon 7.04 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks to the (1) NtCreateKey and (2) NtOpenKey Windows Native API functions.
unknown
2007-09-18
0.0CVE-2007-4972
BUGTRAQ
OTHER-REF
OTHER-REF
Back to top



Last updated September 24, 2007